Release date:
2026-09-23 16:29:03 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in
tarfile's makelink_with_filter(), so a crafted archive whose hard link
targets a just-extracted symlink can no longer duplicate that symlink
inode one directory shallower, where its relative payload re-bases
outside the destination and the following chmod/utime act on the
outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation.
Effective only together with CVE-2026-11940, which is native in 3.13.15
and blocks the no-decoy variant that never reaches os.link() under the
"data" filter
Updated packages:
-
alt-python313-3.13.15-3.el10.x86_64.rpm
sha:e0eec236fa0ccdc9840e4345b95878c4c31d4d97e6e38cb3b9643f784acac345
-
alt-python313-debug-3.13.15-3.el10.x86_64.rpm
sha:2cd8eed1d5cd6b1394c8668a7a9d7c93f3b4641ed4896abf5b06a3fd872020ed
-
alt-python313-devel-3.13.15-3.el10.x86_64.rpm
sha:07e0359e1efdd7f29ee3dd42e16a50053aef28bc0e17f4efc5d686cc42f31216
-
alt-python313-idle-3.13.15-3.el10.x86_64.rpm
sha:1f39310ae2554f6ce9135fbe02f2c74386c5b30fcb63c54c1ad6ecd415bb8f82
-
alt-python313-libs-3.13.15-3.el10.x86_64.rpm
sha:83ae864897740b90bd0ca932a9e79d27dd0185f3fc3e9911027ac8b2b3192eea
-
alt-python313-test-3.13.15-3.el10.x86_64.rpm
sha:7ed6049c68727d987b19dd498533ab901d0bdc015f527aa1dc16d9df27b080d1
-
alt-python313-tkinter-3.13.15-3.el10.x86_64.rpm
sha:5cbae04a9dffb67c2ac92cadaa49a63ec99a2e725085249d4b57229f2f5755a9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.