Release date:
2026-09-23 16:39:49 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in
tarfile's makelink_with_filter(), so a crafted archive whose hard link
targets a just-extracted symlink can no longer duplicate that symlink
inode one directory shallower, where its relative payload re-bases
outside the destination and the following chmod/utime act on the
outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation.
Effective only together with CVE-2026-11940, which is native in 3.12.14
and blocks the no-decoy variant that never reaches os.link() under the
"data" filter
Updated packages:
-
alt-python312-3.12.14-6.el7.x86_64.rpm
sha:a5e0c712c301f1d1368bb081092da346a7a5c771d1420805172673ca17838538
-
alt-python312-debug-3.12.14-6.el7.x86_64.rpm
sha:05672428e849fb1d9720db6b575b74ac7a1c8c4b036b737516b4933010e7b1a0
-
alt-python312-devel-3.12.14-6.el7.x86_64.rpm
sha:5957de34fa3e770668812a1c6b259decc7e8c827de9830202cec94810c67acfc
-
alt-python312-idle-3.12.14-6.el7.x86_64.rpm
sha:497fd1057c999b9f89dfe212de65816f5b1e93dc591192175e44d1a48d131f19
-
alt-python312-libs-3.12.14-6.el7.x86_64.rpm
sha:d5594f235f5be1228ca16c2d58a8cfd3ebe49d3d5836c0f772c5ae132ddfc9d8
-
alt-python312-test-3.12.14-6.el7.x86_64.rpm
sha:f0efc734dda5add2a6134f4afdb9c41cebbeb4f58bdb4cca610f8402be6e9959
-
alt-python312-tkinter-3.12.14-6.el7.x86_64.rpm
sha:77b75a302a6f15b91f275b7ffeae81755892f8a7e5581934bcb219510f860722
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.