[CLSA-2026:1790185694] alt-python313: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 17:48:24 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in tarfile's makelink_with_filter(), so a crafted archive whose hard link targets a just-extracted symlink can no longer duplicate that symlink inode one directory shallower, where its relative payload re-bases outside the destination and the following chmod/utime act on the outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation. Effective only together with CVE-2026-11940, which is native in 3.13.15 and blocks the no-decoy variant that never reaches os.link() under the "data" filter
CVEs fixed:
Updated packages:
  • alt-python313-3.13.15-3.el7.x86_64.rpm
    sha:24731ab316f8c16e97158f60c5623ed2face2ef9ae9d89fbcd2d4236f0a6d492
  • alt-python313-debug-3.13.15-3.el7.x86_64.rpm
    sha:a6241703f5db457d7e1c2e9a6848f1852977246060604b0667772a9d1c94497e
  • alt-python313-devel-3.13.15-3.el7.x86_64.rpm
    sha:3ab2d11b2a8e4e417809590dede938e1c8965bd7ef82b7f860e669075015f33f
  • alt-python313-idle-3.13.15-3.el7.x86_64.rpm
    sha:31d4edbfd2a002ecd9a11bc38526be90d3961d64b6f41ccc9412756c959f992e
  • alt-python313-libs-3.13.15-3.el7.x86_64.rpm
    sha:2be637172416b6cda685e3123b887f5cfcbba18be0194cd86651937dd1f65231
  • alt-python313-test-3.13.15-3.el7.x86_64.rpm
    sha:86b130385600175fd0bdf3230721db0470a661f3f1565c55df63f777857d7076
  • alt-python313-tkinter-3.13.15-3.el7.x86_64.rpm
    sha:5386842d3f02d9faebaf305e7b3813aee3ab9c97c617d93b4389d804b5f85a73
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.