[CLSA-2026:1790211073] alt-python310: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-24 00:51:24 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in tarfile's makelink_with_filter(), so a crafted archive whose hard link targets a just-extracted symlink can no longer duplicate that symlink inode one directory shallower, where its relative payload re-bases outside the destination and the following chmod/utime act on the outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation. Effective only together with CVE-2026-11940, which is native in 3.10.21 and blocks the no-decoy variant that never reaches os.link()
CVEs fixed:
Updated packages:
  • alt-python310-3.10.21-2.el7.x86_64.rpm
    sha:c4c830bef7e9ef835755ff417dfafa849f47db3cc606c6da96e1d6aed3e227ca
  • alt-python310-debug-3.10.21-2.el7.x86_64.rpm
    sha:a4de9ca0b3cec00c19367452cc731f0a0b07af7c4f285db10bbe679579357a02
  • alt-python310-devel-3.10.21-2.el7.x86_64.rpm
    sha:c8c5deae56fc11438a59ade44ee2b947816bc31da18a5afcbb6c09325a4d94e5
  • alt-python310-idle-3.10.21-2.el7.x86_64.rpm
    sha:81a125abcb1e020be8cd4ee04b5deacce555fed3229b8826b36d3b50ff968cf7
  • alt-python310-libs-3.10.21-2.el7.x86_64.rpm
    sha:2ee454abf64a787e3c04c737e5dc665818ec2508566349b4db90efc970b6d4af
  • alt-python310-test-3.10.21-2.el7.x86_64.rpm
    sha:56dc58bb7bf9493d706d7f36324036aac3c43a552fa7e6d28f3fd968373b757d
  • alt-python310-tkinter-3.10.21-2.el7.x86_64.rpm
    sha:dbdb6d7de86b26faab6bfc3e69c9e5654bba1a886c966c857bfdde7c1b8ca911
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.