[CLSA-2026:1790213099] alt-python38: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-24 01:25:10 UTC
Description:
- CVE-2026-82049: tarfile 'data'/'tar' extraction filter bypass via a hard link to a symbolic link (CWE-59). TarFile.makelink_with_filter() passed tarinfo._link_target straight to os.link(); link(2) does not follow symbolic links, so an archive storing a hard link whose target is an archived symlink got the same symlink inode materialised one directory shallower than the symlink the filter had validated. Its relative body then re-based outside the destination directory, and the chmod()/utime() applied to the newly created name followed the link onto the outside file, changing its permissions and modification time and exposing its contents inside the extracted tree. - debian/patches/CVE-2026-82049.patch: backport of cpython b8f23e307097552eaea2604383a12ab280520d0d (gh-157190), which resolves the hard-link source with os.path.realpath() before os.link(), plus its regression test test_sneaky_hardlink_relocation. Sufficient only in combination with CVE-2026-11940, already applied here, which blocks the no-decoy variant that never reaches os.link(); the two must not be separated.
CVEs fixed:
Updated packages:
  • alt-python38-3.8.20-27.el7.x86_64.rpm
    sha:303e9ec35e303a813acbb91273e76980948f18032129886d8ca0424e80abf63e
  • alt-python38-debug-3.8.20-27.el7.x86_64.rpm
    sha:a35c6e2ca1ea501ff47ad8b61988f16005758ed5b562e86758f4e8bc03911b64
  • alt-python38-devel-3.8.20-27.el7.x86_64.rpm
    sha:45f26e94c2b14693ba8833afcb0ad4715c41a4bc0e51b8e953697f42c3484be6
  • alt-python38-idle-3.8.20-27.el7.x86_64.rpm
    sha:7c0742901bb51b9f6ea45d4994650417da00aad26793e0955e89e2888d02f7e3
  • alt-python38-libs-3.8.20-27.el7.x86_64.rpm
    sha:e4267dcadef689dbbc0aef647919b4a81530e54a9bdb15c1d827b16a5b29e557
  • alt-python38-test-3.8.20-27.el7.x86_64.rpm
    sha:13f21ed70404944acd566ba498b51c875578997356841038b4620229823f0181
  • alt-python38-tkinter-3.8.20-27.el7.x86_64.rpm
    sha:a0396b2e14292ffcae1d3c938ea7dbce5fccc7e24705d97236574fa807019b76
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.