[CLSA-2026:1790168488] alt-python312: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 18:41:48 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in tarfile's makelink_with_filter(), so a crafted archive whose hard link targets a just-extracted symlink can no longer duplicate that symlink inode one directory shallower, where its relative payload re-bases outside the destination and the following chmod/utime act on the outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation. Effective only together with CVE-2026-11940, which is native in 3.12.14 and blocks the no-decoy variant that never reaches os.link() under the "data" filter
CVEs fixed:
Updated packages:
  • alt-python312-3.12.14-6.el8.x86_64.rpm
    sha:ede8037b400f244a4162a7d7cd135089133e7f0c123345db60278cba0bdc38e8
  • alt-python312-debug-3.12.14-6.el8.x86_64.rpm
    sha:d22f225e228b9a00ed614faa13f064196cb2ed027dcd7e8771d81cd9a7bccec9
  • alt-python312-devel-3.12.14-6.el8.x86_64.rpm
    sha:fd8262a27294fec49f2e493661324b95af9e7fd71524a2814e81d58c2bea443b
  • alt-python312-idle-3.12.14-6.el8.x86_64.rpm
    sha:d915360194df738d2b5572e8ab77201747ea6729aa2309d8e4228c8e95898587
  • alt-python312-libs-3.12.14-6.el8.x86_64.rpm
    sha:9a888ca24cf4931142cd23b57fa0d6d498a082b53187eaca207f2b29df3c6042
  • alt-python312-test-3.12.14-6.el8.x86_64.rpm
    sha:6fde43594076560dbab10fa8d99c52344cf83d6935abb86fe6f7dae95cc6b7c7
  • alt-python312-tkinter-3.12.14-6.el8.x86_64.rpm
    sha:e6acca8462e892a30d359f6d405e3f2fa537e7300801f8ad177f58ba4c3b8803
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.