[CLSA-2026:1790171215] alt-python39: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 13:47:05 UTC
Description:
- CVE-2026-82049: tarfile 'data'/'tar' extraction filter bypass via a hard link to a symbolic link (CWE-59). TarFile.makelink_with_filter() passed tarinfo._link_target straight to os.link(); link(2) does not follow symbolic links, so an archive storing a hard link whose target is an archived symlink got the same symlink inode materialised one directory shallower than the symlink the filter had validated. Its relative body then re-based outside the destination directory, and the chmod()/utime() applied to the newly created name followed the link onto the outside file, changing its permissions and modification time and exposing its contents inside the extracted tree. - debian/patches/CVE-2026-82049.patch: backport of cpython b8f23e307097552eaea2604383a12ab280520d0d (gh-157190), which resolves the hard-link source with os.path.realpath() before os.link(), plus its regression test test_sneaky_hardlink_relocation. Sufficient only in combination with CVE-2026-11940, already applied here, which blocks the no-decoy variant that never reaches os.link(); the two must not be separated.
CVEs fixed:
Updated packages:
  • alt-python39-3.9.23-28.el8.x86_64.rpm
    sha:e680471f06b9e63182037b297a89dbfd5d13bb397bf07db273d7612c919f2bd7
  • alt-python39-debug-3.9.23-28.el8.x86_64.rpm
    sha:e2453889ae778ae6f578acd2f64809d8d78543d39e181220a80697a0a8d853ea
  • alt-python39-devel-3.9.23-28.el8.x86_64.rpm
    sha:2ff7da7cf017d8b75066099ea49bf944125dedc5827e81b63401daea99405997
  • alt-python39-idle-3.9.23-28.el8.x86_64.rpm
    sha:2092c7de232ee9823c4d11de9d44206c9a7761c1354dffe6024394d9438262f6
  • alt-python39-libs-3.9.23-28.el8.x86_64.rpm
    sha:6eb294760d2d6988aa4713eb3e1ed3495460252f7a3c91bd0a6c75c7c065d0e2
  • alt-python39-test-3.9.23-28.el8.x86_64.rpm
    sha:f2a2118be5f3b052cd3282442f5c47b94f6da13d32e07f5929848a6fc8994cf7
  • alt-python39-tkinter-3.9.23-28.el8.x86_64.rpm
    sha:09f81d9ccfcf1ee137b2f5da116076d6a39cc201e4399462ab970640dbdd374d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.