[CLSA-2026:1790187680] alt-python37: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 18:21:32 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in tarfile's makelink_with_filter(), so a crafted archive whose hard link targets a just-extracted symlink can no longer duplicate that symlink inode one directory shallower, where its relative payload re-bases outside the destination and the following chmod/utime act on the outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation. Effective only together with CVE-2026-11940.patch, which blocks the no-decoy variant that never reaches os.link() under the "data" filter
CVEs fixed:
Updated packages:
  • alt-python37-3.7.17-29.el8.x86_64.rpm
    sha:820f6994e8f99c7665fba912826e64325f6d0e600779c0adab71a34bc3cc12cb
  • alt-python37-debug-3.7.17-29.el8.x86_64.rpm
    sha:22532ff212909bf176450c92f465ef2fab3b29a36418d9ed56211eea7b37b3f9
  • alt-python37-devel-3.7.17-29.el8.x86_64.rpm
    sha:be4595b24249936660ce21a50ef8088b07a8acd6425b12bd874e1f423c84dfa0
  • alt-python37-libs-3.7.17-29.el8.x86_64.rpm
    sha:adff9f7ea3706c994648c82c5b365aa329a00d166e2badd2dcabb989e7a8328b
  • alt-python37-test-3.7.17-29.el8.x86_64.rpm
    sha:22efc542758cc4f6cbfc4a31f599f5e242c416f2c62c953e2a5554dcc5e4ca62
  • alt-python37-tkinter-3.7.17-29.el8.x86_64.rpm
    sha:9a50e70cc7b62d73c82d1c62075e2bf9d2f54206b875c505b78acb5902c9b4a7
  • alt-python37-tools-3.7.17-29.el8.x86_64.rpm
    sha:486296cd1a7c67d056f1d081f5e52917b30de00e985f013a605b6200dad63fbf
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.