[CLSA-2026:1790178496] alt-python36: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 15:48:28 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in tarfile's makelink_with_filter(), so a crafted archive whose hard link targets a just-extracted symlink can no longer duplicate that symlink inode one directory shallower, where its relative payload re-bases outside the destination and the following chmod/utime act on the outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation. Effective only together with CVE-2026-11940.patch, which blocks the no-decoy variant that never reaches os.link() under the "data" filter
CVEs fixed:
Updated packages:
  • alt-python36-3.6.15-37.el9.x86_64.rpm
    sha:ffaad38e529cb1a30fc9752104086f40e1b68beb44b2bf69a6436bf579dd8d1a
  • alt-python36-debug-3.6.15-37.el9.x86_64.rpm
    sha:eb495754b6820ad31759cdcdc83b39f5e847020d1c6d5569fd63e6b56a7c8ee1
  • alt-python36-devel-3.6.15-37.el9.x86_64.rpm
    sha:3af5278a035f23611a7199bb46965f254bd2c7ccd97e9cb4172e81d10bea2531
  • alt-python36-libs-3.6.15-37.el9.x86_64.rpm
    sha:dd232c187bdf714b22a8fda4cd1b8838caae786a38552b251f69817e2548df74
  • alt-python36-test-3.6.15-37.el9.x86_64.rpm
    sha:0f2af1c3d15b462d112f49ded7cd0108fe607b7ffab362bb515690a2d476c32c
  • alt-python36-tkinter-3.6.15-37.el9.x86_64.rpm
    sha:da62bcaff6100a7a470a19d00676941dacfe18393b3defbf36160e60da812bc3
  • alt-python36-tools-3.6.15-37.el9.x86_64.rpm
    sha:6a2e6c2617ba903db66d2991262dea2b99548c110e68e92ff7bfebc057e75e4d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.