[CLSA-2026:1790185476] alt-python312: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 17:44:47 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in tarfile's makelink_with_filter(), so a crafted archive whose hard link targets a just-extracted symlink can no longer duplicate that symlink inode one directory shallower, where its relative payload re-bases outside the destination and the following chmod/utime act on the outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation. Effective only together with CVE-2026-11940, which is native in 3.12.14 and blocks the no-decoy variant that never reaches os.link() under the "data" filter
CVEs fixed:
Updated packages:
  • alt-python312-3.12.14-6.el9.x86_64.rpm
    sha:5d44b276ba3b612f61f7db62ddb67320f259551a60323fc8da6e5d35e58366a3
  • alt-python312-debug-3.12.14-6.el9.x86_64.rpm
    sha:954a5a6db5871520535cdd4c1504c16529b7dcedaff07c63232e8b6c94b2d089
  • alt-python312-devel-3.12.14-6.el9.x86_64.rpm
    sha:2bd4bc0ca67356ef56824f0fbdd18eb045345652832bf72c348dd034d916f5b3
  • alt-python312-idle-3.12.14-6.el9.x86_64.rpm
    sha:e075b88f7dd87965c5c0898f33d63a1daede238fd7c2de97466730a6d7d26208
  • alt-python312-libs-3.12.14-6.el9.x86_64.rpm
    sha:01d36dcf3ef438f833a54e4b79b0e74e82cb4ecf6556e7793ff2f22091f9608a
  • alt-python312-test-3.12.14-6.el9.x86_64.rpm
    sha:32c8a2e81e0c24d1d10cb51f1ccf08af6956c2bc9d9cd86b7e73894cbceac16f
  • alt-python312-tkinter-3.12.14-6.el9.x86_64.rpm
    sha:0f7c480965e96aa87b33cc537b5dcd0a85e2cf438c5060c63dcc01a1b481c2fb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.