[CLSA-2026:1790190249] alt-python311: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 19:04:20 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in tarfile's makelink_with_filter(), so a crafted archive whose hard link targets a just-extracted symlink can no longer duplicate that symlink inode one directory shallower, where its relative payload re-bases outside the destination and the following chmod/utime act on the outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation. Effective only together with CVE-2026-11940, which is native in 3.11.16 and blocks the no-decoy variant that never reaches os.link()
CVEs fixed:
Updated packages:
  • alt-python311-3.11.16-2.el9.x86_64.rpm
    sha:fcd73b7b3533c75445f33591d48a728fbf6bb3285768010a1eb0c30f50999785
  • alt-python311-debug-3.11.16-2.el9.x86_64.rpm
    sha:e45fa717c8c61f789284cdea71d2083cfeb867f6f9c4938c18d66ef810b84722
  • alt-python311-devel-3.11.16-2.el9.x86_64.rpm
    sha:bc6272cedad41603694a2ff202c524695124d838b445f42cc515a19e308e61d1
  • alt-python311-idle-3.11.16-2.el9.x86_64.rpm
    sha:a05624113f9cbc199e0bea37fb834eaf62a13a4bed8e7ecee243302f2b2dcb07
  • alt-python311-libs-3.11.16-2.el9.x86_64.rpm
    sha:a7f22d57947ce88452fe0bbb150f218dac8a99c82bc55d4509bd1c77fce69594
  • alt-python311-test-3.11.16-2.el9.x86_64.rpm
    sha:7e8d0c5af6c6ac2a33780ceca5628751bf0937934288b0d33efba3fcf87e73f5
  • alt-python311-tkinter-3.11.16-2.el9.x86_64.rpm
    sha:b5f0b944b3f53c9485ccb7f02c45d93f18679030f565b83e03dd9676849313ce
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.