[CLSA-2026:1790207798] alt-python313: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 23:56:48 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in tarfile's makelink_with_filter(), so a crafted archive whose hard link targets a just-extracted symlink can no longer duplicate that symlink inode one directory shallower, where its relative payload re-bases outside the destination and the following chmod/utime act on the outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation. Effective only together with CVE-2026-11940, which is native in 3.13.15 and blocks the no-decoy variant that never reaches os.link() under the "data" filter
CVEs fixed:
Updated packages:
  • alt-python313-3.13.15-3.el9.x86_64.rpm
    sha:d8bf06ecfd957c94555aeda5e87bf8454908d500bb2e953678c8125e96d0b45b
  • alt-python313-debug-3.13.15-3.el9.x86_64.rpm
    sha:6d3dc4d94c3a9a1ea27b95de675fd9c2d8a6daff468e93596eafeb78b26aa1a5
  • alt-python313-devel-3.13.15-3.el9.x86_64.rpm
    sha:c5494cd6d14ee03e96048bab3853632d320ad156c5edc6470f2e5f82aeac54ad
  • alt-python313-idle-3.13.15-3.el9.x86_64.rpm
    sha:5b5d16c751eec3ec8e86cdab3d5075dbf8f5bd739c33f196b538415296290634
  • alt-python313-libs-3.13.15-3.el9.x86_64.rpm
    sha:b98a654e7cc6f76d254ef12ea9246a9c1de17bbf72ea46d2ce15b365115355ad
  • alt-python313-test-3.13.15-3.el9.x86_64.rpm
    sha:cc9f2c65a904c4048c6cbe472c91a5e272e96131e7fddec9879671fc6c2268d1
  • alt-python313-tkinter-3.13.15-3.el9.x86_64.rpm
    sha:2a278edbbbb389c7b166e0653c40ac8809b2cf54b8158b76f752bb67d339f7f9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.