Release date:
2026-09-24 00:12:20 UTC
Description:
- CVE-2026-82049: tarfile 'data'/'tar' extraction filter bypass via a hard link to a
symbolic link (CWE-59). TarFile.makelink_with_filter() passed
tarinfo._link_target straight to os.link(); link(2) does not follow symbolic
links, so an archive storing a hard link whose target is an archived symlink
got the same symlink inode materialised one directory shallower than the
symlink the filter had validated. Its relative body then re-based outside the
destination directory, and the chmod()/utime() applied to the newly created
name followed the link onto the outside file, changing its permissions and
modification time and exposing its contents inside the extracted tree.
- debian/patches/CVE-2026-82049.patch: backport of cpython
b8f23e307097552eaea2604383a12ab280520d0d (gh-157190), which resolves the
hard-link source with os.path.realpath() before os.link(), plus its
regression test test_sneaky_hardlink_relocation. Sufficient only in
combination with CVE-2026-11940, already applied here, which blocks the
no-decoy variant that never reaches os.link(); the two must not be separated.
Updated packages:
-
alt-python38-3.8.20-27.el9.x86_64.rpm
sha:8fa781509d7233a23a4a608650d4f02cacb70c33b9358acf46249a813b7b09bb
-
alt-python38-devel-3.8.20-27.el9.x86_64.rpm
sha:0c319d1d8ba833e78f7d68e9e5d69ccae3e4529d6e4658547f8ae35c106a5d06
-
alt-python38-idle-3.8.20-27.el9.x86_64.rpm
sha:4dfd7b78f027cc4bc64738a13c71dc9cfd4b3d5e40021d7aab1757930cea820f
-
alt-python38-libs-3.8.20-27.el9.x86_64.rpm
sha:78c300fbe5f0c63889ada33e88af53274a10e812a25bf39b19e2532bf51acd70
-
alt-python38-test-3.8.20-27.el9.x86_64.rpm
sha:04fd5a0545fb3f94488a394dcdb65733ea5a59137d15f7d5529de9a9505ac66d
-
alt-python38-tkinter-3.8.20-27.el9.x86_64.rpm
sha:c699716b099b7bbd441d69826f93e17e2ba0b9679fe3df6681bf00318a623811
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.