Release date:
2026-09-24 00:39:03 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in
tarfile's makelink_with_filter(), so a crafted archive whose hard link
targets a just-extracted symlink can no longer duplicate that symlink
inode one directory shallower, where its relative payload re-bases
outside the destination and the following chmod/utime act on the
outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation.
Effective only together with CVE-2026-11940.patch, which blocks the
no-decoy variant that never reaches os.link() under the "data" filter
Updated packages:
-
alt-python37-3.7.17-29.el9.x86_64.rpm
sha:31a4c7b6f9b4cb3a32d5c2bba6021df2688d7dea6e8994fc6236470c675a58ee
-
alt-python37-debug-3.7.17-29.el9.x86_64.rpm
sha:c4d69f7450a30f6e3851448baa476314a8ecf8b00a25ad1a2419718cd27e8a38
-
alt-python37-devel-3.7.17-29.el9.x86_64.rpm
sha:998fbb417514707000b19f71fd78199bb757f180050546ed23f21864ff033813
-
alt-python37-libs-3.7.17-29.el9.x86_64.rpm
sha:242b3ef6369d86b221de2283a7bca0c4c6ae1f23f0b1f3983c862be582c5493c
-
alt-python37-test-3.7.17-29.el9.x86_64.rpm
sha:4490333e2ee8496893eda279c1f57f5bec8b333d70e84057c01bdb2f5e9b484e
-
alt-python37-tkinter-3.7.17-29.el9.x86_64.rpm
sha:073b45c6e9abde598fce9d854a5481866ef4dc96b800cc5c384c2a52e64813c7
-
alt-python37-tools-3.7.17-29.el9.x86_64.rpm
sha:3c6efab40169d0bdc158cacd072b3280e2314d70d4189d9f10d3c764bba7f184
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.