[CLSA-2026:1790210333] alt-python37: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-24 00:39:03 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in tarfile's makelink_with_filter(), so a crafted archive whose hard link targets a just-extracted symlink can no longer duplicate that symlink inode one directory shallower, where its relative payload re-bases outside the destination and the following chmod/utime act on the outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation. Effective only together with CVE-2026-11940.patch, which blocks the no-decoy variant that never reaches os.link() under the "data" filter
CVEs fixed:
Updated packages:
  • alt-python37-3.7.17-29.el9.x86_64.rpm
    sha:31a4c7b6f9b4cb3a32d5c2bba6021df2688d7dea6e8994fc6236470c675a58ee
  • alt-python37-debug-3.7.17-29.el9.x86_64.rpm
    sha:c4d69f7450a30f6e3851448baa476314a8ecf8b00a25ad1a2419718cd27e8a38
  • alt-python37-devel-3.7.17-29.el9.x86_64.rpm
    sha:998fbb417514707000b19f71fd78199bb757f180050546ed23f21864ff033813
  • alt-python37-libs-3.7.17-29.el9.x86_64.rpm
    sha:242b3ef6369d86b221de2283a7bca0c4c6ae1f23f0b1f3983c862be582c5493c
  • alt-python37-test-3.7.17-29.el9.x86_64.rpm
    sha:4490333e2ee8496893eda279c1f57f5bec8b333d70e84057c01bdb2f5e9b484e
  • alt-python37-tkinter-3.7.17-29.el9.x86_64.rpm
    sha:073b45c6e9abde598fce9d854a5481866ef4dc96b800cc5c384c2a52e64813c7
  • alt-python37-tools-3.7.17-29.el9.x86_64.rpm
    sha:3c6efab40169d0bdc158cacd072b3280e2314d70d4189d9f10d3c764bba7f184
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.