Skip to content

Commit 1eed6ff

Browse files
StanFromIrelandfreakboy3742
authored andcommitted
[3.11] gh-157190: Fix tarfile data/tar filter bypass via hard link to a symlink (GH-157191) (GH-157192)
(cherry picked from commit 480ea4a) The backport to 3.13 and below includes a NEWS entry. (cherry picked from commit b8f23e3) Co-authored-by: Stan Ulbrych <stan@python.org>
1 parent 543f8d9 commit 1eed6ff

4 files changed

Lines changed: 47 additions & 1 deletion

File tree

‎Lib/tarfile.py‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2650,7 +2650,11 @@ def makelink_with_filter(self, tarinfo, targetpath,
26502650
return
26512651
else:
26522652
if os.path.exists(tarinfo._link_target):
2653-
os.link(tarinfo._link_target, targetpath)
2653+
# Resolve the target so the hard link points to the file
2654+
# itself. Otherwise os.link() may duplicate a symlink to a
2655+
# shallower location, where it's relative target escapes the
2656+
# destination directory. (CVE-2026-82049)
2657+
os.link(os.path.realpath(tarinfo._link_target), targetpath)
26542658
return
26552659
except symlink_exception:
26562660
keyerror_to_extracterror = True

‎Lib/test/support/os_helper.py‎

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,8 @@
99
import unittest
1010
import warnings
1111

12+
from test import support
13+
1214

1315
# Filename used for testing
1416
if os.name == 'java':
@@ -194,6 +196,23 @@ def skip_unless_symlink(test):
194196
return test if ok else unittest.skip(msg)(test)
195197

196198

199+
_can_hardlink = None
200+
201+
def can_hardlink():
202+
global _can_hardlink
203+
if _can_hardlink is None:
204+
# Android blocks hard links using SELinux
205+
# (https://stackoverflow.com/q/32365690).
206+
_can_hardlink = hasattr(os, "link") and not support.is_android
207+
return _can_hardlink
208+
209+
210+
def skip_unless_hardlink(test):
211+
ok = can_hardlink()
212+
msg = "requires hardlink support"
213+
return test if ok else unittest.skip(msg)(test)
214+
215+
197216
_can_xattr = None
198217

199218

‎Lib/test/test_tarfile.py‎

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4105,6 +4105,24 @@ def test_sneaky_hardlink_fallback_deep(self):
41054105
self.expect_file("a/b/s", symlink_to=os.path.join('..', 'escape'))
41064106
self.expect_file("s", symlink_to=os.path.join('..', 'escape'))
41074107

4108+
@symlink_test
4109+
@os_helper.skip_unless_hardlink
4110+
def test_sneaky_hardlink_relocation(self):
4111+
with ArchiveMaker() as arc:
4112+
arc.add("a/escape", content="decoy")
4113+
arc.add("a/b/s", symlink_to=os.path.join("..", "escape"))
4114+
arc.add("s", hardlink_to=os.path.join("a", "b", "s"))
4115+
4116+
for filter in 'data', 'tar':
4117+
with self.subTest(filter), self.check_context(arc.open(), filter):
4118+
self.expect_file("a/escape", content="decoy")
4119+
if os_helper.can_symlink():
4120+
self.expect_file("a/b/s", symlink_to=os.path.join('..', 'escape'))
4121+
else:
4122+
self.expect_file("a/b/s", content="decoy")
4123+
self.expect_file("s", content="decoy")
4124+
self.assertFalse((self.destdir / "s").is_symlink())
4125+
41084126
@symlink_test
41094127
def test_exfiltration_via_symlink(self):
41104128
# (CVE-2025-4138)
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
Fixed a vulnerability in the :mod:`tarfile` ``data`` and ``tar`` extraction
2+
filters where a crafted archive using a hard link to a symbolic link could
3+
change the permissions and modification time of a file outside the
4+
destination directory, and expose its contents inside the extracted tree.
5+
This addresses :cve:`2026-82049`.

0 commit comments

Comments
 (0)