Release date:
2026-09-11 09:50:27 UTC
Description:
* SECURITY UPDATE: MANIFEST.in exclusion bypass via Unicode normalization
- debian/patches/CVE-2026-59890.patch: normalize both the MANIFEST.in
pattern and the walked path to NFC before matching, via a new
unicode_utils.normalize() helper and a _NormalizedMatcher wrapper in
translate_pattern(), so an exclude/global-exclude/recursive-exclude/
prune rule can no longer be bypassed by an NFC/NFD mismatch and leak
the excluded file into the source distribution (CWE-176/CWE-697).
- CVE-2026-59890
Updated packages:
-
alt-python313-setuptools_69.0.2-4_all.deb
sha:ee9a860271c0f6bb76c97ec1a2fcb3fdae1931ce
-
alt-python313-setuptools-wheel_69.0.2-4_all.deb
sha:3e4ee3a3edcb1293c10bf2849d6bdd3608759c41
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.