[CLSA-2026:1788439804] alt-python312-pip: Fix of 6 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-03 12:50:20 UTC
Description:
- CVE-2025-8869: symlink targets were not validated in the tarfile extraction fallback used on pythons without pep 706 - CVE-2026-1703: wheel extraction could write files into a sibling directory sharing a name prefix with the install directory - CVE-2026-3219: a file that is both a tar and a zip archive was always treated as a zip, causing archive-type confusion - CVE-2026-6357: the self version-update check ran after wheel install and could import a module planted by a just-installed wheel - CVE-2026-8643: entry point script names were treated as paths, letting scripts be installed outside the scripts directory - CVE-2026-13346: doubly-encoded package URL from an index could write files to arbitrary paths on download
Updated packages:
  • alt-python312-pip-23.3.1-4.el8.noarch.rpm
    sha:e5a0e775a50560afc59857a68aac92c863328c12913f9e647e6abc69645c3aa9
  • alt-python312-pip-wheel-23.3.1-4.el8.noarch.rpm
    sha:9e504793668b1e2db0801ac3aa2f3002a808039c29cc3c1c77e5c8e635828c43
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.