Release date:
2026-07-28 10:57:03 UTC
Description:
- CVE-2022-40897: regex denial of service via crafted HTML in package_index
- CVE-2024-6345: remote code execution via command injection in VCS download functions
- CVE-2025-47273: path traversal in PackageIndex download filename resolution
- Fix el7 build so the CVE fixes above can ship there: rpm 4.11 strips
backslashes in shell-expansion macro bodies, so the sed capture
group in the os_install_post override never matched and python3.9
modules were bytecompiled with the system python2, failing the
install step on python3-only syntax; rewrite the sed without a
group and stop relying on the interpreter-path macro from
alt-python39-devel, whose macros file lives in /usr/lib/rpm/macros.d
that rpm 4.11 does not read
Updated packages:
-
alt-python39-setuptools-58.3.0-5.el8.noarch.rpm
sha:1575d4f7264e2fbed2823e1e79446de9cf7cb6e74ac9b3ce62f834dceae03ed0
-
alt-python39-setuptools-wheel-58.3.0-5.el8.noarch.rpm
sha:b6b5677956b6c8eb7a8093048532908b8c5fbd53e6e0b8d32971dd58d1344510
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.