[CLSA-2026:1787932999] Fix CVE(s): CVE-2022-40898
Type:
security
Severity:
Important
Release date:
2026-08-28 17:38:24 UTC
Description:
* SECURITY UPDATE: denial of service via attacker-controlled wheel filename (ReDoS in WHEEL_INFO_RE) - debian/patches/CVE-2022-40898.patch: bound the unbounded regex spans in wheel/install.py so they cannot cross the "-" delimiter. - CVE-2022-40898
CVEs fixed:
Updated packages:
  • alt-python27-wheel_0.29.0-8_all.deb
    sha:84674bb8ed2029c83f66c3d5f29cfb275ee5844b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.