[CLSA-2026:1785335861] Fix CVE(s): CVE-2022-40898
Type:
security
Severity:
Important
Release date:
2026-07-29 14:37:51 UTC
Description:
* SECURITY UPDATE: regex denial of service via crafted wheel filename - debian/patches/CVE-2022-40898.patch: restrict WHEEL_INFO_RE character classes to prevent catastrophic backtracking - CVE-2022-40898
CVEs fixed:
Updated packages:
  • alt-python37-wheel_0.31.1-2_all.deb
    sha:c6c1cf342a7cdf00d70cf5c44801dc34148d60a0
  • alt-python37-wheel-wheel_0.31.1-2_all.deb
    sha:889d3a0224192f5f5839b96412d0c84f5da4db08
  • alt-python37-wheel_0.31.1-2_all.deb
    sha:c6c1cf342a7cdf00d70cf5c44801dc34148d60a0
  • alt-python37-wheel-wheel_0.31.1-2_all.deb
    sha:889d3a0224192f5f5839b96412d0c84f5da4db08
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.