[CLSA-2026:1785232246] alt-python39-setuptools: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-28 09:50:58 UTC
Description:
- CVE-2022-40897: regex denial of service via crafted HTML in package_index - CVE-2024-6345: remote code execution via command injection in VCS download functions - CVE-2025-47273: path traversal in PackageIndex download filename resolution - Fix el7 build so the CVE fixes above can ship there: rpm 4.11 strips backslashes in shell-expansion macro bodies, so the sed capture group in the os_install_post override never matched and python3.9 modules were bytecompiled with the system python2, failing the install step on python3-only syntax; rewrite the sed without a group and stop relying on the interpreter-path macro from alt-python39-devel, whose macros file lives in /usr/lib/rpm/macros.d that rpm 4.11 does not read
Updated packages:
  • alt-python39-setuptools-58.3.0-5.el10.noarch.rpm
    sha:b27b7b3c70d2f6c231b997d8246ec584b318e11f8ae833f73b2f806dd1423595
  • alt-python39-setuptools-wheel-58.3.0-5.el10.noarch.rpm
    sha:df7d13f550b215357d339d8e98ba6e7e4e7c4cebcf8f862c8782fdc4216fcfa0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.