[CLSA-2026:1785234014] Fix CVE(s): CVE-2022-40898
Type:
security
Severity:
Important
Release date:
2026-07-28 10:20:25 UTC
Description:
* SECURITY UPDATE: regex denial of service via crafted wheel filename - debian/patches/CVE-2022-40898.patch: restrict WHEEL_INFO_RE character classes to prevent catastrophic backtracking - CVE-2022-40898
CVEs fixed:
Updated packages:
  • alt-python38-wheel_0.37.1-3_all.deb
    sha:c43111f68decf50aa02b2cdd0fce6d01e082c838
  • alt-python38-wheel-wheel_0.37.1-3_all.deb
    sha:6bfa36978a5199ef0664c8ba312e275a0e9e89dd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.