Описание
Security update for python-pip
This update for python-pip fixes the following issue
- CVE-2026-8643: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite (bsc#1266669).
Список пакетов
openSUSE Leap 16.0
python313-pip-25.0.1-160000.5.1
python313-pip-wheel-25.0.1-160000.5.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1266669
- SUSE CVE CVE-2026-8643 page
Описание
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
Затронутые продукты
openSUSE Leap 16.0:python313-pip-25.0.1-160000.5.1
openSUSE Leap 16.0:python313-pip-wheel-25.0.1-160000.5.1
Ссылки
- CVE-2026-8643
- SUSE Bug 1266669