Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-25820

python-pip missing tarfile extract mitigation

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • rhel-10.0.beta
    • rhel-10.0.beta, rhel-10.0
    • python-pip
    • None
    • python-pip-23.3.2-2.el10
    • None
    • Low
    • sst_cs_apps
    • ssg_core_services
    • 10
    • 22
    • 5
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • All
    • None

      RHEL's pip was patched to mitigate malicious tarfile extract, but Fedora's pip was not patched. Upstream has not yet merged https://github.com/pypa/pip/pull/12214 when c10s was forked (and still hasn't now).

      tl;dr the pip in RHEL 10.0 will have a regression compared to RHEL 9.x unless we add the patch donwstream.

      To reproduce, run https://bugzilla.redhat.com/show_bug.cgi?id=2218247#c2

            python-maint python-maint
            mhroncok@redhat.com Miro HronĨok
            Charalampos Stratakis Charalampos Stratakis
            Lukas Zachar Lukas Zachar
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated: