|
|
Log in / Subscribe / Register

Ubuntu alert USN-8221-1 (wheel)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8221-1] wheel vulnerability
Date:  Wed, 29 Apr 2026 06:18:51 +0000
Message-ID:  <E1wHyG3-0005yu-Ug@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-8221-1 April 29, 2026 wheel vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: wheel could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - wheel: Command line tool for manipulating Python wheel files Details: It was discovered that wheel did not correctly handle certain file paths. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS python-wheel-common 0.42.0-2ubuntu0.1~esm1 Available with Ubuntu Pro python3-wheel 0.42.0-2ubuntu0.1~esm1 Available with Ubuntu Pro python3-wheel-whl 0.42.0-2ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8221-1 CVE-2026-24049


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmnxoe4ACgkQcpJm3tlz hgEP9BAAsD39J2jUKbvtXKr9FaTM3khO+sPc0hQBUv2nakjcUXVtQNFsa/00CewO 9ZQkCxR9aX678rgG3lavqqxvHzYItB4fdS2p+ygw+vT4156aE+3rbnjZtKzIH5xm 1TZFdBl9+aAkosaU2RubkzSQL+lBWXrF4H9OsHNd5s118eO1oUZTRwbiC2kFuvVA vZmh1/Lp6xx8NbxdcNh3dMql6Q1SC6Yll75gddfNae+hQp40yG6G9GK/WNaTpH7I qFDTyKRlfDXRK+WxDRR0iomDtMBp7AXmJylfEsJBsgJi17jEKchfreiarR3jdGKX 3I6Aaj4SOKUd4ZS/DSXVkA1dsco5XG2PBQgFIS4LroggSPZQkH923/Ez6lMhHSSY 1P7nHfOLgK00bTa7Ikjy2yl1xIW5Izlc8ZEeY4uuicDqZXImBjeQhHrYmiMSh4CE P4ukzS+aG/2igSbMPbNakqpz2rVND0fdaK9/1XVCQEYmc9Xm7e7JWLEh9a3xlq4N aBd5dZHaWVCrN6tGSHmdOoZeXmR0+zCNfq7KiqXyCYVOdeD+JuwzEYdLw6zz1CIZ nuAtlyxVhTYhvqF+o6iXYAqAZqk7q/V2kjbdu6/X2elx03hQyQQXLXc9P0Kn0Dtu HJ+u//NtWzaHlnRIKQoy4gZ8+Ff46DJbAPAlfxoyXDGKkGKlu9A= =ST5B -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds