|
|
Log in / Subscribe / Register

Ubuntu alert USN-8344-1 (python-pip)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8344-1] pip vulnerabilities
Date:  Thu, 28 May 2026 20:05:44 +0000
Message-ID:  <E1wSgzA-0005oP-P6@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-8344-1 May 28, 2026 python-pip vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in pip. Software Description: - python-pip: Python package installer Details: It was discovered that pip incorrectly handled TLS certificate verification in session connections. If a session was first used with certificate verification disabled, subsequent requests to the same host would also skip verification regardless of the session's current settings. A remote attacker could possibly use this issue to perform a machine-in-the-middle attack and expose sensitive information. (CVE-2024-35195) It was discovered that pip's bundled urllib3 library did not limit the number of decompression steps when processing HTTP responses. A remote attacker could possibly use this issue to cause pip to consume excessive resources, leading to a denial of service. (CVE-2025-66418) It was discovered that pip's bundled urllib3 library improperly handled streaming decompression of highly compressed data. A remote attacker could possibly use this issue to cause pip to consume excessive resources, leading to a denial of service. (CVE-2025-66471) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS python3-pip 25.1.1+dfsg-1ubuntu2+esm1 Available with Ubuntu Pro python3-pip-whl 25.1.1+dfsg-1ubuntu2+esm1 Available with Ubuntu Pro Ubuntu 24.04 LTS python3-pip 24.0+dfsg-1ubuntu1.3+esm1 Available with Ubuntu Pro python3-pip-whl 24.0+dfsg-1ubuntu1.3+esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS python3-pip 22.0.2+dfsg-1ubuntu0.7+esm1 Available with Ubuntu Pro python3-pip-whl 22.0.2+dfsg-1ubuntu0.7+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8344-1 CVE-2024-35195, CVE-2025-66418, CVE-2025-66471


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmoYntkACgkQcpJm3tlz hgFD3xAAl4cls8Rstqlneo/RQIECTojDjXmcUGJVYxpavem41IPzIdSvatCL69Mj k4I3PHHFKRRDyGEkLpbUxr0lrTJ+ELgRHIR/gezg4UuUvU4MwjD+D9eiV4ADSoaq V+DWIUyJqC97QRWN9W5II2Kf3FXyqe/1M0apkm9yUIwIDb7NUOTQQDROHDaFt/zk k3s+xjB5e27iluIzd/lIGOH3AOggG3yZTxlNhtQt8DcLdrH1IHeK0MDbVHwipj2h g8K9BcNbPpq8gIBHcsOX28JADO1x2lM8buAk1B4QRW158eIHQVYOziTDjfEjM+v7 vIZMFw/Mkici6LITouPkdjYvUFZTU1hRpStfra+PvD6V5FVW2Epn7jZ4sxhAfmKN B7WXct5f26r+/OsDpVo6Bbm/5pjA4F7q4dnXPNhmPk2uHtBU0zRYjiF2bvn+t7tL uTmOnhgGZYZJuTAtPH/Amf57DJIxHs/CmiPXj3GnT6FKu4C0eKPPJgG755qH7N+w VT1f7uB4USKMhKcp18iBtKM+OvqsqWtfXszNyYHl/7+kA4CqhgNX/UdzrWhjH378 lOrCqfC0RoaINWg7+f9bNEURhxryhyz3N/nzRjF6qWCe8KzsFY5NQHE3tk4hKzwa 4R/ji72wcmxq3a67lvJmZlq8CL0o2TP7E5k/F2v/PvauHZnbEh0= =EDyS -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds