|
|
Log in / Subscribe / Register

Ubuntu alert USN-8344-3 (python-pip)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8344-3] pip vulnerability
Date:  Wed, 03 Jun 2026 14:26:31 +0000
Message-ID:  <E1wUmYB-0000yl-7g@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8344-3 June 03, 2026 python-pip vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: A regression was fixed in pip. Software Description: - python-pip: Python package installer Details: USN-8344-1 introduced a regression in pip. This update provides a complete fix for this issue.. We apologize for the inconvenience. Original advisory details: It was discovered that pip's bundled urllib3 library improperly handled streaming decompression of highly compressed data. A remote attacker could possibly use this issue to cause pip to consume excessive resources, leading to a denial of service. (CVE-2025-66471) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS python3-pip 25.1.1+dfsg-1ubuntu2+esm3 Available with Ubuntu Pro python3-pip-whl 25.1.1+dfsg-1ubuntu2+esm3 Available with Ubuntu Pro Ubuntu 24.04 LTS python3-pip 24.0+dfsg-1ubuntu1.3+esm3 Available with Ubuntu Pro python3-pip-whl 24.0+dfsg-1ubuntu1.3+esm3 Available with Ubuntu Pro Ubuntu 22.04 LTS python3-pip 22.0.2+dfsg-1ubuntu0.7+esm3 Available with Ubuntu Pro python3-pip-whl 22.0.2+dfsg-1ubuntu0.7+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8344-3 https://ubuntu.com/security/notices/USN-8344-2 https://ubuntu.com/security/notices/USN-8344-1 CVE-2025-66471


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmogNroACgkQcpJm3tlz hgGrERAAhe5p0L7umQ+I2S2gUBl5MgSBrXtowLc822lctMb2FXtYZRhQZuWQrEYV jZRzZ+MOdcW/IxjAgoEVlvcf6C6nA9t/EwL2fp6Hj/GWeoaLCwBoiUyvKiA6yoqE KcULLBl0qLguazQmIHxxJerTn5bdjhKr3+VS2VOQQm67RcqeS1bniVKwLNxU6wol aalIU9MTJOkySaU0OHuHIMq2FsD5XrnvgTTAIp/ixDD4eKqLt4ulbuItJNXVDv0X blrLvRrRJ9iYDO4VNCIRswy+7U4LFjv5BPff766/YIIW+luLIvXZ5QkvUR20XDE+ jpc67WuGFjttwrbmS6ei67iK1FUwxzyX/1mIRD1tPRZ1F6O7S/ddk3LeOGgHHJgb GFwLnW4ZpyDYyPGvsAl7r5O0N/79qbfBo6x5BiWAGATCNzupzrU7atIl29w21QnL 28Q84ImOP4LHZ3xLSMuAtMXH7+1ezdFwp/F5zBrDWHRtJ+6Lx5wSu+UvGJ45ZGsH DiREPfJWIAMSk/EhEavPtuATdGUgmdOhE78XC6e477S3DFNo7DNNMeKveH3LsRRW 18OqLN+8LFNJB2lZS5DoTheodV0q2XI5uy7LjBD29ZjEOiFlbGgDsxMJ8Ze3y6/i qPu4Ee87j0nfnxcE6OOIgZ/A9CKo3x1gdC3o3jyB5fnHH6O78tU= =+uHm -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds