--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-ce64e86fd8
2026-02-01 00:49:17.189389+00:00
--------------------------------------------------------------------------------

Name        : python-wheel
Product     : Fedora 43
Version     : 0.45.1
Release     : 20.fc43
URL         : https://github.com/pypa/wheel
Summary     : Built-package format for Python
Description :
This is a command line tool for manipulating Python wheel files,
as defined in PEP 427. It contains the following functionality:

- Convert .egg archives into .whl.
- Unpack wheel archives.
- Repack wheel archives.
- Add or remove tags in existing wheel archives.

--------------------------------------------------------------------------------
Update Information:

Security fix for CVE-2026-24049
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jan 23 2026 Miro Hrončok <[email protected]> - 1:0.45.1-20
- Security fix for CVE-2026-24049
* Sat Jan 17 2026 Fedora Release Engineering <[email protected]> - 
1:0.45.1-19
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2432109 - CVE-2026-24049 python-wheel: wheel: Privilege Escalation 
or Arbitrary Code Execution via malicious wheel file unpacking [fedora-43]
        https://bugzilla.redhat.com/show_bug.cgi?id=2432109
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-ce64e86fd8' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

-- 
_______________________________________________
package-announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to