已开启
fix(cve): 修复 CVE-2026-8643 在 python-pip 中的漏洞 #257
infra_team创建于 6月3日
fix(cve): 修复 CVE-2026-8643 在 python-pip 中的漏洞 #257
已开启
共 2 个文件变更+72-1
| @@ -0,0 +1,66 @@ | |||
| 1 | +From 7f85b4d60f6efc690baf11266650eaba0b1d6c46 Mon Sep 17 00:00:00 2001 | ||
| 2 | +From: Damian Shaw <damian.peter.shaw@gmail.com> | ||
| 3 | +Date: Mon, 18 May 2026 23:04:43 -0400 | ||
| 4 | +Subject: [PATCH] fix: CVE-2026-8643 - Reject entry point names that escape scripts dir | ||
| 5 | + | ||
| 6 | +Replace _raise_for_invalid_entrypoint with _script_within_dir helper to | ||
| 7 | +prevent console_scripts/gui_scripts entry point names with path separators | ||
| 8 | +or '..' components from resolving outside the scripts installation directory. | ||
| 9 | + | ||
| 10 | +Upstream-commit: https://github.com/pypa/pip/commit/7f85b4d60f6efc690baf11266650eaba0b1d6c46 | ||
| 11 | +Signed-off-by: infra_team <zhaiwenjie1@huawei.com> | ||
| 12 | +--- | ||
| 13 | +--- a/src/pip/_internal/operations/install/wheel.py 2026-06-03 09:49:50.771102276 +0800 | ||
| 14 | ++++ b/src/pip/_internal/operations/install/wheel.py 2026-06-03 09:49:50.771102276 +0800 | ||
| 15 | + | ||
| 16 | + import csv | ||
| 17 | + import importlib | ||
| 18 | + import logging | ||
| 19 | +-import os.path | ||
| 20 | ++import os | ||
| 21 | + import re | ||
| 22 | + import shutil | ||
| 23 | + import sys | ||
| 24 | + | ||
| 25 | + ) | ||
| 26 | + | ||
| 27 | + | ||
| 28 | +-def _raise_for_invalid_entrypoint(specification: str) -> None: | ||
| 29 | ++def _script_within_dir(name: str, scripts_dir: str) -> bool: | ||
| 30 | ++ """Return whether script ``name`` resolves to a path inside the ``scripts_dir``. | ||
| 31 | ++ | ||
| 32 | ++ distlib joins the entry point name onto the scripts directory, so a name | ||
| 33 | ++ with path separators or ``..`` components can resolve elsewhere. | ||
| 34 | ++ """ | ||
| 35 | ++ root = os.path.normpath(scripts_dir) | ||
| 36 | ++ dest = os.path.normpath(os.path.join(scripts_dir, name)) | ||
| 37 | ++ return dest.startswith(root + os.sep) | ||
| 38 | ++ | ||
| 39 | ++ | ||
| 40 | ++def _raise_for_invalid_entrypoint(specification: str, scripts_dir: str) -> None: | ||
| 41 | + entry = get_export_entry(specification) | ||
| 42 | +- if entry is not None and entry.suffix is None: | ||
| 43 | ++ if entry is None: | ||
| 44 | ++ return | ||
| 45 | ++ | ||
| 46 | ++ if entry.suffix is None: | ||
| 47 | + raise MissingCallableSuffix(str(entry)) | ||
| 48 | + | ||
| 49 | ++ if not _script_within_dir(entry.name, scripts_dir): | ||
| 50 | ++ raise InstallationError( | ||
| 51 | ++ "Invalid script entry point name {!r}: the script " | ||
| 52 | ++ "would be installed outside the scripts directory ({}).".format( | ||
| 53 | ++ entry.name, scripts_dir | ||
| 54 | ++ ) | ||
| 55 | ++ ) | ||
| 56 | ++ | ||
| 57 | + | ||
| 58 | + class PipScriptMaker(ScriptMaker): | ||
| 59 | + def make( | ||
| 60 | + self, specification: str, options: Optional[Dict[str, Any]] = None | ||
| 61 | + ) -> List[str]: | ||
| 62 | +- _raise_for_invalid_entrypoint(specification) | ||
| 63 | ++ _raise_for_invalid_entrypoint(specification, self.target_dir) | ||
| 64 | + return super().make(specification, options) | ||
| 65 | + | ||
| 66 | + | ||
| @@ -6,7 +6,7 @@ pip is the package installer for Python. You can use pip to install packages fro | |||
| 6 | %global bashcompdir %(b=$(pkg-config --variable=completionsdir bash-completion 2>/dev/null); echo ${b:-%{_sysconfdir}/bash_completion.d}) | 6 | %global bashcompdir %(b=$(pkg-config --variable=completionsdir bash-completion 2>/dev/null); echo ${b:-%{_sysconfdir}/bash_completion.d}) |
| 7 | Name: python-%{srcname} | 7 | Name: python-%{srcname} |
| 8 | Version: 23.3.1 | 8 | Version: 23.3.1 |
| 9 | -Release: 12 | 9 | +Release: 13 |
| 10 | Summary: A tool for installing and managing Python packages | 10 | Summary: A tool for installing and managing Python packages |
| 11 | License: MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD) | 11 | License: MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD) |
| 12 | URL: http://www.pip-installer.org | 12 | URL: http://www.pip-installer.org |
| @@ -26,6 +26,7 @@ Patch6008: backport-CVE-2026-21441.patch | |||
| 26 | Patch6009: backport-CVE-2026-25645.patch | 26 | Patch6009: backport-CVE-2026-25645.patch |
| 27 | Patch6010: backport-CVE-2026-3219.patch | 27 | Patch6010: backport-CVE-2026-3219.patch |
| 28 | Patch6011: backport-CVE-2026-44431.patch | 28 | Patch6011: backport-CVE-2026-44431.patch |
| 29 | +Patch6012: backport-CVE-2026-8643.patch | ||
| 29 | 30 | ||
| 30 | Source10: pip-allow-older-versions.patch | 31 | Source10: pip-allow-older-versions.patch |
| 31 | 32 | ||
| @@ -143,6 +144,10 @@ install -D -m0644 %{SOURCE1} %{buildroot}%{_sysconfdir}/pip.conf | |||
| 143 | %{python_wheeldir}/%{python_wheelname} | 144 | %{python_wheeldir}/%{python_wheelname} |
| 144 | 145 | ||
| 145 | %changelog | 146 | %changelog |
| 147 | +* Wed Jun 03 2026 infra_team <zhaiwenjie1@huawei.com> - 23.3.1-13 | ||
| 148 | +- fix CVE: CVE-2026-8643 | ||
| 149 | +- Backport fix to reject entry point names that escape scripts directory | ||
| 150 | + | ||
| 146 | * Tue Jun 02 2026 Linux_zhang <244695981@qq.com> - 23.3.1-12 | 151 | * Tue Jun 02 2026 Linux_zhang <244695981@qq.com> - 23.3.1-12 |
| 147 | - fix CVE-2026-44431 | 152 | - fix CVE-2026-44431 |
| 148 | 153 | ||