已开启
fix(cve): 修复 CVE-2026-8643 在 python-pip 中的漏洞 #257
fix(cve): 修复 CVE-2026-8643 在 python-pip 中的漏洞 #257
已开启
infra_team创建于 6月3日
共 2 个文件变更+72-1
@@ -0,0 +1,66 @@
1+From 7f85b4d60f6efc690baf11266650eaba0b1d6c46 Mon Sep 17 00:00:00 2001
2+From: Damian Shaw <damian.peter.shaw@gmail.com>
3+Date: Mon, 18 May 2026 23:04:43 -0400
4+Subject: [PATCH] fix: CVE-2026-8643 - Reject entry point names that escape scripts dir
5+ 
6+Replace _raise_for_invalid_entrypoint with _script_within_dir helper to
7+prevent console_scripts/gui_scripts entry point names with path separators
8+or '..' components from resolving outside the scripts installation directory.
9+ 
10+Upstream-commit: https://github.com/pypa/pip/commit/7f85b4d60f6efc690baf11266650eaba0b1d6c46
11+Signed-off-by: infra_team <zhaiwenjie1@huawei.com>
12+---
13+--- a/src/pip/_internal/operations/install/wheel.py 2026-06-03 09:49:50.771102276 +0800
14++++ b/src/pip/_internal/operations/install/wheel.py 2026-06-03 09:49:50.771102276 +0800
15+@@ -7,7 +7,7 @@
16+ import csv
17+ import importlib
18+ import logging
19+-import os.path
20++import os
21+ import re
22+ import shutil
23+ import sys
24+@@ -415,17 +415,39 @@
25+ )
26+
27+
28+-def _raise_for_invalid_entrypoint(specification: str) -> None:
29++def _script_within_dir(name: str, scripts_dir: str) -> bool:
30++ """Return whether script ``name`` resolves to a path inside the ``scripts_dir``.
31++
32++ distlib joins the entry point name onto the scripts directory, so a name
33++ with path separators or ``..`` components can resolve elsewhere.
34++ """
35++ root = os.path.normpath(scripts_dir)
36++ dest = os.path.normpath(os.path.join(scripts_dir, name))
37++ return dest.startswith(root + os.sep)
38++
39++
40++def _raise_for_invalid_entrypoint(specification: str, scripts_dir: str) -> None:
41+ entry = get_export_entry(specification)
42+- if entry is not None and entry.suffix is None:
43++ if entry is None:
44++ return
45++
46++ if entry.suffix is None:
47+ raise MissingCallableSuffix(str(entry))
48+
49++ if not _script_within_dir(entry.name, scripts_dir):
50++ raise InstallationError(
51++ "Invalid script entry point name {!r}: the script "
52++ "would be installed outside the scripts directory ({}).".format(
53++ entry.name, scripts_dir
54++ )
55++ )
56++
57+
58+ class PipScriptMaker(ScriptMaker):
59+ def make(
60+ self, specification: str, options: Optional[Dict[str, Any]] = None
61+ ) -> List[str]:
62+- _raise_for_invalid_entrypoint(specification)
63++ _raise_for_invalid_entrypoint(specification, self.target_dir)
64+ return super().make(specification, options)
65+
66+
@@ -6,7 +6,7 @@ pip is the package installer for Python. You can use pip to install packages fro
6%global bashcompdir %(b=$(pkg-config --variable=completionsdir bash-completion 2>/dev/null); echo ${b:-%{_sysconfdir}/bash_completion.d})6%global bashcompdir %(b=$(pkg-config --variable=completionsdir bash-completion 2>/dev/null); echo ${b:-%{_sysconfdir}/bash_completion.d})
7Name: python-%{srcname}7Name: python-%{srcname}
8Version: 23.3.18Version: 23.3.1
9-Release: 129+Release: 13
10Summary: A tool for installing and managing Python packages10Summary: A tool for installing and managing Python packages
11License: MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD)11License: MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD)
12URL: http://www.pip-installer.org12URL: http://www.pip-installer.org
@@ -26,6 +26,7 @@ Patch6008: backport-CVE-2026-21441.patch
26Patch6009: backport-CVE-2026-25645.patch26Patch6009: backport-CVE-2026-25645.patch
27Patch6010: backport-CVE-2026-3219.patch27Patch6010: backport-CVE-2026-3219.patch
28Patch6011: backport-CVE-2026-44431.patch28Patch6011: backport-CVE-2026-44431.patch
29+Patch6012: backport-CVE-2026-8643.patch
29 30 
30Source10: pip-allow-older-versions.patch31Source10: pip-allow-older-versions.patch
31 32 
@@ -143,6 +144,10 @@ install -D -m0644 %{SOURCE1} %{buildroot}%{_sysconfdir}/pip.conf
143%{python_wheeldir}/%{python_wheelname}144%{python_wheeldir}/%{python_wheelname}
144 145 
145%changelog146%changelog
147+* Wed Jun 03 2026 infra_team <zhaiwenjie1@huawei.com> - 23.3.1-13
148+- fix CVE: CVE-2026-8643
149+- Backport fix to reject entry point names that escape scripts directory
150+ 
146* Tue Jun 02 2026 Linux_zhang <244695981@qq.com> - 23.3.1-12151* Tue Jun 02 2026 Linux_zhang <244695981@qq.com> - 23.3.1-12
147- fix CVE-2026-44431152- fix CVE-2026-44431
148 153