VDB
RHSA-2026%3A6565
RHSA-2026%3A6565
PUBLISHED
CVSS 7.099999904632568 HIGH
A path traversal flaw has been discovered in the python wheel too. The unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts.
Risk Scores
CVSS 3.1
7.099999904632568
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/openshift4/sriov-cni-rhel9@sha256:13f46adc15dee5fa2731d79b79209d4b3eb9b92d9bdf91af3d4fb6c2c27532a4_amd64 as a component of Red Hat OpenShift Container Platform 4.2 | *, registry.redhat.io/openshift4/sriov-cni-rhel9@sha256:13f46adc15dee5fa2731d79b79209d4b3eb9b92d9bdf91af3d4fb6c2c27532a4_amd64, * |
| Red Hat | registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9-operator@sha256:cd48a341d012a6d97fbbd308fb31627b93757a80978d6dd22df610b6bbcc5b49_ppc64le as a component of Red Hat OpenShift Container Platform 4.2 | *, registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9-operator@sha256:cd48a341d012a6d97fbbd308fb31627b93757a80978d6dd22df610b6bbcc5b49_ppc64le, * |
| Red Hat | registry.redhat.io/openshift4/ose-dpu-daemon-rhel9@sha256:313cc95c154746ed81502f49c636e231af07c9c98cef42ccd77c2a28bce195b8_arm64 as a component of Red Hat OpenShift Container Platform 4.2 | *, *, registry.redhat.io/openshift4/ose-dpu-daemon-rhel9@sha256:313cc95c154746ed81502f49c636e231af07c9c98cef42ccd77c2a28bce195b8_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9@sha256:72f0236d53c1241dda739e4c91247c4badc7168483b03fe40d28746b9798ecb7_ppc64le as a component of Red Hat OpenShift Container Platform 4.2 | *, *, registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9@sha256:72f0236d53c1241dda739e4c91247c4badc7168483b03fe40d28746b9798ecb7_ppc64le |
| Red Hat | registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:b705a3866e5324e99b2f11337b82e2a5e45e4145e7c4d5121e10e15901d2ee91_amd64 as a component of Red Hat OpenShift Container Platform 4.2 | *, registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:b705a3866e5324e99b2f11337b82e2a5e45e4145e7c4d5121e10e15901d2ee91_amd64, * |
| Red Hat | registry.redhat.io/openshift4/ose-clusterresourceoverride-rhel9@sha256:7325e5acd633cffac77f94baffabf26475d0f95c557d27867b10f4fd982cac7c_ppc64le as a component of Red Hat OpenShift Container Platform 4.2 | *, registry.redhat.io/openshift4/ose-clusterresourceoverride-rhel9@sha256:7325e5acd633cffac77f94baffabf26475d0f95c557d27867b10f4fd982cac7c_ppc64le, * |
| Red Hat | registry.redhat.io/openshift4/ose-cluster-nfd-rhel9-operator@sha256:5bcbcdfbe01cbca63b6762fd6798b7a14d3dc385832799fa5cfb9fe164406deb_ppc64le as a component of Red Hat OpenShift Container Platform 4.2 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:4678de5a7671204af30f9eb0101b7d64017ef13d8f5f7d6df91e341af068ffed_amd64 as a component of Red Hat OpenShift Container Platform 4.2 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-dp-admission-controller-rhel9@sha256:e74fbec714db4fb05c166be752b0141a9cdb23374a55ab89556bcbce44ce592a_amd64 as a component of Red Hat OpenShift Container Platform 4.2 | registry.redhat.io/openshift4/ose-sriov-dp-admission-controller-rhel9@sha256:e74fbec714db4fb05c166be752b0141a9cdb23374a55ab89556bcbce44ce592a_amd64, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:e40efea9b1dd4e0e699f9da4ae71f6835144dfa424ea46fd3a27655051e069b3_arm64 as a component of Red Hat OpenShift Container Platform 4.2 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-gcp-filestore-csi-driver-rhel9-operator@sha256:0ff7f98574c1414ff8652021caa7503071c0fee27ca39f5f7aa9ff8fb541ea90_amd64 as a component of Red Hat OpenShift Container Platform 4.2 | *, *, registry.redhat.io/openshift4/ose-gcp-filestore-csi-driver-rhel9-operator@sha256:0ff7f98574c1414ff8652021caa7503071c0fee27ca39f5f7aa9ff8fb541ea90_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-local-storage-rhel9-operator@sha256:3b69318db2803d99e0ff47212a91406cc55e12127a183921b1202b5c2c16f370_s390x as a component of Red Hat OpenShift Container Platform 4.2 | *, *, registry.redhat.io/openshift4/ose-local-storage-rhel9-operator@sha256:3b69318db2803d99e0ff47212a91406cc55e12127a183921b1202b5c2c16f370_s390x |
| Red Hat | registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:51555ddddc967cfbcd08ed51c16ae2c91039c697f9d3a5b76247fcfe6b68392e_arm64 as a component of Red Hat OpenShift Container Platform 4.2 | *, registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:51555ddddc967cfbcd08ed51c16ae2c91039c697f9d3a5b76247fcfe6b68392e_arm64, * |
| Red Hat | registry.redhat.io/openshift4/ose-local-storage-rhel9-operator@sha256:200d97c395e80ee8cfb7c2e30c237ddfdf6369642ac3dc8f5ddb33e700c244d6_arm64 as a component of Red Hat OpenShift Container Platform 4.2 | *, registry.redhat.io/openshift4/ose-local-storage-rhel9-operator@sha256:200d97c395e80ee8cfb7c2e30c237ddfdf6369642ac3dc8f5ddb33e700c244d6_arm64, * |
| Red Hat | registry.redhat.io/openshift4/ose-secrets-store-csi-driver-rhel9-operator@sha256:6e2a5eb540fe6b40447140d3dd6858e43879f2daa25684d57307bd1dfe6f4a89_ppc64le as a component of Red Hat OpenShift Container Platform 4.2 | *, *, registry.redhat.io/openshift4/ose-secrets-store-csi-driver-rhel9-operator@sha256:6e2a5eb540fe6b40447140d3dd6858e43879f2daa25684d57307bd1dfe6f4a89_ppc64le |
| Red Hat | registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:d29a2ef03939ed893ce5a60cbf1ac8a3508c9207d248d0ef9ff5aa24da60278b_s390x as a component of Red Hat OpenShift Container Platform 4.2 | registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:d29a2ef03939ed893ce5a60cbf1ac8a3508c9207d248d0ef9ff5aa24da60278b_s390x, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-network-rhel9-operator@sha256:8e2a66f405f4acbe7236fa7cc9314faeef2d2f8aff1b3e6c548ba27c2ba7b87f_amd64 as a component of Red Hat OpenShift Container Platform 4.2 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9@sha256:1ae942b49bcd7370390fb7182d03c9295d40abe15bafd91aedcc669d753aacdc_amd64 as a component of Red Hat OpenShift Container Platform 4.2 | *, *, registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9@sha256:1ae942b49bcd7370390fb7182d03c9295d40abe15bafd91aedcc669d753aacdc_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-infiniband-cni-rhel9@sha256:81b44e5761ee7a3d68f42661f108245ba46b81ac5504722ae8430cfef9263b32_ppc64le as a component of Red Hat OpenShift Container Platform 4.2 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:a585c5250936744601288328554ec9dd5fd69ebb0d9f628328cc72ba3c3bf4f2_amd64 as a component of Red Hat OpenShift Container Platform 4.2 | registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:a585c5250936744601288328554ec9dd5fd69ebb0d9f628328cc72ba3c3bf4f2_amd64, *, * |
…and 158 more
Timeline
- Apr 9, 2026 CVE Published
- May 5, 2026 Distribution Patch
- May 5, 2026 Distribution Patch
- May 5, 2026 Security Advisory
- May 5, 2026 Security Advisory
- Jul 26, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2026:6565 advisory
- https://access.redhat.com/security/cve/CVE-2026-24049 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_6565.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2431959 issue
- https://www.cve.org/CVERecord?id=CVE-2026-24049 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-24049 advisory
- https://github.com/pypa/wheel/commit/7a7d2de96b22a9adf9208afcc9547e1001569fef advisory
- https://github.com/pypa/wheel/releases/tag/0.46.2 advisory
- https://github.com/pypa/wheel/security/advisories/GHSA-8rrh-rw8j-w5fx advisory