HomeDefectsLIN1025-7839
Fixed

LIN1025-7839 : Security Advisory - python3-pip - CVE-2026-1703

Created: Feb 2, 2026    Updated: Aug 31, 2026
Resolved Date: Aug 31, 2026
Found In Version: 10.25.33.2
Fix Version: 10.25.33.11
Severity: Standard
Applicable for: Wind River Linux LTS 25
Component/s: Userspace

Description

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

CVEs