Bug 2158559 (CVE-2022-40897)

Summary: CVE-2022-40897 pypa-setuptools: Regular Expression Denial of Service (ReDoS) in package_index.py
Product: [Other] Security Response Reporter: Chess Hazlett <chazlett>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: bbuckingham, bcoca, bcourt, bdettelb, btotty, cstratak, davidn, dfreiber, eglynn, ehelms, epacific, gtanzill, hhorak, jb2592, jburrell, jcammara, jhardy, jjoyce, jneedle, jobarker, jorton, jsherril, lhh, lmadsen, lzap, mabashia, mburns, mgarciac, mhulan, mminar, mrunge, myarboro, nboldt, nmoumoul, orabin, osapryki, pcreech, python-maint, rbiba, rchan, rogbas, rpalathi, saroy, scorneli, security-response-team, simaishi, smcdonal, spower, sskracic, teagle, vkumar, yguenane, zsadeh
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in Python Setuptools due to a regular expression Denial of Service (ReDoS) present in package_index.py. This issue could allow a remote attacker to cause a denial of service via HTML in a crafted package or custom PackageIndex page.
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-02-28 12:16:10 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2158677, 2158679, 2158680, 2158681, 2158682, 2158683, 2159296, 2159297, 2159298, 2188149    
Bug Blocks: 2158555    

Description Chess Hazlett 2023-01-05 18:14:45 UTC
Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.

Comment 1 Sandipan Roy 2023-01-06 04:19:37 UTC
Created python-setuptools tracking bugs for this issue:

Affects: fedora-all [bug 2158677]

Comment 12 errata-xmlrpc 2023-02-21 09:22:21 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2023:0835 https://access.redhat.com/errata/RHSA-2023:0835

Comment 13 errata-xmlrpc 2023-02-28 08:18:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2023:0952 https://access.redhat.com/errata/RHSA-2023:0952

Comment 14 Product Security DevOps Team 2023-02-28 12:16:05 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2022-40897

Comment 19 errata-xmlrpc 2023-11-08 08:17:08 UTC
This issue has been addressed in the following products:

  Red Hat Software Collections for Red Hat Enterprise Linux 7

Via RHSA-2023:6793 https://access.redhat.com/errata/RHSA-2023:6793

Comment 20 errata-xmlrpc 2023-11-21 11:40:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Extended Update Support

Via RHSA-2023:7395 https://access.redhat.com/errata/RHSA-2023:7395

Comment 23 errata-xmlrpc 2024-05-22 09:26:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2024:2985 https://access.redhat.com/errata/RHSA-2024:2985

Comment 24 errata-xmlrpc 2024-05-22 09:26:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2024:2987 https://access.redhat.com/errata/RHSA-2024:2987

Comment 25 errata-xmlrpc 2024-07-09 10:41:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Extended Update Support

Via RHSA-2024:4421 https://access.redhat.com/errata/RHSA-2024:4421

Comment 26 errata-xmlrpc 2024-09-23 01:47:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2024:6915 https://access.redhat.com/errata/RHSA-2024:6915