-
Notifications
You must be signed in to change notification settings - Fork 44
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Vulnerable shared libraries might make skia-python vulnerable. Can you help upgrade to patch versions? #175
Comments
@andy201709 skia-python bundles those shared libraries via |
@kyamagu , thank you for your feedback. |
Manylinux2014 End of Life (EOL) on June 30th, 2024; so we have to switch upwards in the next 8 months. This should close when we switch. |
There is a new manylinux on 2024.07.02. (and m128/m130 has been using that for a couple of releases) This is due a revisit. |
Seems the current m132 build is still against |
That said, the middle CVE said it is not exploitable on glibc system, and we ONLY do glibc systems (until / unless anybody works on #172 , I guess). And I am not sure about the other two - util-linux is a big package, I am not sure libuuid is involved in umount (the first) or removable dos media (last). |
See also improving #257 as an alternative to many linux wheels |
Hi, @kyamagu , @jljusten , I'd like to report a vulnerability issue in skia-python_87.4.
Dependency Graph between Python and Shared Libraries
Issue Description
As shown in the above dependency graph, skia-python_87.4 directly or transitively depends on 4 C libraries (.so). However, I noticed that one C library is vulnerable, containing the following CVEs:
libuuid-f64cda11.so.1.3.0
from C project util-linux(version:2.27.1) exposed 3 vulnerabilities:CVE-2018-7738, CVE-2021-37600, CVE-2016-5011
Suggested Vulnerability Patch Versions
util-linux has fixed the vulnerabilities in versions >=2.37.2
Python build tools cannot report vulnerable C libraries, which may induce potential security issues to many downstream Python projects.
As a popular python package (skia-python has 8,051 downloads per month), could you please upgrade the above shared libraries to their patch versions?
Thanks for your help~
Best regards,
Andy
The text was updated successfully, but these errors were encountered: