Source: python-sh
Version: 2.2.1-2
Severity: important
Tags: security upstream
Forwarded: https://github.com/amoffat/sh/pull/776
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for python-sh.

CVE-2026-54552[0]:
| sh provides Python process launching. Prior to 2.2.4, the _uid
| option in sh.py performs an incomplete privilege drop on Linux and
| Unix-like systems. When sh runs from an elevated process and
| launches a command with _uid set to an unprivileged user, the child
| changes its UID but can retain the parent process's supplementary
| groups because the privilege-drop sequence does not fully establish
| the target user's UID, primary GID, and supplementary groups. The
| child can therefore retain access to files or resources granted to
| privileged groups such as root, docker, disk, shadow, or sudo,
| violating the expected _uid privilege boundary. This issue is fixed
| in version 2.2.4.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-54552
    https://www.cve.org/CVERecord?id=CVE-2026-54552
[1] https://github.com/amoffat/sh/security/advisories/GHSA-q38v-wp89-2w55
[2] https://github.com/amoffat/sh/pull/776
[3] 
https://github.com/amoffat/sh/commit/3d855daba91f87a089b490c0d1cf1df3faace2f1

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to