CVE-2026-24049

Red Hat Security Advisory: Red Hat AI Inference Server 3.2.2 (CUDA)

Description

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.

Metrics

Severity
high
no public PoC known
7.1
Source: cna-v3
25.2 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
0.3 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-02-27 14:54 UTC
CWE-22, CWE-732

Weakness classes (CWE)

  • CWE-22Base

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

    cwe.mitre.org →
  • CWE-732Class

    Incorrect Permission Assignment for Critical Resource

    The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-09-10 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/24xxx/CVE-2026-24049.json">CVE-2026-24049</a>
  2. CVE Modified2026-09-09 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/24xxx/CVE-2026-24049.json">CVE-2026-24049</a>
  3. CVE Modified2026-09-07 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/24xxx/CVE-2026-24049.json">CVE-2026-24049</a>
  4. CVE Modified2026-09-01 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:61628
  5. CVE Modified2026-08-24 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Discovery 2 for RHEL 10, Discovery 2 for RHEL 8, Discovery 2 for RHEL 9 (+183)Discovery 2 for RHEL 10, Discovery 2 for RHEL 8, Discovery 2 for RHEL 9 (+183)

Affected operating systems

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    ubuntu / gdaltrusty

  • linux

    ubuntu / gdalxenial

  • linux

    ubuntu / golang-go.cryptobionic

  • linux

    ubuntu / golang-go.cryptofocal

  • linux

    ubuntu / golang-go.cryptojammy

  • linux

    ubuntu / golang-go.cryptonoble

  • linux

    ubuntu / golang-go.cryptoquesting

  • linux

    ubuntu / golang-go.cryptoxenial

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • aiohttp

    aiohttp3.13.3

  • anyscale

    ray2.52.0

  • bitnami

    golang1.24.0

  • bitnami

    sqlite

  • Dell

    Secure Connect GatewayAppliance 5.32.00.18

  • go

    github.com/opencontainers/runc1.0.0-rc3

  • go

    github.com/opencontainers/runc1.3.0-rc.1

  • go

    github.com/opencontainers/runc1.4.0-rc.1

  • go

    github.com/sigstore/fulcio

  • go

    golang.org/x/oauth2

  • google

    protobuf33.4

  • IBM

    AIX7.2

  • IBM

    AIX7.3

  • IBM

    Concert< 3.0.0

    fixed in 3.0.0

  • IBM

    DevOps Code ClearCase10.0.1.05

  • IBM

    DevOps Code ClearCase11.0.0.05

  • IBM

    DevOps Code ClearCase9.1.0.10

  • IBM

    MQContainer

  • IBM

    MQOperator

  • IBM

    TXSeriesfor multiplatforms

  • IBM

    VIOS3.1

  • IBM

    VIOS4.1

  • IGEL

    OS11.11.100

  • IGEL

    OS12.7.4

References & sources

Linked CVEs

Show 15 more CVEs
IDCVE-2026-24049