yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2022-40898
Component Overview
Vulnerability Overview
Name
CVE-2022-40898
Source
NVD (
link
)
Debian (
link
)
Description
An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.
CWEs
CWE-20
Published Date
Dec 23, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/pypa/wheel/blob/main/src/wheel/wheelfile.py#L18
Third Party Advisory
https://pypi.org/project/wheel/
Product
https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/
Exploit
https://github.com/pypa/wheel/blob/main/src/wheel/wheelfile.py#L18
Third Party Advisory
https://pypi.org/project/wheel/
Product
https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/
Exploit
Analysis
#
Affected Component
Analysis
python3-wheel
Patched
Vulnerability Ratings
#
7.5
CVSSv31
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
python3-wheel
yocto
master
0.47.0
Not Affected
python3-wheel
yocto
scarthgap
0.42.0
Not Affected
Resolved with patches
#
python3-wheel (yocto:kirkstone)
#
Title
Author
Resolve
1
Fixed potential DoS attack via WHEEL_INFO_RE
Narpat Mali <narpat.mali@windriver.com>
CVE-2022-40898