- Package:
- src:python-sh
- Source:
- src:python-sh
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-09-19 11:21:02 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for python-sh. CVE-2026-54552[0]: | sh provides Python process launching. Prior to 2.2.4, the _uid | option in sh.py performs an incomplete privilege drop on Linux and | Unix-like systems. When sh runs from an elevated process and | launches a command with _uid set to an unprivileged user, the child | changes its UID but can retain the parent process's supplementary | groups because the privilege-drop sequence does not fully establish | the target user's UID, primary GID, and supplementary groups. The | child can therefore retain access to files or resources granted to | privileged groups such as root, docker, disk, shadow, or sudo, | violating the expected _uid privilege boundary. This issue is fixed | in version 2.2.4. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-54552 https://www.cve.org/CVERecord?id=CVE-2026-54552 [1] https://github.com/amoffat/sh/security/advisories/GHSA-q38v-wp89-2w55 [2] https://github.com/amoffat/sh/pull/776 [3] https://github.com/amoffat/sh/commit/3d855daba91f87a089b490c0d1cf1df3faace2f1 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of python-sh, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1145886@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Lester Guerzon <lester@guerzon.net> (supplier of updated python-sh package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Sat, 05 Sep 2026 16:01:19 +0800 Source: python-sh Architecture: source Version: 2.4.0-1 Distribution: unstable Urgency: medium Maintainer: Debian Python Team <team+python@tracker.debian.org> Changed-By: Lester Guerzon <lester@guerzon.net> Closes: 1145886 Changes: python-sh (2.4.0-1) unstable; urgency=medium . * Team upload. * New upstream version; fix for CVE-2026-54552 (Closes: #1145886) * d/control: use autopkgtest-pkg-pybuild, compat to 14 * d/control: replace poetry-core with hatchling * d/control: remove explicit deps * d/copyright: add file with different copyright year * d/rules: add fix to prevent core dumps from being packaged * d/example: add example * Minor improvement to d/u/metadata * Rename branch and add gbp.conf Checksums-Sha1: 9521c2d30dec425949763af6db62af16b6933f99 2137 python-sh_2.4.0-1.dsc f2671b70f79bee78d7b6e22620747942555dff89 464236 python-sh_2.4.0.orig.tar.xz 8bebb8039ee91bf7a9d148b8e67cc180acbd06bc 4184 python-sh_2.4.0-1.debian.tar.xz 2a529c4e2691c78eeee6aebceddbbf755a636cfc 6809 python-sh_2.4.0-1_source.buildinfo Checksums-Sha256: 095b87d15f6cb49a421cc1aa6207826246f8a1ecb61403104e4252f8804e2071 2137 python-sh_2.4.0-1.dsc 2d23badbca5105a6fa4f6e81486a99aec1e4e4fdbd3c16ed157b4d1beda0a614 464236 python-sh_2.4.0.orig.tar.xz 538c09c8d42f0bf42a0f63585a29e3beb84dfd0c2a0dbf404c0e5e0b9d602634 4184 python-sh_2.4.0-1.debian.tar.xz bbd896cb7d1a2faa349c04c4a47c7a3f68acc47fdd226165770f278e40c1d55a 6809 python-sh_2.4.0-1_source.buildinfo Files: 7d7aa4504a9ef312780d92e0b4a1cc29 2137 python optional python-sh_2.4.0-1.dsc 9152640d81171b97ba19330fc1e59d07 464236 python optional python-sh_2.4.0.orig.tar.xz fdc7f86baf853baf3b405e6ac8a687f4 4184 python optional python-sh_2.4.0-1.debian.tar.xz 6ab1fd9721c5b0f69e9f083e6bd2e6a3 6809 python optional python-sh_2.4.0-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEj23hBDd/OxHnQXSHMfMURUShdBoFAmqubGoACgkQMfMURUSh dBqlMw//TwIKRirDG/TFLmFV4ALLmDTBMUEn32ptB8ObNGNwkN8BsdBVI+lFjIVm v33ZxrPvW9btZwRzuwnqeOhA8l35VlorImNUAfxi134YBWsAkeRtx5TXTtfgSYvS DRsqivVA07FXwX56BHTF06Rl59ZDDOKerQqm8OBqr39is2oqP8f1Z7lVrfkxbcra SbiuSQu1pL/KC89wnJhyeoIk7L+MkqfRxVj61uGkjjtmKgQ1JyKMag4u2PMP9Gl3 WcBXZHK8j/AgZQBfQaVU2U91IXCoyn0GpDSlS0cVwaUqSczj4tdzil6BQqps7iNv QmWQQ7l4JcVxVZZPN5KQIv6d792e8MWIY4W74JcbQQmPvKgfKx96vrrLlZRfv+AL rH2sqfLVz/4lpBRYpmN+9L6TvpGcljn7yhnjMixPWn8X4n3IaSnujFt0oWvZ96wE N9LARBdhBgTdN0vB3JP0cVtZWE6mobFAn+dxgHORLFjYCY76fwJF7/Hhzm5N0Zio 58XLDX/TjyY28dkJMEcErfkvOvv9FndQY7wXwgCzAUogrdz5z3sU99wRjp3PGGkz YpjBm2tY32SIrg69gW27TYTCoskn+JN+gM4fcYM4BRMheZnS1AACEqW0XXqYxYCL 2EBhvfV5IC/hB2/hG9HPdIop7pol3AcK2eBxjnz7i7uWDjRzc6Q= =IqDI -----END PGP SIGNATURE-----