ALAS2-2025-2876


Amazon Linux 2 Security Advisory: ALAS2-2025-2876
Advisory Released Date: 2025-06-12
Advisory Updated Date: 2025-06-12
Severity: Important

Issue Overview:

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue. (CVE-2025-47273)


Affected Packages:

python-setuptools


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update python-setuptools to update your system.

New Packages:
noarch:
    python3-setuptools-49.1.3-1.amzn2.0.6.noarch
    python-setuptools-wheel-49.1.3-1.amzn2.0.6.noarch

src:
    python-setuptools-49.1.3-1.amzn2.0.6.src