VYPR

rpm package

opensuse/python-sh&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/python-sh&distro=openSUSE%20Leap%2016.0

Vulnerabilities (1)

  • CVE-2026-54552HigAug 18, 2026
    affected < 2.2.2-160000.3.1fixed 2.2.2-160000.3.1

    sh provides Python process launching. Prior to 2.2.4, the _uid option in sh.py performs an incomplete privilege drop on Linux and Unix-like systems. When sh runs from an elevated process and launches a command with _uid set to an unprivileged user, the child changes its UID but c