Skip to content

[RHOAI 3.4] CVE-2026-102930, CVE-2026-102925: bump virtualenv 21.7.11 → 21.7.13 in py312-rocm64-torch280 - #1083

Merged
sutaakar merged 1 commit into
red-hat-data-services:rhoai-3.4from
redhat-chai-bot:cve-virtualenv-21.7.13-rhoai-3.4
Oct 2, 2026
Merged

sutaakar merged 1 commit into
red-hat-data-services:rhoai-3.4from
redhat-chai-bot:cve-virtualenv-21.7.13-rhoai-3.4

Conversation

@redhat-chai-bot

Copy link
Copy Markdown

Bumps virtualenv from 21.7.11 to 21.7.13 in images/runtime/training/py312-rocm64-torch280/Pipfile.lock to fix:

  • CVE-2026-102930 — Arbitrary code execution via unverified downloaded seed wheels (fix: ≥21.7.12)
  • CVE-2026-102925 — Arbitrary code execution via crafted paths in activation scripts (fix: ≥21.7.13)

Related Jira tickets


AI-generated. Review for accuracy.

@sutaakar requested from Slack

…n py312-rocm64-torch280

Bumps virtualenv from 21.7.11 to 21.7.13 to address:
- CVE-2026-102930 (RHAI-3861): unverified seed wheels (fixed in ≥21.7.12)
- CVE-2026-102925 (RHAI-3836): crafted activation script paths (fixed in ≥21.7.13)

Signed-off-by: redhat-chai-bot <redhat-chai-bot@users.noreply.github.com>
@sutaakar
sutaakar merged commit 8ee44eb into red-hat-data-services:rhoai-3.4 Oct 2, 2026
4 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants