[CLSA-2026:1787663936] python2: Fix of CVE-2026-0864
Type:
security
Severity:
Important
Release date:
2026-08-25 13:19:07 UTC
Description:
- CVE-2026-0864: normalize CR and CRLF line endings to LF plus tab continuation when ConfigParser writes multi-line values, so a carriage return inside an attacker-controlled value can no longer inject extra keys and values into the written configuration file
CVEs fixed:
Updated packages:
  • python2-2.7.18-7.module_el8.5.0+2507+560ae92e.tuxcare.els26.x86_64.rpm
    sha:5862766208ed267b386143b91d3c743af1165c695b48232a13a9c7c77403e6c6
  • python2-debug-2.7.18-7.module_el8.5.0+2507+560ae92e.tuxcare.els26.x86_64.rpm
    sha:133d5d39ff69819bd6bcf07c7fd4c1064b624dca6f189ec1e9f3219b3e6a22a6
  • python2-devel-2.7.18-7.module_el8.5.0+2507+560ae92e.tuxcare.els26.x86_64.rpm
    sha:6e083d1e82d3d62f577d385f2f3874da07238c2de07a0829964a9c8171b609ac
  • python2-libs-2.7.18-7.module_el8.5.0+2507+560ae92e.tuxcare.els26.x86_64.rpm
    sha:d27a9267a9e34450ef5d83f86b90559937276a06a5f4d65c95946757faa43fa3
  • python2-test-2.7.18-7.module_el8.5.0+2507+560ae92e.tuxcare.els26.x86_64.rpm
    sha:8969785dbb09ab07f1a5d1c5d163bd05fdc830090c4206d8e0340c4429f3b64e
  • python2-tkinter-2.7.18-7.module_el8.5.0+2507+560ae92e.tuxcare.els26.x86_64.rpm
    sha:803a54a402acce08e56c77ab7ed185552f00ab8774d538d8b27eac24a96efb9a
  • python2-tools-2.7.18-7.module_el8.5.0+2507+560ae92e.tuxcare.els26.x86_64.rpm
    sha:79484f76f68945c95a56a4cb4e8768bb8a647514c4711c67e9f5594723eb294c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.