[CLSA-2026:1787647093] Fix CVE(s): CVE-2026-0864
Type:
security
Severity:
Important
Release date:
2026-08-25 15:21:49 UTC
Description:
* SECURITY UPDATE: configuration file injection via carriage returns in multi-line ConfigParser values (CVE-2026-0864) - debian/patches/CVE-2026-0864.patch: normalize CR and CRLF to LF plus tab continuation at both value-serialisation sites in RawConfigParser.write() in Lib/ConfigParser.py, so a carriage return inside an attacker-controlled value can no longer inject extra keys and sections into the written file; adds the upstream regression test to Lib/test/test_cfgparser.py. - CVE-2026-0864
CVEs fixed:
Updated packages:
  • idle-python2.7_2.7.12-1ubuntu0~16.04.18+tuxcare.els22_all.deb
    sha:d688222d12b731e590ea3414f4e803e1884cb6dc
  • libpython2.7_2.7.12-1ubuntu0~16.04.18+tuxcare.els22_amd64.deb
    sha:f03fb2a2eb72929a17169c020e89138e78c6d539
  • libpython2.7-dev_2.7.12-1ubuntu0~16.04.18+tuxcare.els22_amd64.deb
    sha:17f380c089a7033ee6cf1bfdd9e29a3f8a7061ac
  • libpython2.7-minimal_2.7.12-1ubuntu0~16.04.18+tuxcare.els22_amd64.deb
    sha:7551cb838ff86582e142d96f87f584a7f63f8f91
  • libpython2.7-stdlib_2.7.12-1ubuntu0~16.04.18+tuxcare.els22_amd64.deb
    sha:e28fd04cd941a0fc25a6c07ac819875d9068eb9a
  • libpython2.7-testsuite_2.7.12-1ubuntu0~16.04.18+tuxcare.els22_all.deb
    sha:191603fa4925e3e5eba0d1927aae79a78e1f3880
  • python2.7_2.7.12-1ubuntu0~16.04.18+tuxcare.els22_amd64.deb
    sha:76a3b88237884a712b6fb570d2558ded141b0c1a
  • python2.7-dev_2.7.12-1ubuntu0~16.04.18+tuxcare.els22_amd64.deb
    sha:3aaa7b68b9ce81f811d072b945ed9e95d769df69
  • python2.7-doc_2.7.12-1ubuntu0~16.04.18+tuxcare.els22_all.deb
    sha:8724606353c8356d780b059f0a651efeb124db71
  • python2.7-examples_2.7.12-1ubuntu0~16.04.18+tuxcare.els22_all.deb
    sha:df224c34a3eb3c447b0015b6201ea703df0b8dfc
  • python2.7-minimal_2.7.12-1ubuntu0~16.04.18+tuxcare.els22_amd64.deb
    sha:d25acc6c753aa26ae423a3283be42530b3c77195
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.