Release date:
2026-08-25 15:21:49 UTC
Description:
* SECURITY UPDATE: configuration file injection via carriage returns in
multi-line ConfigParser values (CVE-2026-0864)
- debian/patches/CVE-2026-0864.patch: normalize CR and CRLF to LF plus tab
continuation at both value-serialisation sites in
RawConfigParser.write() in Lib/ConfigParser.py, so a carriage return
inside an attacker-controlled value can no longer inject extra keys and
sections into the written file; adds the upstream regression test to
Lib/test/test_cfgparser.py.
- CVE-2026-0864
Updated packages:
-
idle-python2.7_2.7.12-1ubuntu0~16.04.18+tuxcare.els22_all.deb
sha:d688222d12b731e590ea3414f4e803e1884cb6dc
-
libpython2.7_2.7.12-1ubuntu0~16.04.18+tuxcare.els22_amd64.deb
sha:f03fb2a2eb72929a17169c020e89138e78c6d539
-
libpython2.7-dev_2.7.12-1ubuntu0~16.04.18+tuxcare.els22_amd64.deb
sha:17f380c089a7033ee6cf1bfdd9e29a3f8a7061ac
-
libpython2.7-minimal_2.7.12-1ubuntu0~16.04.18+tuxcare.els22_amd64.deb
sha:7551cb838ff86582e142d96f87f584a7f63f8f91
-
libpython2.7-stdlib_2.7.12-1ubuntu0~16.04.18+tuxcare.els22_amd64.deb
sha:e28fd04cd941a0fc25a6c07ac819875d9068eb9a
-
libpython2.7-testsuite_2.7.12-1ubuntu0~16.04.18+tuxcare.els22_all.deb
sha:191603fa4925e3e5eba0d1927aae79a78e1f3880
-
python2.7_2.7.12-1ubuntu0~16.04.18+tuxcare.els22_amd64.deb
sha:76a3b88237884a712b6fb570d2558ded141b0c1a
-
python2.7-dev_2.7.12-1ubuntu0~16.04.18+tuxcare.els22_amd64.deb
sha:3aaa7b68b9ce81f811d072b945ed9e95d769df69
-
python2.7-doc_2.7.12-1ubuntu0~16.04.18+tuxcare.els22_all.deb
sha:8724606353c8356d780b059f0a651efeb124db71
-
python2.7-examples_2.7.12-1ubuntu0~16.04.18+tuxcare.els22_all.deb
sha:df224c34a3eb3c447b0015b6201ea703df0b8dfc
-
python2.7-minimal_2.7.12-1ubuntu0~16.04.18+tuxcare.els22_amd64.deb
sha:d25acc6c753aa26ae423a3283be42530b3c77195
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.