[CLSA-2026:1787648497] Fix CVE(s): CVE-2026-0864
Type:
security
Severity:
Important
Release date:
2026-08-25 15:24:49 UTC
Description:
* SECURITY UPDATE: configuration-file injection in the configparser module when writing multi-line values containing carriage returns - debian/patches/CVE-2026-0864.patch: normalize CRLF and bare CR to LF before applying the '\n' -> '\n\t' continuation escape in _write_section() in Lib/configparser.py, so an attacker-controlled value can no longer inject additional keys and values into the written file; adds the upstream regression test test_crlf_normalization to Lib/test/test_configparser.py. - CVE-2026-0864
CVEs fixed:
Updated packages:
  • idle-python3.5_3.5.2-2ubuntu0~16.04.13+tuxcare.els29_all.deb
    sha:aa0930f7b83c2df7c5109154ec3423e7a299b79d
  • libpython3.5_3.5.2-2ubuntu0~16.04.13+tuxcare.els29_amd64.deb
    sha:f4082895969b0788beca8b51c29d0fadf30cc4ee
  • libpython3.5-dev_3.5.2-2ubuntu0~16.04.13+tuxcare.els29_amd64.deb
    sha:14500911fd60539bfe74548a9fafe93a49a6482b
  • libpython3.5-minimal_3.5.2-2ubuntu0~16.04.13+tuxcare.els29_amd64.deb
    sha:4ca496111d4543d75a7d86241a58c82ca6ccdbf6
  • libpython3.5-stdlib_3.5.2-2ubuntu0~16.04.13+tuxcare.els29_amd64.deb
    sha:b55d86a6b3a29a43841a13a736c95d9ee3a944c2
  • libpython3.5-testsuite_3.5.2-2ubuntu0~16.04.13+tuxcare.els29_all.deb
    sha:6b1bb0a28826400c3029ab73940ecda139e2f8a1
  • python3.5_3.5.2-2ubuntu0~16.04.13+tuxcare.els29_amd64.deb
    sha:a1616f45346146588133730ef218709538a7a433
  • python3.5-dev_3.5.2-2ubuntu0~16.04.13+tuxcare.els29_amd64.deb
    sha:fd5fc534215add720ebbabdef87af7ac5b278a73
  • python3.5-doc_3.5.2-2ubuntu0~16.04.13+tuxcare.els29_all.deb
    sha:c52021add433edfa6f140109c7296b7ae70a2e96
  • python3.5-examples_3.5.2-2ubuntu0~16.04.13+tuxcare.els29_all.deb
    sha:bdb5728452792dbd79fc7f1995e0528dfde873ee
  • python3.5-minimal_3.5.2-2ubuntu0~16.04.13+tuxcare.els29_amd64.deb
    sha:e62758403e330e5c338bc5430ec5df89250cd2bc
  • python3.5-venv_3.5.2-2ubuntu0~16.04.13+tuxcare.els29_amd64.deb
    sha:5bd1ee46b098de602ca9d98ea45430627f2905d9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.