[CLSA-2026:1787664255] Fix CVE(s): CVE-2026-0864
Type:
security
Severity:
Important
Release date:
2026-08-25 15:26:34 UTC
Description:
* SECURITY UPDATE: configuration-file injection in the configparser module when writing multi-line values that contain carriage returns - debian/patches/CVE-2026-0864.patch: normalize CRLF and bare CR to LF before applying the newline-to-tab continuation escape in _write_section() in Lib/configparser.py, so an attacker-controlled value can no longer inject additional keys and sections into the written file; adds the upstream regression test test_crlf_normalization to Lib/test/test_configparser.py. - CVE-2026-0864
CVEs fixed:
Updated packages:
  • idle-python3.6_3.6.9-1~18.04ubuntu1.12+tuxcare.els25_all.deb
    sha:ecd4fce5f06dc6d2fde6630ef9f55af8352f01af
  • libpython3.6_3.6.9-1~18.04ubuntu1.12+tuxcare.els25_amd64.deb
    sha:52b3a72472f66834d4d4e27d867c255283c3ea98
  • libpython3.6-dev_3.6.9-1~18.04ubuntu1.12+tuxcare.els25_amd64.deb
    sha:c99060c829b0128bcf30551c6b58a7b98564a879
  • libpython3.6-minimal_3.6.9-1~18.04ubuntu1.12+tuxcare.els25_amd64.deb
    sha:f4c5fde1831bbefc122e1e5ca5c885530035cd04
  • libpython3.6-stdlib_3.6.9-1~18.04ubuntu1.12+tuxcare.els25_amd64.deb
    sha:cd108a9961c4df9abdb51f3a5822c166df4bdb96
  • libpython3.6-testsuite_3.6.9-1~18.04ubuntu1.12+tuxcare.els25_all.deb
    sha:90d4e8b6bd702dae8e5c1cb8b7b6bb37a9ed957f
  • python3.6_3.6.9-1~18.04ubuntu1.12+tuxcare.els25_amd64.deb
    sha:0e9cf6f2d9cf54c874afebcb1f5c28c04bcd0d4e
  • python3.6-dev_3.6.9-1~18.04ubuntu1.12+tuxcare.els25_amd64.deb
    sha:368054a95629a793fcf0dfdaf5c4cd8e828fd14f
  • python3.6-doc_3.6.9-1~18.04ubuntu1.12+tuxcare.els25_all.deb
    sha:4579f9aece1604560ad56703f50bcee3e7dfbcaf
  • python3.6-examples_3.6.9-1~18.04ubuntu1.12+tuxcare.els25_all.deb
    sha:ac11d128ed1e323694ce31d15f270c5cbea86075
  • python3.6-minimal_3.6.9-1~18.04ubuntu1.12+tuxcare.els25_amd64.deb
    sha:41ac8a24d69daedfaf7e70e233d01d880f16bbd0
  • python3.6-venv_3.6.9-1~18.04ubuntu1.12+tuxcare.els25_amd64.deb
    sha:fba5146c9b66912ef5eaadc812b8c2a93871348f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.