Release date:
2026-08-26 08:35:18 UTC
Description:
* SECURITY UPDATE: configuration file injection via carriage returns in
multi-line ConfigParser values (CVE-2026-0864)
- debian/patches/CVE-2026-0864.patch: normalize CR and CRLF to LF plus tab
continuation at both value-serialisation sites in
RawConfigParser.write() in Lib/ConfigParser.py, so a carriage return
inside an attacker-controlled value can no longer inject extra keys and
sections into the written file; adds the upstream regression test to
Lib/test/test_cfgparser.py.
- CVE-2026-0864
Updated packages:
-
idle-python2.7_2.7.17-1~18.04ubuntu1.11+tuxcare.els16_all.deb
sha:013f79e00e6f480eef2400f5807f02140024ae65
-
libpython2.7_2.7.17-1~18.04ubuntu1.11+tuxcare.els16_amd64.deb
sha:f0be673b7d3ba420d05b5fe68805d7f80f998ddc
-
libpython2.7-dev_2.7.17-1~18.04ubuntu1.11+tuxcare.els16_amd64.deb
sha:1aa95049417611c66619fa8bb039833f1bed23b3
-
libpython2.7-minimal_2.7.17-1~18.04ubuntu1.11+tuxcare.els16_amd64.deb
sha:ebd4079890c1281a0e8a60ca2662974bc3da48ab
-
libpython2.7-stdlib_2.7.17-1~18.04ubuntu1.11+tuxcare.els16_amd64.deb
sha:bd5b72cc2a1ac7d496f0ecb2df4d170582195d6b
-
libpython2.7-testsuite_2.7.17-1~18.04ubuntu1.11+tuxcare.els16_all.deb
sha:57661af0e72e07730c73e79cf70087e4904826bc
-
python2.7_2.7.17-1~18.04ubuntu1.11+tuxcare.els16_amd64.deb
sha:d849f30ec7122b14ef9e50ac4645126678d9b9ff
-
python2.7-dev_2.7.17-1~18.04ubuntu1.11+tuxcare.els16_amd64.deb
sha:7a11eeefd3f5b8e102f80214d3bd6b302246d652
-
python2.7-doc_2.7.17-1~18.04ubuntu1.11+tuxcare.els16_all.deb
sha:ddace4cf0942554c0cd846877690f25b3f135d73
-
python2.7-examples_2.7.17-1~18.04ubuntu1.11+tuxcare.els16_all.deb
sha:f42602486e83831eeca9c53d2d1f56d191f85af3
-
python2.7-minimal_2.7.17-1~18.04ubuntu1.11+tuxcare.els16_amd64.deb
sha:868e33d9e91d572e66070dd26d8a5806457037d7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.