[CLSA-2026:1787679403] Fix CVE(s): CVE-2026-0864
Type:
security
Severity:
Important
Release date:
2026-08-25 17:36:53 UTC
Description:
* SECURITY UPDATE: Configuration file injection via unescaped carriage returns in ConfigParser.write() - debian/patches/CVE-2026-0864.patch: normalize CR, CRLF and LF line endings to '\n\t' in both value-escaping call sites of RawConfigParser.write() in Lib/ConfigParser.py, so an attacker controlled value can no longer inject unexpected keys into the written file; add regression test to Lib/test/test_cfgparser.py - CVE-2026-0864
CVEs fixed:
Updated packages:
  • idle-python2.7_2.7.18-1~20.04.7+tuxcare.els6_all.deb
    sha:b633d8a8a91e40fad1ef6b68407b66b829999485
  • libpython2.7_2.7.18-1~20.04.7+tuxcare.els6_amd64.deb
    sha:5c09cf2919f9b2928ba61030653befc9d70beb3a
  • libpython2.7-dev_2.7.18-1~20.04.7+tuxcare.els6_amd64.deb
    sha:91dfdf64ee19eced2d21c240925516a6fbae9f9a
  • libpython2.7-minimal_2.7.18-1~20.04.7+tuxcare.els6_amd64.deb
    sha:cab8a96ebd17a30faa8220ee6fdb2fda93e1e5ad
  • libpython2.7-stdlib_2.7.18-1~20.04.7+tuxcare.els6_amd64.deb
    sha:4ef73e750122a17565128319edab1d0af9224a1d
  • libpython2.7-testsuite_2.7.18-1~20.04.7+tuxcare.els6_all.deb
    sha:e4c3121a33856216cd4b69fff2058c6536d94d3e
  • python2.7_2.7.18-1~20.04.7+tuxcare.els6_amd64.deb
    sha:49cf706572cb6e75abcaabf77a2d6b30f51dc716
  • python2.7-dev_2.7.18-1~20.04.7+tuxcare.els6_amd64.deb
    sha:595062e424f44544e060c0ad7b1e7b00c3c765ff
  • python2.7-doc_2.7.18-1~20.04.7+tuxcare.els6_all.deb
    sha:026c5286342da061ff171ed7156f9b4f3194b9a4
  • python2.7-examples_2.7.18-1~20.04.7+tuxcare.els6_all.deb
    sha:128257d722a3bf8e5dbec9bf0b9442130658abf7
  • python2.7-minimal_2.7.18-1~20.04.7+tuxcare.els6_amd64.deb
    sha:da8cb221d8a9e4d1dabd91a811a337e83043748e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.