[CLSA-2026:1786357657] Fix CVE(s): CVE-2026-0864, CVE-2026-11972
Type:
security
Severity:
Important
Release date:
2026-08-10 10:27:49 UTC
Description:
* SECURITY UPDATE: configuration file injection via carriage returns in written option values - debian/patches/CVE-2026-0864.patch: normalise CR and CRLF, and not only LF, into '\n\t' continuation lines when writing option values in RawConfigParser.write() in Lib/ConfigParser.py, so that an attacker-controlled value can no longer inject additional sections, keys and values into the written file - CVE-2026-0864 * SECURITY UPDATE: CPU denial-of-service in tarfile streaming mode via a member size declared past the end of the stream - debian/patches/CVE-2026-11972.patch: stop _Stream.seek() at the first empty read instead of looping once per attacker-declared block against an already-exhausted stream in Lib/tarfile.py - CVE-2026-11972
Updated packages:
  • idle-python2.7_2.7.16-2+deb10u4+tuxcare.els4_all.deb
    sha:64d44ec3f988f36c019ca22bb22cc26905d51024
  • libpython2.7_2.7.16-2+deb10u4+tuxcare.els4_amd64.deb
    sha:f2151e1383e5ad5f017a980ddeb18b273992706d
  • libpython2.7-dev_2.7.16-2+deb10u4+tuxcare.els4_amd64.deb
    sha:037ccc64d081a6d206eda8ff766720d2567f0899
  • libpython2.7-minimal_2.7.16-2+deb10u4+tuxcare.els4_amd64.deb
    sha:d5010b1aaa8e3e2c2ed63502bd7a20fbb1f8da15
  • libpython2.7-stdlib_2.7.16-2+deb10u4+tuxcare.els4_amd64.deb
    sha:7fd75aa1c667255af7f69e63009ee2d7c8908add
  • libpython2.7-testsuite_2.7.16-2+deb10u4+tuxcare.els4_all.deb
    sha:fb06504d2e431ca82462f28c5325bb6e2093118d
  • python2.7_2.7.16-2+deb10u4+tuxcare.els4_amd64.deb
    sha:d5e14d154116d837a73508df86c6c7d465a7e9bc
  • python2.7-dev_2.7.16-2+deb10u4+tuxcare.els4_amd64.deb
    sha:ce00b364688f426a3a83726989682e0c26f721e4
  • python2.7-doc_2.7.16-2+deb10u4+tuxcare.els4_all.deb
    sha:fa22faf3ab64825a2592c61d08a7cff2d938cadf
  • python2.7-examples_2.7.16-2+deb10u4+tuxcare.els4_all.deb
    sha:26f32860caa06bdd7c41f29791bdae147982ef7a
  • python2.7-minimal_2.7.16-2+deb10u4+tuxcare.els4_amd64.deb
    sha:498b562a6d0a02885e5b2ac4c3721c0b1dff94cd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.