Release date:
2026-08-10 10:27:49 UTC
Description:
* SECURITY UPDATE: configuration file injection via carriage returns in
written option values
- debian/patches/CVE-2026-0864.patch: normalise CR and CRLF, and not
only LF, into '\n\t' continuation lines when writing option values in
RawConfigParser.write() in Lib/ConfigParser.py, so that an
attacker-controlled value can no longer inject additional sections,
keys and values into the written file
- CVE-2026-0864
* SECURITY UPDATE: CPU denial-of-service in tarfile streaming mode via a
member size declared past the end of the stream
- debian/patches/CVE-2026-11972.patch: stop _Stream.seek() at the first
empty read instead of looping once per attacker-declared block against
an already-exhausted stream in Lib/tarfile.py
- CVE-2026-11972
Updated packages:
-
idle-python2.7_2.7.16-2+deb10u4+tuxcare.els4_all.deb
sha:64d44ec3f988f36c019ca22bb22cc26905d51024
-
libpython2.7_2.7.16-2+deb10u4+tuxcare.els4_amd64.deb
sha:f2151e1383e5ad5f017a980ddeb18b273992706d
-
libpython2.7-dev_2.7.16-2+deb10u4+tuxcare.els4_amd64.deb
sha:037ccc64d081a6d206eda8ff766720d2567f0899
-
libpython2.7-minimal_2.7.16-2+deb10u4+tuxcare.els4_amd64.deb
sha:d5010b1aaa8e3e2c2ed63502bd7a20fbb1f8da15
-
libpython2.7-stdlib_2.7.16-2+deb10u4+tuxcare.els4_amd64.deb
sha:7fd75aa1c667255af7f69e63009ee2d7c8908add
-
libpython2.7-testsuite_2.7.16-2+deb10u4+tuxcare.els4_all.deb
sha:fb06504d2e431ca82462f28c5325bb6e2093118d
-
python2.7_2.7.16-2+deb10u4+tuxcare.els4_amd64.deb
sha:d5e14d154116d837a73508df86c6c7d465a7e9bc
-
python2.7-dev_2.7.16-2+deb10u4+tuxcare.els4_amd64.deb
sha:ce00b364688f426a3a83726989682e0c26f721e4
-
python2.7-doc_2.7.16-2+deb10u4+tuxcare.els4_all.deb
sha:fa22faf3ab64825a2592c61d08a7cff2d938cadf
-
python2.7-examples_2.7.16-2+deb10u4+tuxcare.els4_all.deb
sha:26f32860caa06bdd7c41f29791bdae147982ef7a
-
python2.7-minimal_2.7.16-2+deb10u4+tuxcare.els4_amd64.deb
sha:498b562a6d0a02885e5b2ac4c3721c0b1dff94cd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.