[CLSA-2026:1788356018] python2: Fix of CVE-2026-0864
Type:
security
Severity:
Important
Release date:
2026-09-02 13:33:50 UTC
Description:
- CVE-2026-0864: normalize CR and CRLF line endings to LF plus tab continuation when ConfigParser.write() serialises a multi-line value. A bare carriage return inside an attacker-controlled value was emitted verbatim and read back by line-oriented consumers as a line break, injecting unintended keys and values into the written file.
CVEs fixed:
Updated packages:
  • python2-2.7.18-17.module_el8+2542+58c84dd1.tuxcare.els15.x86_64.rpm
    sha:b42f8f549f337ff9f8834579fc81807153069a2989b7e10c1247b2299f1b5baf
  • python2-debug-2.7.18-17.module_el8+2542+58c84dd1.tuxcare.els15.x86_64.rpm
    sha:e87be8dac7b4090602cdbe71306d7712fa172ea6ca53f2756516d30ca8124365
  • python2-devel-2.7.18-17.module_el8+2542+58c84dd1.tuxcare.els15.x86_64.rpm
    sha:c1218d759b9ece40abeca8020e620e65a82e03d5ce5a67d6be0a65e28b37350e
  • python2-libs-2.7.18-17.module_el8+2542+58c84dd1.tuxcare.els15.x86_64.rpm
    sha:fb902edd3d95bac772797c76cd5b860ac69c6e564da3baa2dc3e3d0767e0fd09
  • python2-test-2.7.18-17.module_el8+2542+58c84dd1.tuxcare.els15.x86_64.rpm
    sha:7a8ea8f84b307a66b7021b6785a58a919649f041e69ce0dff3d77cb980274fb9
  • python2-tkinter-2.7.18-17.module_el8+2542+58c84dd1.tuxcare.els15.x86_64.rpm
    sha:39a8675a6c106560d1ada1a691bc7bac508030fc75095d2120541daf51164c6c
  • python2-tools-2.7.18-17.module_el8+2542+58c84dd1.tuxcare.els15.x86_64.rpm
    sha:d3e74294a702444ee7d0802120fdebfd3776a65e83b8fc870efde304a57f7f39
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.