[CLSA-2026:1787305287] python: Fix of CVE-2026-0864
Type:
security
Severity:
Important
Release date:
2026-08-25 11:17:15 UTC
Description:
- CVE-2026-0864: normalize CR and CRLF line endings to LF+TAB when writing multi-line configparser values so an attacker-controlled value cannot inject unexpected keys and sections into the generated file
CVEs fixed:
Updated packages:
  • python-2.7.18-1.amzn2.0.22.tuxcare.els2.x86_64.rpm
    sha:2f1bf60a548cb1c9881cfec168524181a55ed613b725607b40941a59a5d9ee1a
  • python-debug-2.7.18-1.amzn2.0.22.tuxcare.els2.x86_64.rpm
    sha:74f7e03c5a77eba975525a8dff06fa95b1d5b6baff9e8e9a177e91556dccf606
  • python-devel-2.7.18-1.amzn2.0.22.tuxcare.els2.x86_64.rpm
    sha:56d402030ca31f8be04d13b0709595c9110dd9a66c73ddc86b7c3e65e5603e33
  • python-libs-2.7.18-1.amzn2.0.22.tuxcare.els2.i686.rpm
    sha:af32cb200424caf9e64f78e0d650464dfacdeae2b25e950585a828a13859a025
  • python-libs-2.7.18-1.amzn2.0.22.tuxcare.els2.x86_64.rpm
    sha:6612e8e47782a3882071eea25b0a5c12cc38e17d93fa952f69d48480d3da16d5
  • python-test-2.7.18-1.amzn2.0.22.tuxcare.els2.x86_64.rpm
    sha:494114c55451e1bc712fab455fbc7f7de40749fbc769df58877c75e5f939b2b4
  • python-tools-2.7.18-1.amzn2.0.22.tuxcare.els2.x86_64.rpm
    sha:b5cd46ea62049c9bbf9b311393b3f0759b86a2de5a2063dcb2252d6ad7ee80dc
  • tkinter-2.7.18-1.amzn2.0.22.tuxcare.els2.x86_64.rpm
    sha:0406d4311190ac0b382a3a22a89c1c546984ea2374b3b8340e707ef08fb25926
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.