[CLSA-2026:1771925958] python2: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-02-24 09:39:23 UTC
Description:
- CVE-2026-1299: reject email header values containing newlines without whitespace to prevent header injection and info leak via the buffer protocol - CVE-2024-6923: ensure email headers are encoded and verified correctly, raising exceptions for malformed input to prevent processing of invalid or dangerous headers
Updated packages:
  • python2-2.7.18-7.module_el8.5.0+2354+0d350335.tuxcare.els17.x86_64.rpm
    sha:4c320d1023dd25bd64f1ab2a05200954f3dd43acf6dc7fbb5c64e87fe0cbdc6a
  • python2-debug-2.7.18-7.module_el8.5.0+2354+0d350335.tuxcare.els17.x86_64.rpm
    sha:cd961310e19861d4c118cea49c32aaa54066a4b3f982998fc0643424947f2526
  • python2-devel-2.7.18-7.module_el8.5.0+2354+0d350335.tuxcare.els17.x86_64.rpm
    sha:3dae6f6a4ce06aefb7d25c6a646b2d1f3527bac3a397aef764113f1637b9d705
  • python2-libs-2.7.18-7.module_el8.5.0+2354+0d350335.tuxcare.els17.x86_64.rpm
    sha:8bc0c23077185e14544d1c71257bbdabaa10b04bf1a28f197d13a76d92641d86
  • python2-test-2.7.18-7.module_el8.5.0+2354+0d350335.tuxcare.els17.x86_64.rpm
    sha:d44052ed228c0fdaabd91e9ad8cdcb8d1b8462b7826fb75153a22a85120383ee
  • python2-tkinter-2.7.18-7.module_el8.5.0+2354+0d350335.tuxcare.els17.x86_64.rpm
    sha:08ab7072b127061fb86205f54656542cdf007cce865458f58b195857ae23448f
  • python2-tools-2.7.18-7.module_el8.5.0+2354+0d350335.tuxcare.els17.x86_64.rpm
    sha:f55df049edf9f2f5cceab935ae7699020c4e457bd43dac633a10ab4e74ffe0ed
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.