Release date:
2026-08-25 12:14:10 UTC
Description:
* SECURITY UPDATE: configuration injection in configparser via a carriage
return in an attacker-controlled written value
- debian/patches/CVE-2026-0864.patch: in Lib/configparser.py, normalize
CR and CRLF to LF before indenting continuation lines in
RawConfigParser._write_section(), so a bare carriage return inside a
written value can no longer round-trip into an unindented line that
the parser reads back as a separate "key = value" pair. Backport of
upstream commit 5858e42c539d (gh-143927 / GH-143929) via the 3.10
backport 12dcbd74d356; applies to 3.7.3 with line offsets only.
Bundles the upstream regression test test_crlf_normalization
(test_configparser.py).
- CVE-2026-0864
Updated packages:
-
idle-python3.7_3.7.3-2+deb10u7+tuxcare.els7_all.deb
sha:2692ee437fb5b243e16bb84419ef092eb2d3bfc2
-
libpython3.7_3.7.3-2+deb10u7+tuxcare.els7_amd64.deb
sha:43c5664ba223c7fc5668338930bdec56f973ff79
-
libpython3.7-dev_3.7.3-2+deb10u7+tuxcare.els7_amd64.deb
sha:31d3e98fb2c378cfa30b8eac916febbbbe6f3638
-
libpython3.7-minimal_3.7.3-2+deb10u7+tuxcare.els7_amd64.deb
sha:10a534398f2f98afb6966934273f0da9ede02b11
-
libpython3.7-stdlib_3.7.3-2+deb10u7+tuxcare.els7_amd64.deb
sha:40cb20bfedca567d787882a8b521865a5fd56bca
-
libpython3.7-testsuite_3.7.3-2+deb10u7+tuxcare.els7_all.deb
sha:15f1dcd248edef5e46a3acafc1172f7a3e49c342
-
python3.7_3.7.3-2+deb10u7+tuxcare.els7_amd64.deb
sha:9d64bf0e31b0ae4a8fef9ccdb63a212e0c25ea73
-
python3.7-dev_3.7.3-2+deb10u7+tuxcare.els7_amd64.deb
sha:04207792098716849f76ede7c1bad00b3b5f6bec
-
python3.7-doc_3.7.3-2+deb10u7+tuxcare.els7_all.deb
sha:4a889daaa116dd6fb22a7d2c2ddaee9cecc0f547
-
python3.7-examples_3.7.3-2+deb10u7+tuxcare.els7_all.deb
sha:cbdc8cc7383e78789d1fe2b55f9e6359c56193c5
-
python3.7-minimal_3.7.3-2+deb10u7+tuxcare.els7_amd64.deb
sha:db34ca7e78a3304de92cad53c38cbc3c6c013c6d
-
python3.7-venv_3.7.3-2+deb10u7+tuxcare.els7_amd64.deb
sha:47afe77168905468a082358ac089f290f200a774
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.