Release date:
2026-08-25 08:26:16 UTC
Description:
- CVE-2026-0864: normalize CR and CRLF line endings when writing multi-line
values in ConfigParser - RawConfigParser.write() escaped only '\n' (to
'\n\t'), so an attacker-controlled value containing a bare carriage return
was written out verbatim and injected unexpected keys and values into the
resulting configuration file. Applied at both write() call sites, for the
DEFAULT section and for named sections; Python 2.7 has no _write_section().
Backported from upstream CPython (gh-143927, GH-143929).
Updated packages:
-
python-2.7.5-94.0.5.el7_9.tuxcare.els2.x86_64.rpm
sha:9680505a374ff46051e7bee9d4e983b421da21961fce49a5923e52d81425cadd
-
python-debug-2.7.5-94.0.5.el7_9.tuxcare.els2.x86_64.rpm
sha:fe667d9328de479260bbfedf16ee5c21a06353ce3e6ff4cfe93ed37fff0dc6df
-
python-devel-2.7.5-94.0.5.el7_9.tuxcare.els2.x86_64.rpm
sha:9f39b5a2b86b5df45cd5c64765111d5c2f6920a7856d4b315510b132cbc4dd8a
-
python-libs-2.7.5-94.0.5.el7_9.tuxcare.els2.i686.rpm
sha:03f48258a75b8a7aad181b23cbb3ae83a6d09fce1de3b3808f0e463bf8cd259f
-
python-libs-2.7.5-94.0.5.el7_9.tuxcare.els2.x86_64.rpm
sha:fe328dc77cfd2a24b5940a57a7e9c62ea5947e9c1e6650bc62c6d78424e53183
-
python-test-2.7.5-94.0.5.el7_9.tuxcare.els2.x86_64.rpm
sha:bcc2c0ddce6c4ad5b69ab32bb09f00312aeb000b3d158a8f389a958f580f4e7b
-
python-tools-2.7.5-94.0.5.el7_9.tuxcare.els2.x86_64.rpm
sha:ce235077a81e7dbcb68c95a257a84b7d0f468095a50fda7a7609af1aadb07ffb
-
tkinter-2.7.5-94.0.5.el7_9.tuxcare.els2.x86_64.rpm
sha:c6e40bc3fb30cb2d06077aa1a42ff8f20b5e91c1983e03d15852bc9fbae9415b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.