[CLSA-2026:1787646114] python: Fix of CVE-2026-0864
Type:
security
Severity:
Important
Release date:
2026-08-25 08:22:06 UTC
Description:
- CVE-2026-0864: normalize CR and CRLF line endings when writing multi-line values in ConfigParser - RawConfigParser.write() escaped only '\n' (to '\n\t'), so an attacker-controlled value containing a bare carriage return was written out verbatim and injected unexpected keys and values into the resulting configuration file. Applied at both write() call sites, for the DEFAULT section and for named sections; Python 2.7 has no _write_section(). Backported from upstream CPython (gh-143927, GH-143929).
CVEs fixed:
Updated packages:
  • python-2.7.5-94.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:3efb349265e8fd6481ade12bb684595bc793217adf2c72bf431fe20fcff5443a
  • python-debug-2.7.5-94.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:dd777c743d3ff25b193cf520be794517a3cf489ed43dfe1deef8183f8f231c29
  • python-devel-2.7.5-94.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:335e4694f4cd2eb4fb66a936cd538b661c45b7b5c34a4af5d3400c82ccff9c4e
  • python-libs-2.7.5-94.0.5.el7_9.tuxcare.els2.i686.rpm
    sha:a4a5cdc26c679a7a992b127640dc5095200dec66e8f1ffa9dd1ddb633b1540b2
  • python-libs-2.7.5-94.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:c411d2eaefcc7542b1d0a9fdfa210e823d1acb4e9bd1edd4e0f41c1048720cdc
  • python-test-2.7.5-94.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:cc3e3e7f39b4b29f61e5191b25a25dc8345647472178134bcee795455d584957
  • python-tools-2.7.5-94.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:2b081d160d5199a301b216fc09f793e085b9380ac9749e3380bc7704dcaa2560
  • tkinter-2.7.5-94.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:475a15c3020e0fdec26f82ab8e5a2459ca9d67ef9e0313575286da24efc13fef
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.