[CLSA-2026:1771432562] Fix CVE(s): CVE-2025-15366
Type:
security
Severity:
Important
Release date:
2026-02-18 16:36:07 UTC
Description:
* SECURITY UPDATE: defect in imaplib module, when passed a user-controlled command, commands can be injected using newlines - debian/patches/CVE-2025-15366.patch: Fix command injection by rejecting commands containing control characters - CVE-2025-15366
Updated packages:
  • idle-python3.5_3.5.2-2ubuntu0~16.04.13+tuxcare.els22_all.deb
    sha:e9ea5a3a90532823ce8e39b7d0b4484cf88aff98
  • libpython3.5_3.5.2-2ubuntu0~16.04.13+tuxcare.els22_amd64.deb
    sha:af90fb9d81ba6144ac9f4c85bf7d03ec03dd6a06
  • libpython3.5-dev_3.5.2-2ubuntu0~16.04.13+tuxcare.els22_amd64.deb
    sha:a49c0ad8f254447a82d3aac943d0d4365f1a8897
  • libpython3.5-minimal_3.5.2-2ubuntu0~16.04.13+tuxcare.els22_amd64.deb
    sha:ffd790a3777ec45fb47d234c2c06539d6c892221
  • libpython3.5-stdlib_3.5.2-2ubuntu0~16.04.13+tuxcare.els22_amd64.deb
    sha:eae8071830192200c00969274bc4906e278c0e06
  • libpython3.5-testsuite_3.5.2-2ubuntu0~16.04.13+tuxcare.els22_all.deb
    sha:29611a57340059b448ee3fae7f61b56ed2c74bad
  • python3.5_3.5.2-2ubuntu0~16.04.13+tuxcare.els22_amd64.deb
    sha:22bb92d9296f85135bd0c0d4b2a26eae1f4afc76
  • python3.5-dev_3.5.2-2ubuntu0~16.04.13+tuxcare.els22_amd64.deb
    sha:c8f8784371dfbfeb0bb84c1f577956915ba60d81
  • python3.5-doc_3.5.2-2ubuntu0~16.04.13+tuxcare.els22_all.deb
    sha:fcb8169be481f2ecdcdb36664f94faead28f4ae5
  • python3.5-examples_3.5.2-2ubuntu0~16.04.13+tuxcare.els22_all.deb
    sha:1ce0dae9f255d17b96b1dff16a8736c98fe01c17
  • python3.5-minimal_3.5.2-2ubuntu0~16.04.13+tuxcare.els22_amd64.deb
    sha:82c1bfc18efd6c085d294a19eb587cdd4f2af3c2
  • python3.5-venv_3.5.2-2ubuntu0~16.04.13+tuxcare.els22_amd64.deb
    sha:990bc37bde6980a0e9727d918224bb089a8e6c56
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.