[CLSA-2026:1771597605] Fix CVE(s): CVE-2025-15367
Type:
security
Severity:
Important
Release date:
2026-02-20 14:26:49 UTC
Description:
* SECURITY UPDATE: defect in poplib module, when passed a user-controlled command, commands can be injected using newlines - debian/patches/CVE-2025-15367.patch: Fix command injection by rejecting commands containing control characters - CVE-2025-15367
Updated packages:
  • idle-python3.5_3.5.2-2ubuntu0~16.04.13+tuxcare.els23_all.deb
    sha:be5b966defe7831800e8f332431898e124f71ec6
  • libpython3.5_3.5.2-2ubuntu0~16.04.13+tuxcare.els23_amd64.deb
    sha:9d4542a98840acdcf892673a29962fac57b52c5e
  • libpython3.5-dev_3.5.2-2ubuntu0~16.04.13+tuxcare.els23_amd64.deb
    sha:b63f4836775ba6fdba1d56078d13e3ca9ee18d7a
  • libpython3.5-minimal_3.5.2-2ubuntu0~16.04.13+tuxcare.els23_amd64.deb
    sha:bb4ccbac07645b394d45824c930ad3a0ff2c4d75
  • libpython3.5-stdlib_3.5.2-2ubuntu0~16.04.13+tuxcare.els23_amd64.deb
    sha:2ad73523420c86622436fa9be935eea14a08575c
  • libpython3.5-testsuite_3.5.2-2ubuntu0~16.04.13+tuxcare.els23_all.deb
    sha:2f161e2b3b98724744a46fb9e56bb8be09441419
  • python3.5_3.5.2-2ubuntu0~16.04.13+tuxcare.els23_amd64.deb
    sha:0b3237a2b9871eb90aff8547e4fbb6707e273d02
  • python3.5-dev_3.5.2-2ubuntu0~16.04.13+tuxcare.els23_amd64.deb
    sha:779abccb9b92227ea031e5bd9c2073262518343d
  • python3.5-doc_3.5.2-2ubuntu0~16.04.13+tuxcare.els23_all.deb
    sha:6e8ff68da1b9a447cd923d18a4bb8698941201bd
  • python3.5-examples_3.5.2-2ubuntu0~16.04.13+tuxcare.els23_all.deb
    sha:9b8de081907ec83f281386909bd231df57f522a6
  • python3.5-minimal_3.5.2-2ubuntu0~16.04.13+tuxcare.els23_amd64.deb
    sha:dae6a7d26ee266eb2d1f472ed6d62266770d49e2
  • python3.5-venv_3.5.2-2ubuntu0~16.04.13+tuxcare.els23_amd64.deb
    sha:b5a9b2a47fb6ea6cbc76520952ffffc0a7585747
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.