[CLSA-2026:1771597308] Fix CVE(s): CVE-2025-15366
Type:
security
Severity:
Important
Release date:
2026-02-20 14:21:52 UTC
Description:
* SECURITY UPDATE: defect in imaplib module, when passed a user-controlled command, commands can be injected using newlines - debian/patches/CVE-2025-15366.patch: Fix command injection by rejecting commands containing control characters - CVE-2025-15366
Updated packages:
  • idle-python3.6_3.6.9-1~18.04ubuntu1.12+tuxcare.els18_all.deb
    sha:f0cc835c67dde2366b2588bc96a51ba3d1b3b0ee
  • libpython3.6_3.6.9-1~18.04ubuntu1.12+tuxcare.els18_amd64.deb
    sha:033bfac27ddeee961803c380eef27e60d57f694f
  • libpython3.6-dev_3.6.9-1~18.04ubuntu1.12+tuxcare.els18_amd64.deb
    sha:81801955bdffb70748c850c060a655d2a3b63491
  • libpython3.6-minimal_3.6.9-1~18.04ubuntu1.12+tuxcare.els18_amd64.deb
    sha:32d4cb678d47c92743e0a703519e282d37976997
  • libpython3.6-stdlib_3.6.9-1~18.04ubuntu1.12+tuxcare.els18_amd64.deb
    sha:c8842a5b12dcc89ef006a039b227b14a1d154bc2
  • libpython3.6-testsuite_3.6.9-1~18.04ubuntu1.12+tuxcare.els18_all.deb
    sha:5779f79141440e8d3dc83d91fc7ea3b0be5d7044
  • python3.6_3.6.9-1~18.04ubuntu1.12+tuxcare.els18_amd64.deb
    sha:30b9127c201f9b212a51f8c712108edfddac768d
  • python3.6-dev_3.6.9-1~18.04ubuntu1.12+tuxcare.els18_amd64.deb
    sha:166f10141184595edaa70e7c9069289d041b5dd7
  • python3.6-doc_3.6.9-1~18.04ubuntu1.12+tuxcare.els18_all.deb
    sha:7c62e3404887502bc0fb813426d29780c298b54a
  • python3.6-examples_3.6.9-1~18.04ubuntu1.12+tuxcare.els18_all.deb
    sha:b807008b57666e010c7b1539da6d732cf9f72f40
  • python3.6-minimal_3.6.9-1~18.04ubuntu1.12+tuxcare.els18_amd64.deb
    sha:46aa957074ec25610045f8c5626b0463e12b35d4
  • python3.6-venv_3.6.9-1~18.04ubuntu1.12+tuxcare.els18_amd64.deb
    sha:3f3fe2da3487a026eb010e56be396d6fadd19cd7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.