[CLSA-2026:1788185792] python3: Fix of CVE-2026-0864
Type:
security
Severity:
Important
Release date:
2026-08-31 14:16:43 UTC
Description:
- CVE-2026-0864: normalize all line endings (CR, CRLF and LF) when writing multi-line configparser values so a value cannot inject extra keys
CVEs fixed:
Updated packages:
  • python3-3.7.16-1.amzn2.0.29.tuxcare.els2.i686.rpm
    sha:ccc38c37b6aaeb848124bac316ff7122762d2b2c8735454e8bad6b32ca6405e0
  • python3-3.7.16-1.amzn2.0.29.tuxcare.els2.x86_64.rpm
    sha:8c0a4e1eb3bc1eb6e2e2448cd48b7d2e19f57e59286222be24b194d90d3a51bc
  • python3-debug-3.7.16-1.amzn2.0.29.tuxcare.els2.x86_64.rpm
    sha:0204f4bb70ca310a61b1382db7c3d60a79bb96cbc8266b59477a2478b1cb0ced
  • python3-devel-3.7.16-1.amzn2.0.29.tuxcare.els2.x86_64.rpm
    sha:41bbaa662bf2e889c2dbecbbc4a5d334f2957d1ce95dd3a1a0da8af6b9e2800c
  • python3-libs-3.7.16-1.amzn2.0.29.tuxcare.els2.i686.rpm
    sha:53dce377a1f8aa126df261a0a33420c268b24a0202b30c4b300e90dd869ea587
  • python3-libs-3.7.16-1.amzn2.0.29.tuxcare.els2.x86_64.rpm
    sha:c3bbea75ecf28f329f5d2a945e60a3390de6f1338f6d509ec06eba86793fc8e1
  • python3-test-3.7.16-1.amzn2.0.29.tuxcare.els2.x86_64.rpm
    sha:50cd553568d8c28d2b11065f3e7416a4a8669801a0e7f0c84a3b6b4d52555469
  • python3-tkinter-3.7.16-1.amzn2.0.29.tuxcare.els2.x86_64.rpm
    sha:3fd4f64e91434b66b39aa9d525b25bcce07deb2f23c9ae3eda95ab7646b278bb
  • python3-tools-3.7.16-1.amzn2.0.29.tuxcare.els2.x86_64.rpm
    sha:bdc9c8aaa31792e2a1f35c75cf0312ed669d9bb5bfe125ff1eb03f74a4931069
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.