|
|
Log in / Subscribe / Register

Ubuntu alert USN-8614-1 (python2.7, python3.5)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8614-1] Python vulnerabilities
Date:  Thu, 30 Jul 2026 14:00:34 +0000
Message-ID:  <E1wpRJK-0000Yn-4g@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8614-1 July 27, 2026 python2.7, python3.5 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Python. Software Description: - python2.7: An interactive high-level object-oriented language - python3.5: An interactive high-level object-oriented language Details: It was discovered that Python incorrectly handled expanding environment variables in os.path.expandvars() when the input was user-controlled. An attacker could possibly use this issue to cause Python to consume resources, leading to a denial of service. (CVE-2025-6075) It was discovered that Python incorrectly handled certain malformed HTML-like markup in the HTMLParser module, raising an uncaught exception. A remote attacker could possibly use this issue to cause applications that parse untrusted input to crash, resulting in a denial of service. (CVE-2025-69534) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS libpython2.7-minimal 2.7.12-1ubuntu0~16.04.18+esm21 Available with Ubuntu Pro libpython2.7-stdlib 2.7.12-1ubuntu0~16.04.18+esm21 Available with Ubuntu Pro libpython3.5-stdlib 3.5.2-2ubuntu0~16.04.13+esm24 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8614-1 CVE-2025-6075, CVE-2025-69534


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmpohTYACgkQcpJm3tlz hgEk9A//axEAFAzTuaIv/CwkbxM5L1YcOfW+Y5aYwvXoTh9MLYEQqRrzEs8+Gz02 gBFbQ4zQIN0KayCvIyhZn+73ubHsvFMj+P/w9E+ETQe84wNgaI1Cqki0TFUbn7OZ bdceShhYutOu3Qzftw/BzcQj3L9g4cD6QHhnM+SR4gJKwnahnHcnuAhV3L8zuDLm 4JFCdgmMf8nGj6Y561JKcVaslqjUpurVF5TC6OkPw6v7lWYj3eBPP9yFhOP3vmtd I6Pj0se1Cgaz+8mPXuKs7uwFEZ6PWSCV+a5qkbMfmsZwo2Rh71yuCbLMyy2vBVHp i8hfHB+hv/rtuIicgC2DMq5tVp4INmGesMST3yOTCCrqcAJm/u9ltSWgM+ze3gR7 oAvd8UC+l//ZYmNIUKhAt796/Xn24ata6dXqsKoXYcYYaNsK3NK3n1wsHi7VUIxC a24ylzIysd90jXe2uUTF20Ib6SZL3tU9rjvgmVNqcsTr9FqdzlBJwgn20X/mrnv9 mb9e0NQ4IhkJKSG3J9fuuE8VHSykEtDqscHj/nZbnYGXGqM4je+C+Iaod+ZfSCfM FBcUIdMIjyLJbTgohJ11NQw6QPDXr9T6gjj5Z1OjHwh/r6OnjRdJxpaoTkS5V/9Y 9sQg53xjmOcaevTZrXx7ANfJH2cKIuoy9GorW1VIEpPMZItIZl0= =ifiU -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds