Skip to content

CVE-2025-15367 on CTRL-OS 26.05

Aliases: CVE-2025-15367

Packages: python315

Status: Blocked, Resolved

Advisory Information

The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

Updates

2026-07-23 16:47 CEST

Metadata changes:

  • Status for package python315: “Resolved” (ca2468533b550e049ad3466c81179e6f116a24ad)

2026-07-23 16:46 CEST

Metadata changes:

  • Status for package python311: “Blocked
  • Status for package python312: “Blocked
  • Status for package python313: “Blocked
  • Status for package python314: “Blocked
  • Status for package python315: “Blocked

Comment:

The change is not backported to stable branches by upstream Python citing concerns regard compatibility.

— https://github.com/python/cpython/pull/143924#issuecomment-3761307730

(Amended on: 2026-07-23 16:47 CEST)

2026-07-23 16:46 CEST

Metadata changes:

  • Status for package python311: “Plausible
  • Status for package python312: “Plausible
  • Status for package python313: “Plausible
  • Status for package python314: “Plausible
  • Status for package python315: “Plausible

(Amended on: 2026-07-23 16:47 CEST)

2026-06-01 17:44 CEST

Metadata changes:

  • Status for package python311: “New
  • Status for package python312: “New
  • Status for package python313: “New
  • Status for package python314: “New
  • Status for package python315: “New