Packages
- python2.7 - An interactive high-level object-oriented language
- python3.10 - An interactive high-level object-oriented language
- python3.11 - An interactive high-level object-oriented language
- python3.12 - An interactive high-level object-oriented language
- python3.14 - An interactive high-level object-oriented language
- python3.4 - An interactive high-level object-oriented language
- python3.5 - An interactive high-level object-oriented language
- python3.6 - An interactive high-level object-oriented language
- python3.7 - An interactive high-level object-oriented language
- python3.8 - An interactive high-level object-oriented language
- python3.9 - An interactive high-level object-oriented language
Details
It was discovered that Python's http.cookies module incorrectly handled
control characters in certain cookie operations. An attacker could possibly
use this issue to inject arbitrary content. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-3644)
It was discovered that the Python pyexpat module was vulnerable to
unbounded recursion in the Expat XML parser. An attacker could possibly use
this issue to cause Python to crash, resulting in a denial of service. This
issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-4224)
It was discovered that Python's tarfile module did not correctly apply the
filter parameter when extracting hard links. An attacker could possibly...
It was discovered that Python's http.cookies module incorrectly handled
control characters in certain cookie operations. An attacker could possibly
use this issue to inject arbitrary content. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-3644)
It was discovered that the Python pyexpat module was vulnerable to
unbounded recursion in the Expat XML parser. An attacker could possibly use
this issue to cause Python to crash, resulting in a denial of service. This
issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-4224)
It was discovered that Python's tarfile module did not correctly apply the
filter parameter when extracting hard links. An attacker could possibly use
this issue to cause files to be extracted with an unexpected uid or gid,
bypassing the restrictions requested via filter='data'. (CVE-2026-4360)
It was discovered that Python's http.cookies module incorrectly escaped
values in the js_output() method. An attacker could possibly use this issue
to inject arbitrary JavaScript. (CVE-2026-6019)
It was discovered that Python's html.parser module incorrectly handled
repeated unterminated markup declarations. An attacker could possibly use
this issue to cause Python to consume excessive CPU resources, leading to a
denial of service. (CVE-2026-15308)
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
| Ubuntu Release | Package Version | ||
|---|---|---|---|
| 26.04 LTS resolute | libpython3.14 – 3.14.4-1ubuntu0.2 | ||
| python3.14 – 3.14.4-1ubuntu0.2 | |||
| 24.04 LTS noble | libpython3.12t64 – 3.12.3-1ubuntu0.17 | ||
| python3.12 – 3.12.3-1ubuntu0.17 | |||
| 22.04 LTS jammy | libpython2.7 – 2.7.18-13ubuntu1.5+esm9 | ||
| libpython3.10 – 3.10.12-1~22.04.18 | |||
| libpython3.11 – 3.11.0~rc1-1~22.04.1+esm2 | |||
| python2.7 – 2.7.18-13ubuntu1.5+esm9 | |||
| python3.10 – 3.10.12-1~22.04.18 | |||
| python3.11 – 3.11.0~rc1-1~22.04.1+esm2 | |||
| 20.04 LTS focal | libpython2.7 – 2.7.18-1~20.04.7+esm10 | ||
| libpython3.8 – 3.8.10-0ubuntu1~20.04.18+esm7 | |||
| libpython3.9 – 3.9.5-3ubuntu0~20.04.1+esm11 | |||
| python2.7 – 2.7.18-1~20.04.7+esm10 | |||
| python3.8 – 3.8.10-0ubuntu1~20.04.18+esm7 | |||
| python3.9 – 3.9.5-3ubuntu0~20.04.1+esm11 | |||
| 18.04 LTS bionic | libpython2.7 – 2.7.17-1~18.04ubuntu1.13+esm15 | ||
| libpython3.6 – 3.6.9-1~18.04ubuntu1.13+esm10 | |||
| libpython3.7 – 3.7.5-2ubuntu1~18.04.2+esm11 | |||
| libpython3.8 – 3.8.0-3ubuntu1~18.04.2+esm11 | |||
| python2.7 – 2.7.17-1~18.04ubuntu1.13+esm15 | |||
| python3.6 – 3.6.9-1~18.04ubuntu1.13+esm10 | |||
| python3.7 – 3.7.5-2ubuntu1~18.04.2+esm11 | |||
| python3.8 – 3.8.0-3ubuntu1~18.04.2+esm11 | |||
| 16.04 LTS xenial | libpython2.7 – 2.7.12-1ubuntu0~16.04.18+esm22 | ||
| libpython3.5 – 3.5.2-2ubuntu0~16.04.13+esm25 | |||
| python2.7 – 2.7.12-1ubuntu0~16.04.18+esm22 | |||
| python3.5 – 3.5.2-2ubuntu0~16.04.13+esm25 | |||
| 14.04 LTS trusty | libpython2.7 – 2.7.6-8ubuntu0.6+esm30 | ||
| libpython3.4 – 3.4.3-1ubuntu1~14.04.7+esm21 | |||
| libpython3.5 – 3.5.2-2ubuntu0~16.04.4~14.04.1+esm11 | |||
| python2.7 – 2.7.6-8ubuntu0.6+esm30 | |||
| python3.4 – 3.4.3-1ubuntu1~14.04.7+esm21 | |||
| python3.5 – 3.5.2-2ubuntu0~16.04.4~14.04.1+esm11 | |||
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.