{"id":"USN-8614-1","summary":"python2.7, python3.5 vulnerabilities","details":"It was discovered that Python incorrectly handled expanding environment\nvariables in os.path.expandvars() when the input was user-controlled. An\nattacker could possibly use this issue to cause Python to consume\nresources, leading to a denial of service. (CVE-2025-6075)\n\nIt was discovered that Python incorrectly handled certain malformed\nHTML-like markup in the HTMLParser module, raising an uncaught exception.\nA remote attacker could possibly use this issue to cause applications that\nparse untrusted input to crash, resulting in a denial of service.\n(CVE-2025-69534)","modified":"2026-07-28T16:45:15.970710317Z","published":"2026-07-27T16:37:15Z","related":["UBUNTU-CVE-2025-6075","UBUNTU-CVE-2025-69534"],"upstream":["CVE-2025-6075","CVE-2025-69534","UBUNTU-CVE-2025-6075","UBUNTU-CVE-2025-69534"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8614-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-6075"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-69534"}],"affected":[{"package":{"name":"python2.7","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/python2.7?arch=source&distro=esm-infra-legacy%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.7.12-1ubuntu0~16.04.18+esm21"}]}],"versions":["2.7.10-4ubuntu1","2.7.10-4ubuntu2","2.7.11-2","2.7.11-3","2.7.11-4","2.7.11-6","2.7.11-7","2.7.11-7ubuntu1","2.7.12-1~16.04","2.7.12-1ubuntu0~16.04.1","2.7.12-1ubuntu0~16.04.2","2.7.12-1ubuntu0~16.04.3","2.7.12-1ubuntu0~16.04.4","2.7.12-1ubuntu0~16.04.8","2.7.12-1ubuntu0~16.04.9","2.7.12-1ubuntu0~16.04.11","2.7.12-1ubuntu0~16.04.12","2.7.12-1ubuntu0~16.04.13","2.7.12-1ubuntu0~16.04.14","2.7.12-1ubuntu0~16.04.16","2.7.12-1ubuntu0~16.04.18","2.7.12-1ubuntu0~16.04.18+esm1","2.7.12-1ubuntu0~16.04.18+esm2","2.7.12-1ubuntu0~16.04.18+esm3","2.7.12-1ubuntu0~16.04.18+esm4","2.7.12-1ubuntu0~16.04.18+esm5","2.7.12-1ubuntu0~16.04.18+esm6","2.7.12-1ubuntu0~16.04.18+esm7","2.7.12-1ubuntu0~16.04.18+esm8","2.7.12-1ubuntu0~16.04.18+esm9","2.7.12-1ubuntu0~16.04.18+esm10","2.7.12-1ubuntu0~16.04.18+esm11","2.7.12-1ubuntu0~16.04.18+esm12","2.7.12-1ubuntu0~16.04.18+esm13","2.7.12-1ubuntu0~16.04.18+esm15","2.7.12-1ubuntu0~16.04.18+esm16","2.7.12-1ubuntu0~16.04.18+esm17","2.7.12-1ubuntu0~16.04.18+esm18","2.7.12-1ubuntu0~16.04.18+esm19","2.7.12-1ubuntu0~16.04.18+esm20"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro","binaries":[{"binary_name":"idle-python2.7","binary_version":"2.7.12-1ubuntu0~16.04.18+esm21"},{"binary_name":"libpython2.7","binary_version":"2.7.12-1ubuntu0~16.04.18+esm21"},{"binary_name":"libpython2.7-minimal","binary_version":"2.7.12-1ubuntu0~16.04.18+esm21"},{"binary_version":"2.7.12-1ubuntu0~16.04.18+esm21","binary_name":"libpython2.7-stdlib"},{"binary_version":"2.7.12-1ubuntu0~16.04.18+esm21","binary_name":"libpython2.7-testsuite"},{"binary_name":"python2.7","binary_version":"2.7.12-1ubuntu0~16.04.18+esm21"},{"binary_version":"2.7.12-1ubuntu0~16.04.18+esm21","binary_name":"python2.7-examples"},{"binary_name":"python2.7-minimal","binary_version":"2.7.12-1ubuntu0~16.04.18+esm21"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:16.04:LTS","cves":[{"id":"CVE-2025-6075","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2025-69534"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8614-1.json"}},{"package":{"name":"python3.5","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/python3.5?arch=source&distro=esm-infra-legacy%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.5.2-2ubuntu0~16.04.13+esm24"}]}],"versions":["3.5.0-3","3.5.0-3ubuntu1","3.5.1~rc1-2ubuntu1","3.5.1-1","3.5.1-2","3.5.1-3","3.5.1-5","3.5.1-6ubuntu1","3.5.1-6ubuntu2","3.5.1-9ubuntu1","3.5.1-10","3.5.2-2~16.01","3.5.2-2~16.04","3.5.2-2ubuntu0~16.04.1","3.5.2-2ubuntu0~16.04.2","3.5.2-2ubuntu0~16.04.3","3.5.2-2ubuntu0~16.04.4","3.5.2-2ubuntu0~16.04.5","3.5.2-2ubuntu0~16.04.8","3.5.2-2ubuntu0~16.04.9","3.5.2-2ubuntu0~16.04.10","3.5.2-2ubuntu0~16.04.11","3.5.2-2ubuntu0~16.04.12","3.5.2-2ubuntu0~16.04.13","3.5.2-2ubuntu0~16.04.13+esm1","3.5.2-2ubuntu0~16.04.13+esm2","3.5.2-2ubuntu0~16.04.13+esm3","3.5.2-2ubuntu0~16.04.13+esm5","3.5.2-2ubuntu0~16.04.13+esm6","3.5.2-2ubuntu0~16.04.13+esm7","3.5.2-2ubuntu0~16.04.13+esm8","3.5.2-2ubuntu0~16.04.13+esm9","3.5.2-2ubuntu0~16.04.13+esm10","3.5.2-2ubuntu0~16.04.13+esm11","3.5.2-2ubuntu0~16.04.13+esm12","3.5.2-2ubuntu0~16.04.13+esm13","3.5.2-2ubuntu0~16.04.13+esm14","3.5.2-2ubuntu0~16.04.13+esm15","3.5.2-2ubuntu0~16.04.13+esm16","3.5.2-2ubuntu0~16.04.13+esm17","3.5.2-2ubuntu0~16.04.13+esm18","3.5.2-2ubuntu0~16.04.13+esm19","3.5.2-2ubuntu0~16.04.13+esm20","3.5.2-2ubuntu0~16.04.13+esm21","3.5.2-2ubuntu0~16.04.13+esm22","3.5.2-2ubuntu0~16.04.13+esm23"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro","binaries":[{"binary_name":"idle-python3.5","binary_version":"3.5.2-2ubuntu0~16.04.13+esm24"},{"binary_name":"libpython3.5","binary_version":"3.5.2-2ubuntu0~16.04.13+esm24"},{"binary_name":"libpython3.5-minimal","binary_version":"3.5.2-2ubuntu0~16.04.13+esm24"},{"binary_version":"3.5.2-2ubuntu0~16.04.13+esm24","binary_name":"libpython3.5-stdlib"},{"binary_name":"libpython3.5-testsuite","binary_version":"3.5.2-2ubuntu0~16.04.13+esm24"},{"binary_version":"3.5.2-2ubuntu0~16.04.13+esm24","binary_name":"python3.5"},{"binary_name":"python3.5-examples","binary_version":"3.5.2-2ubuntu0~16.04.13+esm24"},{"binary_version":"3.5.2-2ubuntu0~16.04.13+esm24","binary_name":"python3.5-minimal"},{"binary_version":"3.5.2-2ubuntu0~16.04.13+esm24","binary_name":"python3.5-venv"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:16.04:LTS","cves":[{"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-6075"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2025-69534"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8614-1.json"}}],"schema_version":"1.7.5"}