[CLSA-2026:1785147561] Fix CVE(s): CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-27 10:19:31 UTC
Description:
* SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser - debian/patches/CVE-2026-15308.patch: buffer incoming feed() chunks in a list and only join and re-scan the unparsed buffer once the pending data crosses a doubling threshold (flushing in close()), so repeated unterminated markup declarations can no longer force quadratic rescanning/concatenation of uncontrolled data (CWE-407/CWE-1333). - CVE-2026-15308
CVEs fixed:
Updated packages:
  • alt-python311_3.11.15-4_amd64.deb
    sha:cd39e3668cbeb0a0b747385afd94375a63d7685e
  • alt-python311-debug_3.11.15-4_amd64.deb
    sha:f7cd22a4749b5a78cafa7a66eb7417f4f1860c23
  • alt-python311-devel_3.11.15-4_amd64.deb
    sha:cdb8d3a88cd67b3978e2b12359e4eed63eacb058
  • alt-python311-idle_3.11.15-4_amd64.deb
    sha:46a5af119a6ce4cd3f0062924da501546c2d25c5
  • alt-python311-libs_3.11.15-4_amd64.deb
    sha:71d27f5534c3a616ab1b9c6f448fc27fbca45805
  • alt-python311-test_3.11.15-4_amd64.deb
    sha:3e66cd18906de9e75af3afe572ff545220b80597
  • alt-python311-tkinter_3.11.15-4_amd64.deb
    sha:de0dd0522665be4d1c5c81be11bd5369720cbd27
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.