[CLSA-2026:1785147858] Fix CVE(s): CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-27 10:24:30 UTC
Description:
* SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser - debian/patches/CVE-2026-15308.patch: buffer incoming feed() chunks in a list and only join and re-scan the unparsed buffer once the pending data crosses a doubling threshold (flushing in close()), so repeated unterminated markup declarations can no longer force quadratic rescanning/concatenation of uncontrolled data (CWE-407/CWE-1333). - CVE-2026-15308
CVEs fixed:
Updated packages:
  • alt-python311_3.11.15-4_amd64.deb
    sha:7c48ae4cf22241c200257d658a2f92fc8fdd70e8
  • alt-python311-debug_3.11.15-4_amd64.deb
    sha:f7cd22a4749b5a78cafa7a66eb7417f4f1860c23
  • alt-python311-devel_3.11.15-4_amd64.deb
    sha:db5dc33c25631f6cb651516f06125251985f8c78
  • alt-python311-idle_3.11.15-4_amd64.deb
    sha:d0c4e68e22b8d146a2df5503cbfec215e6671c67
  • alt-python311-libs_3.11.15-4_amd64.deb
    sha:7f699fecf5b1a7b6e9f380e0c73130f100e52dda
  • alt-python311-test_3.11.15-4_amd64.deb
    sha:6fc7b2d8aab070fe43f689f4e4dc60c4234f15dc
  • alt-python311-tkinter_3.11.15-4_amd64.deb
    sha:7c144770b471b74b8c280f8b70ba07d2ad8ac689
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.