[CLSA-2026:1785142492] Fix CVE(s): CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-27 08:55:05 UTC
Description:
* SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser - debian/patches/CVE-2026-15308.patch: buffer incoming feed() chunks in a list and only join and re-scan the unparsed buffer once the pending data crosses a doubling threshold (flushing in close()), so repeated unterminated markup declarations can no longer force quadratic rescanning/concatenation of uncontrolled data (CWE-407/CWE-1333). - CVE-2026-15308
CVEs fixed:
Updated packages:
  • alt-python311_3.11.15-4_amd64.deb
    sha:7ac610e81cd351919e723fb85590807651875faf
  • alt-python311-debug_3.11.15-4_amd64.deb
    sha:30d9104ce2092522c00b422e4c24f3ea750c596e
  • alt-python311-devel_3.11.15-4_amd64.deb
    sha:3eeff8570c5d4ae3438f8a3118d315c8775feb48
  • alt-python311-idle_3.11.15-4_amd64.deb
    sha:c93f695b3a0038bab77e5251202e693fa4a5450a
  • alt-python311-libs_3.11.15-4_amd64.deb
    sha:1151a3211144090c86837c0266fcbb2786b040b7
  • alt-python311-test_3.11.15-4_amd64.deb
    sha:66283f8cbd91557bd3a179c8ba2e1bc40db6b173
  • alt-python311-tkinter_3.11.15-4_amd64.deb
    sha:c0f2c6665a1af10daec65d127cd59a10b229a3bd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.