[CLSA-2026:1786352720] python: Fix of CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-08-10 09:05:30 UTC
Description:
- CVE-2026-15308: fix quadratic-complexity CPU denial-of-service in the HTMLParser incremental parser - accumulate feed() data in a buffer and only join/rescan once enough has piled up, instead of re-concatenating and re-scanning the whole unparsed buffer on every feed() call. Backported from upstream CPython (gh-153030, GH-153031).
CVEs fixed:
Updated packages:
  • python-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:712a6a8ffbe5ba7604fb15c56b5239da24b88d806cb81d7fbfd9b43833f4847e
  • python-debug-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:b6e0d373b1527b76239f90c71a35eaef547b29c35b4479b929416842e746b154
  • python-devel-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:a2605865e40aa4812639ec48d17269c0abc5bfb0eebd292196079e6a31c47663
  • python-libs-2.7.5-94.0.1.el7_9.tuxcare.els12.i686.rpm
    sha:ec536853aeb693cde48b872d91c286cbc47df4a3c059dc1d941a16cb82c7e816
  • python-libs-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:6771d73036c33905989007d6fcf339003efd5f2f57e9334b77e99594ae94bfea
  • python-test-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:567fd30edfa5798292ced08d850ae011cfe757d970d9d34e2b66f30658d27413
  • python-tools-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:955f686edec1f0d9b8cb35a2cd718236504256ca3c6c28912dc3de2d46fa6b9c
  • tkinter-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:eba7352ea3ef370bd16be81b31494467a002f845a49ea7ed864eed301fc434bb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.