Release date:
2026-07-27 08:55:05 UTC
Description:
* SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser
- debian/patches/CVE-2026-15308.patch: buffer incoming feed() chunks in
a list and only join and re-scan the unparsed buffer once the pending
data crosses a doubling threshold (flushing in close()), so repeated
unterminated markup declarations can no longer force quadratic
rescanning/concatenation of uncontrolled data (CWE-407/CWE-1333).
- CVE-2026-15308
Updated packages:
-
alt-python311_3.11.15-4_amd64.deb
sha:7ac610e81cd351919e723fb85590807651875faf
-
alt-python311-debug_3.11.15-4_amd64.deb
sha:30d9104ce2092522c00b422e4c24f3ea750c596e
-
alt-python311-devel_3.11.15-4_amd64.deb
sha:3eeff8570c5d4ae3438f8a3118d315c8775feb48
-
alt-python311-idle_3.11.15-4_amd64.deb
sha:c93f695b3a0038bab77e5251202e693fa4a5450a
-
alt-python311-libs_3.11.15-4_amd64.deb
sha:1151a3211144090c86837c0266fcbb2786b040b7
-
alt-python311-test_3.11.15-4_amd64.deb
sha:66283f8cbd91557bd3a179c8ba2e1bc40db6b173
-
alt-python311-tkinter_3.11.15-4_amd64.deb
sha:c0f2c6665a1af10daec65d127cd59a10b229a3bd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.