Release date:
2026-07-27 09:00:41 UTC
Description:
* SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser
- debian/patches/CVE-2026-15308.patch: buffer incoming feed() chunks in
a list and only join and re-scan the unparsed buffer once the pending
data crosses a doubling threshold (flushing in close()), so repeated
unterminated markup declarations can no longer force quadratic
rescanning/concatenation of uncontrolled data (CWE-407/CWE-1333).
- CVE-2026-15308
Updated packages:
-
alt-python311_3.11.15-4_amd64.deb
sha:f4fb1f441f38cad5b057b69f5b6760f8da887547
-
alt-python311-debug_3.11.15-4_amd64.deb
sha:d403cd7856cd4e95dac1eea73da3c2f1459855bb
-
alt-python311-devel_3.11.15-4_amd64.deb
sha:db45e958ce25039cb6968ed0899c26fc5e1d6b80
-
alt-python311-idle_3.11.15-4_amd64.deb
sha:9504555ac0275efa032b30716b018e46d6d15927
-
alt-python311-libs_3.11.15-4_amd64.deb
sha:13e937c6e25839a6f40d1f2413c3ab3d50371e14
-
alt-python311-test_3.11.15-4_amd64.deb
sha:e489f77a8194f8c2d20b9ccc28e54b4573cea8c7
-
alt-python311-tkinter_3.11.15-4_amd64.deb
sha:e74f44dea080ce5a67c375be2d309e95e59db364
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.