[CLSA-2026:1785142828] Fix CVE(s): CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-27 09:00:41 UTC
Description:
* SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser - debian/patches/CVE-2026-15308.patch: buffer incoming feed() chunks in a list and only join and re-scan the unparsed buffer once the pending data crosses a doubling threshold (flushing in close()), so repeated unterminated markup declarations can no longer force quadratic rescanning/concatenation of uncontrolled data (CWE-407/CWE-1333). - CVE-2026-15308
CVEs fixed:
Updated packages:
  • alt-python311_3.11.15-4_amd64.deb
    sha:f4fb1f441f38cad5b057b69f5b6760f8da887547
  • alt-python311-debug_3.11.15-4_amd64.deb
    sha:d403cd7856cd4e95dac1eea73da3c2f1459855bb
  • alt-python311-devel_3.11.15-4_amd64.deb
    sha:db45e958ce25039cb6968ed0899c26fc5e1d6b80
  • alt-python311-idle_3.11.15-4_amd64.deb
    sha:9504555ac0275efa032b30716b018e46d6d15927
  • alt-python311-libs_3.11.15-4_amd64.deb
    sha:13e937c6e25839a6f40d1f2413c3ab3d50371e14
  • alt-python311-test_3.11.15-4_amd64.deb
    sha:e489f77a8194f8c2d20b9ccc28e54b4573cea8c7
  • alt-python311-tkinter_3.11.15-4_amd64.deb
    sha:e74f44dea080ce5a67c375be2d309e95e59db364
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.