[CLSA-2026:1785143140] Fix CVE(s): CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-27 09:05:52 UTC
Description:
* SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser - debian/patches/CVE-2026-15308.patch: buffer incoming feed() chunks in a list and only join and re-scan the unparsed buffer once the pending data crosses a doubling threshold (flushing in close()), so repeated unterminated markup declarations can no longer force quadratic rescanning/concatenation of uncontrolled data (CWE-407/CWE-1333). - CVE-2026-15308
CVEs fixed:
Updated packages:
  • alt-python311_3.11.15-4_amd64.deb
    sha:6677ec7eacd39801c8855f19104995607bb7b2a8
  • alt-python311-debug_3.11.15-4_amd64.deb
    sha:d403cd7856cd4e95dac1eea73da3c2f1459855bb
  • alt-python311-devel_3.11.15-4_amd64.deb
    sha:a2a3255b96fbb3b806e8e523046e8e1ab9e46bad
  • alt-python311-idle_3.11.15-4_amd64.deb
    sha:95bbecb3bdcea8cc0420e414cafa76e85acaf620
  • alt-python311-libs_3.11.15-4_amd64.deb
    sha:a0b409725ce3d0379859b08306925f8e9bb27686
  • alt-python311-test_3.11.15-4_amd64.deb
    sha:c71da9bdfc3ca6d77f80c78b18b44d8bbdff551d
  • alt-python311-tkinter_3.11.15-4_amd64.deb
    sha:b09871509a2e6cae9dbbe07ca15bbf2a259c8a0f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.