Release date:
2026-07-27 09:05:52 UTC
Description:
* SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser
- debian/patches/CVE-2026-15308.patch: buffer incoming feed() chunks in
a list and only join and re-scan the unparsed buffer once the pending
data crosses a doubling threshold (flushing in close()), so repeated
unterminated markup declarations can no longer force quadratic
rescanning/concatenation of uncontrolled data (CWE-407/CWE-1333).
- CVE-2026-15308
Updated packages:
-
alt-python311_3.11.15-4_amd64.deb
sha:6677ec7eacd39801c8855f19104995607bb7b2a8
-
alt-python311-debug_3.11.15-4_amd64.deb
sha:d403cd7856cd4e95dac1eea73da3c2f1459855bb
-
alt-python311-devel_3.11.15-4_amd64.deb
sha:a2a3255b96fbb3b806e8e523046e8e1ab9e46bad
-
alt-python311-idle_3.11.15-4_amd64.deb
sha:95bbecb3bdcea8cc0420e414cafa76e85acaf620
-
alt-python311-libs_3.11.15-4_amd64.deb
sha:a0b409725ce3d0379859b08306925f8e9bb27686
-
alt-python311-test_3.11.15-4_amd64.deb
sha:c71da9bdfc3ca6d77f80c78b18b44d8bbdff551d
-
alt-python311-tkinter_3.11.15-4_amd64.deb
sha:b09871509a2e6cae9dbbe07ca15bbf2a259c8a0f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.