[CLSA-2026:1785143761] Fix CVE(s): CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-27 09:16:13 UTC
Description:
* SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser - debian/patches/CVE-2026-15308.patch: buffer incoming feed() chunks in a list and only join and re-scan the unparsed buffer once the pending data crosses a doubling threshold (flushing in close()), so repeated unterminated markup declarations can no longer force quadratic rescanning/concatenation of uncontrolled data (CWE-407/CWE-1333). - CVE-2026-15308
CVEs fixed:
Updated packages:
  • alt-python311_3.11.15-4_amd64.deb
    sha:192731d84a232e3477cd9f5204bd21a1a5325fff
  • alt-python311-debug_3.11.15-4_amd64.deb
    sha:85f0bc669d8b4086f067be49892fe56043fd1b9a
  • alt-python311-devel_3.11.15-4_amd64.deb
    sha:9a9a6bbc302ed6006b412b04ec2dea0f3d06d354
  • alt-python311-idle_3.11.15-4_amd64.deb
    sha:3823439663016cfaff6099984439609101f37f3f
  • alt-python311-libs_3.11.15-4_amd64.deb
    sha:44c0120b5a12151feb00ec4e4f083177b51fb516
  • alt-python311-test_3.11.15-4_amd64.deb
    sha:a17f641131a35ed6838a133223c358c02d94fe1c
  • alt-python311-tkinter_3.11.15-4_amd64.deb
    sha:60584457e43343b09919b60571f7c463b9eb0caa
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.