Release date:
2026-07-27 09:16:13 UTC
Description:
* SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser
- debian/patches/CVE-2026-15308.patch: buffer incoming feed() chunks in
a list and only join and re-scan the unparsed buffer once the pending
data crosses a doubling threshold (flushing in close()), so repeated
unterminated markup declarations can no longer force quadratic
rescanning/concatenation of uncontrolled data (CWE-407/CWE-1333).
- CVE-2026-15308
Updated packages:
-
alt-python311_3.11.15-4_amd64.deb
sha:192731d84a232e3477cd9f5204bd21a1a5325fff
-
alt-python311-debug_3.11.15-4_amd64.deb
sha:85f0bc669d8b4086f067be49892fe56043fd1b9a
-
alt-python311-devel_3.11.15-4_amd64.deb
sha:9a9a6bbc302ed6006b412b04ec2dea0f3d06d354
-
alt-python311-idle_3.11.15-4_amd64.deb
sha:3823439663016cfaff6099984439609101f37f3f
-
alt-python311-libs_3.11.15-4_amd64.deb
sha:44c0120b5a12151feb00ec4e4f083177b51fb516
-
alt-python311-test_3.11.15-4_amd64.deb
sha:a17f641131a35ed6838a133223c358c02d94fe1c
-
alt-python311-tkinter_3.11.15-4_amd64.deb
sha:60584457e43343b09919b60571f7c463b9eb0caa
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.