[CLSA-2026:1785146736] Fix CVE(s): CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-27 10:05:47 UTC
Description:
* SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser - debian/patches/CVE-2026-15308.patch: buffer incoming feed() chunks in a list and only join and re-scan the unparsed buffer once the pending data crosses a doubling threshold (flushing in close()), so repeated unterminated markup declarations can no longer force quadratic rescanning/concatenation of uncontrolled data (CWE-407/CWE-1333). - CVE-2026-15308
CVEs fixed:
Updated packages:
  • alt-python311_3.11.15-4_amd64.deb
    sha:ada33736ede906023544486055148e9ce72d1396
  • alt-python311-debug_3.11.15-4_amd64.deb
    sha:5c2a4eb10b116e835f9fa127303aa0299a0ee110
  • alt-python311-devel_3.11.15-4_amd64.deb
    sha:1d788e3b6228b80f8c9f0285f95e044a244dbc88
  • alt-python311-idle_3.11.15-4_amd64.deb
    sha:8f1d7dc31e21e3ac03d11c69a50d601318c43ea5
  • alt-python311-libs_3.11.15-4_amd64.deb
    sha:d7606656d96e469827ae7b2858c7747030a77bcf
  • alt-python311-test_3.11.15-4_amd64.deb
    sha:09bc39009529baea58e0a5d0126791217eaac321
  • alt-python311-tkinter_3.11.15-4_amd64.deb
    sha:57750dedf419fe22f91b79d7eadc0e063813ed7b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.