Release date:
2026-07-27 10:05:47 UTC
Description:
* SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser
- debian/patches/CVE-2026-15308.patch: buffer incoming feed() chunks in
a list and only join and re-scan the unparsed buffer once the pending
data crosses a doubling threshold (flushing in close()), so repeated
unterminated markup declarations can no longer force quadratic
rescanning/concatenation of uncontrolled data (CWE-407/CWE-1333).
- CVE-2026-15308
Updated packages:
-
alt-python311_3.11.15-4_amd64.deb
sha:ada33736ede906023544486055148e9ce72d1396
-
alt-python311-debug_3.11.15-4_amd64.deb
sha:5c2a4eb10b116e835f9fa127303aa0299a0ee110
-
alt-python311-devel_3.11.15-4_amd64.deb
sha:1d788e3b6228b80f8c9f0285f95e044a244dbc88
-
alt-python311-idle_3.11.15-4_amd64.deb
sha:8f1d7dc31e21e3ac03d11c69a50d601318c43ea5
-
alt-python311-libs_3.11.15-4_amd64.deb
sha:d7606656d96e469827ae7b2858c7747030a77bcf
-
alt-python311-test_3.11.15-4_amd64.deb
sha:09bc39009529baea58e0a5d0126791217eaac321
-
alt-python311-tkinter_3.11.15-4_amd64.deb
sha:57750dedf419fe22f91b79d7eadc0e063813ed7b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.