Release date:
2026-07-27 08:22:35 UTC
Description:
* SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser
- debian/patches/CVE-2026-15308.patch: buffer incoming feed() chunks in
a list and only join and re-scan the unparsed buffer once the pending
data crosses a doubling threshold (flushing in close()), so repeated
unterminated markup declarations can no longer force quadratic
rescanning/concatenation of uncontrolled data (CWE-407/CWE-1333).
- CVE-2026-15308
Updated packages:
-
alt-python311_3.11.15-4_amd64.deb
sha:e2c300d1461013e4d2b4eb7b5e4e795b2a0351aa
-
alt-python311-debug_3.11.15-4_amd64.deb
sha:f7cd22a4749b5a78cafa7a66eb7417f4f1860c23
-
alt-python311-devel_3.11.15-4_amd64.deb
sha:edb287aecf7ab215d3e5a30091e6616c3c6f8438
-
alt-python311-idle_3.11.15-4_amd64.deb
sha:d0c4e68e22b8d146a2df5503cbfec215e6671c67
-
alt-python311-libs_3.11.15-4_amd64.deb
sha:93826d4557ad79f26d59bf943bccd5ccc4a68ece
-
alt-python311-test_3.11.15-4_amd64.deb
sha:b4daa1c60ed2d12b4aa5e63d354e0a7e0a3dd858
-
alt-python311-tkinter_3.11.15-4_amd64.deb
sha:afbbf7a9b15b59beadcfc7f3d93ebd396cb5d8ad
-
alt-python311_3.11.15-4_arm64.deb
sha:23ecd0a16f6f1cb89fe20637ef3643216fd919ec
-
alt-python311-debug_3.11.15-4_arm64.deb
sha:62c90e44e2c5e97a9b6bd019641896ca19483bcd
-
alt-python311-devel_3.11.15-4_arm64.deb
sha:cf4bb5cce1d7bd28af5b6315b4726cb0522c6ea0
-
alt-python311-idle_3.11.15-4_arm64.deb
sha:e32272d5aef15d42a17ce880d41f30015ccce3fd
-
alt-python311-libs_3.11.15-4_arm64.deb
sha:7c597e2bdd5f18a4cf354024d191f51748f0a202
-
alt-python311-test_3.11.15-4_arm64.deb
sha:3c69a739287cb4d9ff8ac62ba9eb3698d78db049
-
alt-python311-tkinter_3.11.15-4_arm64.deb
sha:129d0b06a351117c2a5ab6eb6d60b3ed664b2106
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.