[CLSA-2026:1785140544] Fix CVE(s): CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-27 08:22:35 UTC
Description:
* SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser - debian/patches/CVE-2026-15308.patch: buffer incoming feed() chunks in a list and only join and re-scan the unparsed buffer once the pending data crosses a doubling threshold (flushing in close()), so repeated unterminated markup declarations can no longer force quadratic rescanning/concatenation of uncontrolled data (CWE-407/CWE-1333). - CVE-2026-15308
CVEs fixed:
Updated packages:
  • alt-python311_3.11.15-4_amd64.deb
    sha:e2c300d1461013e4d2b4eb7b5e4e795b2a0351aa
  • alt-python311-debug_3.11.15-4_amd64.deb
    sha:f7cd22a4749b5a78cafa7a66eb7417f4f1860c23
  • alt-python311-devel_3.11.15-4_amd64.deb
    sha:edb287aecf7ab215d3e5a30091e6616c3c6f8438
  • alt-python311-idle_3.11.15-4_amd64.deb
    sha:d0c4e68e22b8d146a2df5503cbfec215e6671c67
  • alt-python311-libs_3.11.15-4_amd64.deb
    sha:93826d4557ad79f26d59bf943bccd5ccc4a68ece
  • alt-python311-test_3.11.15-4_amd64.deb
    sha:b4daa1c60ed2d12b4aa5e63d354e0a7e0a3dd858
  • alt-python311-tkinter_3.11.15-4_amd64.deb
    sha:afbbf7a9b15b59beadcfc7f3d93ebd396cb5d8ad
  • alt-python311_3.11.15-4_arm64.deb
    sha:23ecd0a16f6f1cb89fe20637ef3643216fd919ec
  • alt-python311-debug_3.11.15-4_arm64.deb
    sha:62c90e44e2c5e97a9b6bd019641896ca19483bcd
  • alt-python311-devel_3.11.15-4_arm64.deb
    sha:cf4bb5cce1d7bd28af5b6315b4726cb0522c6ea0
  • alt-python311-idle_3.11.15-4_arm64.deb
    sha:e32272d5aef15d42a17ce880d41f30015ccce3fd
  • alt-python311-libs_3.11.15-4_arm64.deb
    sha:7c597e2bdd5f18a4cf354024d191f51748f0a202
  • alt-python311-test_3.11.15-4_arm64.deb
    sha:3c69a739287cb4d9ff8ac62ba9eb3698d78db049
  • alt-python311-tkinter_3.11.15-4_arm64.deb
    sha:129d0b06a351117c2a5ab6eb6d60b3ed664b2106
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.