[CLSA-2026:1785143443] Fix CVE(s): CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-27 09:10:55 UTC
Description:
* SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser - debian/patches/CVE-2026-15308.patch: buffer incoming feed() chunks in a list and only join and re-scan the unparsed buffer once the pending data crosses a doubling threshold (flushing in close()), so repeated unterminated markup declarations can no longer force quadratic rescanning/concatenation of uncontrolled data (CWE-407/CWE-1333). - CVE-2026-15308
CVEs fixed:
Updated packages:
  • alt-python311_3.11.15-4_amd64.deb
    sha:0b553968b251dfec1d10c569f60970a48dc8ed5d
  • alt-python311-debug_3.11.15-4_amd64.deb
    sha:f7cd22a4749b5a78cafa7a66eb7417f4f1860c23
  • alt-python311-devel_3.11.15-4_amd64.deb
    sha:f61173488dcb333ac181b1fad932b5b7169d9b6b
  • alt-python311-idle_3.11.15-4_amd64.deb
    sha:67bc4d76b3dbce5bb5404136d62c88e043655530
  • alt-python311-libs_3.11.15-4_amd64.deb
    sha:31e2f800154d0e9183cc54a3e416749713e27dea
  • alt-python311-test_3.11.15-4_amd64.deb
    sha:90c659dc2f3eb7eec6b5aa0a9a5860ca0a1dac9b
  • alt-python311-tkinter_3.11.15-4_amd64.deb
    sha:78d6d60c20b7064d1e9c9060dc81a3bd5cbe0ad9
  • alt-python311_3.11.15-4_arm64.deb
    sha:80b00e757e647295d300bf3169b3bdc2cfe2a1ea
  • alt-python311-debug_3.11.15-4_arm64.deb
    sha:62c90e44e2c5e97a9b6bd019641896ca19483bcd
  • alt-python311-devel_3.11.15-4_arm64.deb
    sha:d724b0d36ed2ec861070554c0c2c5df1fc94948c
  • alt-python311-idle_3.11.15-4_arm64.deb
    sha:cf9666f52232e89cd6041c7ce4102f14404b87eb
  • alt-python311-libs_3.11.15-4_arm64.deb
    sha:501e97b91a6f71f73e47afc0305b5714ad4b9a6c
  • alt-python311-test_3.11.15-4_arm64.deb
    sha:5e5ed00a227483e8f25346113224b7c277f23e6f
  • alt-python311-tkinter_3.11.15-4_arm64.deb
    sha:da2f1ff719ccec1cb65ce72654cb6e96e04bfebc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.