Release date:
2026-07-27 09:10:55 UTC
Description:
* SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser
- debian/patches/CVE-2026-15308.patch: buffer incoming feed() chunks in
a list and only join and re-scan the unparsed buffer once the pending
data crosses a doubling threshold (flushing in close()), so repeated
unterminated markup declarations can no longer force quadratic
rescanning/concatenation of uncontrolled data (CWE-407/CWE-1333).
- CVE-2026-15308
Updated packages:
-
alt-python311_3.11.15-4_amd64.deb
sha:0b553968b251dfec1d10c569f60970a48dc8ed5d
-
alt-python311-debug_3.11.15-4_amd64.deb
sha:f7cd22a4749b5a78cafa7a66eb7417f4f1860c23
-
alt-python311-devel_3.11.15-4_amd64.deb
sha:f61173488dcb333ac181b1fad932b5b7169d9b6b
-
alt-python311-idle_3.11.15-4_amd64.deb
sha:67bc4d76b3dbce5bb5404136d62c88e043655530
-
alt-python311-libs_3.11.15-4_amd64.deb
sha:31e2f800154d0e9183cc54a3e416749713e27dea
-
alt-python311-test_3.11.15-4_amd64.deb
sha:90c659dc2f3eb7eec6b5aa0a9a5860ca0a1dac9b
-
alt-python311-tkinter_3.11.15-4_amd64.deb
sha:78d6d60c20b7064d1e9c9060dc81a3bd5cbe0ad9
-
alt-python311_3.11.15-4_arm64.deb
sha:80b00e757e647295d300bf3169b3bdc2cfe2a1ea
-
alt-python311-debug_3.11.15-4_arm64.deb
sha:62c90e44e2c5e97a9b6bd019641896ca19483bcd
-
alt-python311-devel_3.11.15-4_arm64.deb
sha:d724b0d36ed2ec861070554c0c2c5df1fc94948c
-
alt-python311-idle_3.11.15-4_arm64.deb
sha:cf9666f52232e89cd6041c7ce4102f14404b87eb
-
alt-python311-libs_3.11.15-4_arm64.deb
sha:501e97b91a6f71f73e47afc0305b5714ad4b9a6c
-
alt-python311-test_3.11.15-4_arm64.deb
sha:5e5ed00a227483e8f25346113224b7c277f23e6f
-
alt-python311-tkinter_3.11.15-4_arm64.deb
sha:da2f1ff719ccec1cb65ce72654cb6e96e04bfebc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.