Release date:
2026-07-27 10:19:31 UTC
Description:
* SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser
- debian/patches/CVE-2026-15308.patch: buffer incoming feed() chunks in
a list and only join and re-scan the unparsed buffer once the pending
data crosses a doubling threshold (flushing in close()), so repeated
unterminated markup declarations can no longer force quadratic
rescanning/concatenation of uncontrolled data (CWE-407/CWE-1333).
- CVE-2026-15308
Updated packages:
-
alt-python311_3.11.15-4_amd64.deb
sha:cd39e3668cbeb0a0b747385afd94375a63d7685e
-
alt-python311-debug_3.11.15-4_amd64.deb
sha:f7cd22a4749b5a78cafa7a66eb7417f4f1860c23
-
alt-python311-devel_3.11.15-4_amd64.deb
sha:cdb8d3a88cd67b3978e2b12359e4eed63eacb058
-
alt-python311-idle_3.11.15-4_amd64.deb
sha:46a5af119a6ce4cd3f0062924da501546c2d25c5
-
alt-python311-libs_3.11.15-4_amd64.deb
sha:71d27f5534c3a616ab1b9c6f448fc27fbca45805
-
alt-python311-test_3.11.15-4_amd64.deb
sha:3e66cd18906de9e75af3afe572ff545220b80597
-
alt-python311-tkinter_3.11.15-4_amd64.deb
sha:de0dd0522665be4d1c5c81be11bd5369720cbd27
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.