Release date:
2026-07-27 10:24:30 UTC
Description:
* SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser
- debian/patches/CVE-2026-15308.patch: buffer incoming feed() chunks in
a list and only join and re-scan the unparsed buffer once the pending
data crosses a doubling threshold (flushing in close()), so repeated
unterminated markup declarations can no longer force quadratic
rescanning/concatenation of uncontrolled data (CWE-407/CWE-1333).
- CVE-2026-15308
Updated packages:
-
alt-python311_3.11.15-4_amd64.deb
sha:7c48ae4cf22241c200257d658a2f92fc8fdd70e8
-
alt-python311-debug_3.11.15-4_amd64.deb
sha:f7cd22a4749b5a78cafa7a66eb7417f4f1860c23
-
alt-python311-devel_3.11.15-4_amd64.deb
sha:db5dc33c25631f6cb651516f06125251985f8c78
-
alt-python311-idle_3.11.15-4_amd64.deb
sha:d0c4e68e22b8d146a2df5503cbfec215e6671c67
-
alt-python311-libs_3.11.15-4_amd64.deb
sha:7f699fecf5b1a7b6e9f380e0c73130f100e52dda
-
alt-python311-test_3.11.15-4_amd64.deb
sha:6fc7b2d8aab070fe43f689f4e4dc60c4234f15dc
-
alt-python311-tkinter_3.11.15-4_amd64.deb
sha:7c144770b471b74b8c280f8b70ba07d2ad8ac689
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.