[CLSA-2026:1784887717] Fix CVE(s): CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-24 10:09:03 UTC
Description:
* SECURITY UPDATE: quadratic-complexity CPU denial of service in html.parser - debian/patches/CVE-2026-15308.patch: accumulate incremental feed() data to avoid re-scanning/concatenating unterminated constructs quadratically - CVE-2026-15308
CVEs fixed:
Updated packages:
  • alt-python310_3.10.20-5_amd64.deb
    sha:87dce5ac1668c382426b6b855b3885e3e1af6ff1
  • alt-python310-debug_3.10.20-5_amd64.deb
    sha:5b1d452d358bcdd41edf6620d0c98c4bf10074d9
  • alt-python310-devel_3.10.20-5_amd64.deb
    sha:7a0e64c4dd1b21d6e75b3bc9ae7e19c5c04a0579
  • alt-python310-idle_3.10.20-5_amd64.deb
    sha:a336351f33e8e1b4b8ca46d78b0be9307ed70b3c
  • alt-python310-libs_3.10.20-5_amd64.deb
    sha:82c147ac7c21058fc5f2f099fbd4f3af4891a156
  • alt-python310-test_3.10.20-5_amd64.deb
    sha:26e18d0fe3170a3b896ce0f5b6de60b8c896fd24
  • alt-python310-tkinter_3.10.20-5_amd64.deb
    sha:6a960ed58d27d82095724d884702dde74a340ac3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.