[CLSA-2026:1784270796] Fix CVE(s): CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-17 06:46:59 UTC
Description:
* SECURITY UPDATE: CPU denial-of-service in the html.parser module via repeated unterminated markup declarations (quadratic complexity in the incremental HTMLParser) - debian/patches/CVE-2026-15308.patch: accumulate pending data in feed() and parse on a doubling threshold instead of rescanning the whole unparsed buffer each call, in Lib/html/parser.py - CVE-2026-15308
CVEs fixed:
Updated packages:
  • idle-python3.6_3.6.9-1~18.04ubuntu1.12+tuxcare.els24_all.deb
    sha:555f10b67b38fbef7841ded08a912d277b5879f0
  • libpython3.6_3.6.9-1~18.04ubuntu1.12+tuxcare.els24_amd64.deb
    sha:eea3644c956294875e6a5c5ee7b3b4b136cf0c53
  • libpython3.6-dev_3.6.9-1~18.04ubuntu1.12+tuxcare.els24_amd64.deb
    sha:a25be845348ec254340419ddd1cdba2ca762c732
  • libpython3.6-minimal_3.6.9-1~18.04ubuntu1.12+tuxcare.els24_amd64.deb
    sha:2f4bd68a5500d589e70fec52d07f361bfe7b6eeb
  • libpython3.6-stdlib_3.6.9-1~18.04ubuntu1.12+tuxcare.els24_amd64.deb
    sha:ad8c9573aa8fbfa8ab43b83a427f1894ba92f123
  • libpython3.6-testsuite_3.6.9-1~18.04ubuntu1.12+tuxcare.els24_all.deb
    sha:6137510c8161b657d269b47c5aa9bd6d1255b6d7
  • python3.6_3.6.9-1~18.04ubuntu1.12+tuxcare.els24_amd64.deb
    sha:98560bde4086f09323859f36f0ebae1e1894f546
  • python3.6-dev_3.6.9-1~18.04ubuntu1.12+tuxcare.els24_amd64.deb
    sha:2b81edc05d9537b16cbb43ce3449f562f46ccfa3
  • python3.6-doc_3.6.9-1~18.04ubuntu1.12+tuxcare.els24_all.deb
    sha:1ea04009705e78d1dfb06e1140ea5716ee359e57
  • python3.6-examples_3.6.9-1~18.04ubuntu1.12+tuxcare.els24_all.deb
    sha:6f8cac73792f888ad3f70c17390cc95c6da61ef7
  • python3.6-minimal_3.6.9-1~18.04ubuntu1.12+tuxcare.els24_amd64.deb
    sha:b003a67e15fa86c1dd2d08e345297f6ad2e5672f
  • python3.6-venv_3.6.9-1~18.04ubuntu1.12+tuxcare.els24_amd64.deb
    sha:a8fd84bf10a2fca54651046aa937a1c56de2693a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.