[CLSA-2026:1784706665] Fix CVE(s): CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-22 07:51:33 UTC
Description:
* CVE-2026-15308: fix quadratic-complexity CPU denial-of-service in html.parser.HTMLParser incremental parsing. When an unterminated construct (tag or comment) spanned many feed() calls, the growing buffer was rescanned and concatenated on every call. New data is now accumulated in a list and only joined and parsed once enough has piled up; close() flushes any buffered data before the final parse. - debian/patches/CVE-2026-15308.patch: backport upstream bcf98ddbc40ec9b3ee87da0124a5660b19b7e606 (gh-153030 / gh-153031).
CVEs fixed:
Updated packages:
  • alt-python38_3.8.20-23_amd64.deb
    sha:2a64f117195ff85ad12066c947f09e7a14fec016
  • alt-python38-debug_3.8.20-23_amd64.deb
    sha:b004de41f098bbcb7c163e80e5bd87b74c3d257f
  • alt-python38-devel_3.8.20-23_amd64.deb
    sha:118a1266894b356927bf7dfcf1629e6974a6d485
  • alt-python38-idle_3.8.20-23_amd64.deb
    sha:f19df58c6fd63d2780acfbc13ebc5c5c2763f003
  • alt-python38-libs_3.8.20-23_amd64.deb
    sha:a43ca1ea44d8e3df2b28841332ea511cc5cf2db5
  • alt-python38-test_3.8.20-23_amd64.deb
    sha:a223a8cc96e6506b3c6a69197875111ba3f7fd91
  • alt-python38-tkinter_3.8.20-23_amd64.deb
    sha:6dd183bf8613102691d12a78a8b689bc3fc7c8e1
  • alt-python38_3.8.20-23_arm64.deb
    sha:fba9f10d33693c6897b54d795d6c66e5680def0a
  • alt-python38-debug_3.8.20-23_arm64.deb
    sha:f716b6d659d961c1a086bc2fcda9ab1b906f77f9
  • alt-python38-devel_3.8.20-23_arm64.deb
    sha:b5c27fff6f6bdf19e29dafc1663acab68773fd6a
  • alt-python38-idle_3.8.20-23_arm64.deb
    sha:1da14d6485899e7c97df408f3535989279af3d78
  • alt-python38-libs_3.8.20-23_arm64.deb
    sha:0111bc8be1d6193d7a1be605c527f4b163f7d27f
  • alt-python38-test_3.8.20-23_arm64.deb
    sha:c530942ba2232c3d2e14836bc53f0dcea6c5b697
  • alt-python38-tkinter_3.8.20-23_arm64.deb
    sha:92c01726316ddade94350bd39aefc64e200eca36
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.