[CLSA-2026:1784900588] Fix CVE(s): CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-24 13:43:35 UTC
Description:
* SECURITY UPDATE: quadratic-complexity CPU denial of service in html.parser - debian/patches/CVE-2026-15308.patch: accumulate incremental feed() data to avoid re-scanning/concatenating unterminated constructs quadratically - CVE-2026-15308
CVEs fixed:
Updated packages:
  • alt-python310_3.10.20-5_amd64.deb
    sha:f8de96c85acc1880d8207988229e050723493b48
  • alt-python310-debug_3.10.20-5_amd64.deb
    sha:2baebe362f7e533bb10c37f38fcbec921ecbb519
  • alt-python310-devel_3.10.20-5_amd64.deb
    sha:c3acea17fd25caaa06a04aa15e4dd88f776e23dc
  • alt-python310-idle_3.10.20-5_amd64.deb
    sha:c0ec026e55ba025d461bf0bfadc907ef5e6bd907
  • alt-python310-libs_3.10.20-5_amd64.deb
    sha:7ce55399e8a87c9222557e1b603d9c314bb0b16d
  • alt-python310-test_3.10.20-5_amd64.deb
    sha:e3c54876aec32cbbdbb9ba39b61b31e3d442b587
  • alt-python310-tkinter_3.10.20-5_amd64.deb
    sha:85a24a648bec7aa61de48fdf97c7847206f0078e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.