[CLSA-2026:1784798441] python2: Fix of CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-23 09:21:07 UTC
Description:
- CVE-2026-15308: fix quadratic complexity in HTMLParser incremental parsing; an unterminated markup construct fed across many feed() calls no longer causes the growing buffer to be rescanned and reconcatenated on every call (CPU denial of service). Adds a regression test.
CVEs fixed:
Updated packages:
  • python2-2.7.18-17.module_el8+2445+fe325ede.tuxcare.els14.x86_64.rpm
    sha:d26fdea2df0095149b28ba803c714e0958124a9a47d9e188321e1c56d8a58f53
  • python2-debug-2.7.18-17.module_el8+2445+fe325ede.tuxcare.els14.x86_64.rpm
    sha:2e2126cef3f573d6c62407933db05e95c63f6f016d39f2efa8a82322ce249d64
  • python2-devel-2.7.18-17.module_el8+2445+fe325ede.tuxcare.els14.x86_64.rpm
    sha:20308ffd02f96d0a1e65bd30a3a28bd52a554e7b55d9f742d454e5283ffbc3ae
  • python2-libs-2.7.18-17.module_el8+2445+fe325ede.tuxcare.els14.x86_64.rpm
    sha:e699a072cc45b1067c26bca3b4ec7c440143969e83867d51d83fe154d9ade76a
  • python2-test-2.7.18-17.module_el8+2445+fe325ede.tuxcare.els14.x86_64.rpm
    sha:980e0f184885a1e2eb968a9ba46a0af08d286c9e4709e00ec63ed0237ee40797
  • python2-tkinter-2.7.18-17.module_el8+2445+fe325ede.tuxcare.els14.x86_64.rpm
    sha:5e4ed8120a72add2d3f60b52c71c2a0c0a3af6b13b9ebcb3fa7238b7bb609f14
  • python2-tools-2.7.18-17.module_el8+2445+fe325ede.tuxcare.els14.x86_64.rpm
    sha:c59e6501fe096aa5f47c6edd0892bb18601c60fc301777bd0dc876938c9d5c44
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.