[CLSA-2026:1784798087] python2: Fix of CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-23 09:15:13 UTC
Description:
- CVE-2026-15308: fix quadratic complexity in HTMLParser incremental parsing; an unterminated markup construct fed across many feed() calls no longer causes the growing buffer to be rescanned and reconcatenated on every call (CPU denial of service). Adds a regression test.
CVEs fixed:
Updated packages:
  • python2-2.7.18-4.module_el8.4.0+2447+458ce58e.tuxcare.els26.x86_64.rpm
    sha:aceca8ab1192ebed0d29d91fa9b061d73bbf93a211c2dd2c02b0bd93a814ab03
  • python2-debug-2.7.18-4.module_el8.4.0+2447+458ce58e.tuxcare.els26.x86_64.rpm
    sha:b256b28b29870ac9724f78d5404449ef1bc3f27d03967d343f6048db3f6e8bb7
  • python2-devel-2.7.18-4.module_el8.4.0+2447+458ce58e.tuxcare.els26.x86_64.rpm
    sha:5fdfa1de97d1a6a903fff402cb4c25f9f42d213483975b7d46d08a689d6bc7e2
  • python2-libs-2.7.18-4.module_el8.4.0+2447+458ce58e.tuxcare.els26.x86_64.rpm
    sha:ae139860cab92220cd49c46f412a83ab837dd3df503ea5410898eb8df4c28f0d
  • python2-test-2.7.18-4.module_el8.4.0+2447+458ce58e.tuxcare.els26.x86_64.rpm
    sha:cf8982ea6400e81f0b99018392bd46f036f84193ff617568d7f841dd014c2ab6
  • python2-tkinter-2.7.18-4.module_el8.4.0+2447+458ce58e.tuxcare.els26.x86_64.rpm
    sha:525e02c16495f048e36a4f548f6798512588458980dcedef074620e7f4e1cfb8
  • python2-tools-2.7.18-4.module_el8.4.0+2447+458ce58e.tuxcare.els26.x86_64.rpm
    sha:5d17ebbe038096419f86d6568aa9040f6d130b742967b0fc234cb0c2934c1cb2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.