[CLSA-2026:1784188935] Fix CVE(s): CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-16 08:02:39 UTC
Description:
* SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser via repeated unterminated markup declarations - debian/patches/CVE-2026-15308.patch: accumulate incrementally fed data in a list and only join and rescan it once a growing threshold is reached, so an unterminated construct (tag, comment, PI, doctype, CDATA, RAWTEXT element) spread across many feed() calls no longer makes both the buffer concatenation and the rescan quadratic in the input size (backport of upstream commit bcf98ddbc40e, gh-153030 / GH-153031). - CVE-2026-15308
CVEs fixed:
Updated packages:
  • idle-python3.7_3.7.3-2+deb10u7+tuxcare.els6_all.deb
    sha:3fefaa52b391749971db566eb049a3780aab8840
  • libpython3.7_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb
    sha:a5d5389ea819775cf3a517de1d5825132fee0047
  • libpython3.7-dev_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb
    sha:0f280c10770bdda83094bb28c6724e4e4e9f4d1e
  • libpython3.7-minimal_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb
    sha:9d3fd062c7bd96a42337d48d7ba72eaa4930ccde
  • libpython3.7-stdlib_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb
    sha:e021821fa7b0a08190a713f3c6e29769792e8fec
  • libpython3.7-testsuite_3.7.3-2+deb10u7+tuxcare.els6_all.deb
    sha:804ec50a1e56017c006268e1165f048e2d11dfd1
  • python3.7_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb
    sha:71f44bba78caf014b95993cc6828a7e172c32883
  • python3.7-dev_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb
    sha:2e513a5079a773e896da5d508ee7f074a277a401
  • python3.7-doc_3.7.3-2+deb10u7+tuxcare.els6_all.deb
    sha:53ee504e2eb724bf8a033b5e5aed87cd21ae50f7
  • python3.7-examples_3.7.3-2+deb10u7+tuxcare.els6_all.deb
    sha:136a424e2735d967c3ddd9a0157240ae7b4f9f55
  • python3.7-minimal_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb
    sha:a5d7948cb3ce492a532bd6abe2fdbdcfc9a14e70
  • python3.7-venv_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb
    sha:ac688797e5c6719791f324d23628a14eb22d41c9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.