[CLSA-2026:1784218371] python: Fix of CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-16 16:13:13 UTC
Description:
- CVE-2026-15308: fix quadratic-complexity CPU denial-of-service in the HTMLParser incremental parser - accumulate feed() data in a buffer and only join/rescan once enough has piled up, instead of re-concatenating and re-scanning the whole unparsed buffer on every feed() call. Backported from upstream CPython (gh-153030, GH-153031).
CVEs fixed:
Updated packages:
  • python-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:099e2b54bf59f949f63ea848d34c0e9bfdd51da2c86a25eeb6aad69d2b2aae1e
  • python-debug-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:735ddc13cc3fa0080c901b39982cef5d5ed6b81ced0e95399d2e53b4b1781474
  • python-devel-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:08e18f6dd4dd75920dcee8c759fc3744098f16eec5e5f5b4cad173066706ba39
  • python-libs-2.7.5-94.0.1.el7_9.tuxcare.els12.i686.rpm
    sha:2b1655c638f2e714a94b08b12f8a3827a882e0803dadaa4e19882f52e9954826
  • python-libs-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:3baf3810756b016144261cc2c180060ebb4c55ac74c6faa37dce8b7761cbbcb0
  • python-test-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:4738fed7c5cf7dfa97dbdadcbe262a423e4a7ff1396ff65bc9ac2dd20a7fea74
  • python-tools-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:0a8164493d6bc52f0f8c619956e4f1efd2e4411bac188e8894702a245744f0ee
  • tkinter-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:b4273b01e973b79f18da7a224157dcf1b63dd7f593e6531ebfb60b023bddb878
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.