[CLSA-2026:1784280875] python: Fix of CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-17 09:34:57 UTC
Description:
- CVE-2026-15308: fix quadratic-complexity CPU denial-of-service in the HTMLParser incremental parser - accumulate feed() data in a buffer and only join/rescan once enough has piled up, instead of re-concatenating and re-scanning the whole unparsed buffer on every feed() call. Backported from upstream CPython (gh-153030, GH-153031).
CVEs fixed:
Updated packages:
  • python-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:4d816d49aaebc5f9604db3c70c76550835dcddc3a0b51929a541a835d0dd55ad
  • python-debug-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:7e2cd6ba78406339b9187baaa75c2f75a3877fe07099a7c3e8d408c498c559a3
  • python-devel-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:4ed52fa08f57670cd7729c6d87d81e5b3556c0efa3b10414578bc04022295a46
  • python-libs-2.7.5-94.0.1.el7_9.tuxcare.els12.i686.rpm
    sha:90f6ade312eb2ebdc3d89a95d1160e5aa83dc91a3eb7c731b9ce330e193647a7
  • python-libs-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:325922e658034abadb6700f6fb0cd9a931640b387210706495a5943e84572953
  • python-test-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:f0048933b2e30b30a32bc1f69817030f3c90656201436b10cd3d143af9d12244
  • python-tools-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:c66fc96cc24fc54c5a40b49a481a959bb7332df6c86cdc8fa2485d2f41f9835f
  • tkinter-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:dd0f71bc55cdb3a7f5ceafe90c27a65ef6773ca41719f45dfbad1e2b5da2c1a8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.