[CLSA-2026:1784798816] python2: Fix of CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-23 09:27:22 UTC
Description:
- CVE-2026-15308: fix quadratic complexity in HTMLParser incremental parsing; an unterminated markup construct fed across many feed() calls no longer causes the growing buffer to be rescanned and reconcatenated on every call (CPU denial of service). Adds a regression test.
CVEs fixed:
Updated packages:
  • python2-2.7.18-7.module_el8.5.0+2448+00b3b861.tuxcare.els25.x86_64.rpm
    sha:761552f873e1e8cb53b80d5485257a2d465faed27a350c0b3ca20d0fdb606aa6
  • python2-debug-2.7.18-7.module_el8.5.0+2448+00b3b861.tuxcare.els25.x86_64.rpm
    sha:92b3d66e7ba20a11266e735d00a6267b369f0f82df318d32e3bfd0661c0798b0
  • python2-devel-2.7.18-7.module_el8.5.0+2448+00b3b861.tuxcare.els25.x86_64.rpm
    sha:4a8188aa1150bcbb9f93934d0e6d99565e56684e2ce6e9e1fa98f3583a4bde31
  • python2-libs-2.7.18-7.module_el8.5.0+2448+00b3b861.tuxcare.els25.x86_64.rpm
    sha:a3f5d99615b5d90e7f113be50ba2e2c22e69940a3a34e2aed8bdee4b8b4719bf
  • python2-test-2.7.18-7.module_el8.5.0+2448+00b3b861.tuxcare.els25.x86_64.rpm
    sha:bbc1bc0e1e7f0347c5a59f8ec1aaef9e8467766aba1f0f4e3e0fe9a18a67023a
  • python2-tkinter-2.7.18-7.module_el8.5.0+2448+00b3b861.tuxcare.els25.x86_64.rpm
    sha:9e06423b2a344179b3a656e28e7576ff47bc2040f64c1ce5dfba9fd9f645ac1d
  • python2-tools-2.7.18-7.module_el8.5.0+2448+00b3b861.tuxcare.els25.x86_64.rpm
    sha:9b8f7ec5a724f5f27c398c204e715739a79427a1e724ce856e4c3ca82429d6c2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.