[CLSA-2026:1784218124] python: Fix of CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-16 16:09:06 UTC
Description:
- CVE-2026-15308: fix quadratic-complexity CPU denial-of-service in the HTMLParser incremental parser - accumulate feed() data in a buffer and only join/rescan once enough has piled up, instead of re-concatenating and re-scanning the whole unparsed buffer on every feed() call. Backported from upstream CPython (gh-153030, GH-153031).
CVEs fixed:
Updated packages:
  • python-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:d40f45ae4589d84206799cc26731f245a0639818dec5e019c2971965da68aa23
  • python-debug-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:d07f9f453729b950a7a7cf9124c265fb757e36b27e308050da3d6fe99051c79f
  • python-devel-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:97a55e222745e17bd770a44052dcfbfd12db5ade6388ab871bc821f065b4ce83
  • python-libs-2.7.5-94.0.1.el7_9.tuxcare.els12.i686.rpm
    sha:c325e7bc85dc496cceab00614dcc93062b88fc6aa85cb7a0088c046883d4d276
  • python-libs-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:02911e815387b1a76958267b49ff098cfacdec67e5096329837f0e75ed68a779
  • python-test-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:9e73e56de94a7c766c53ef287a061df91bd8b2e4df0223a0e82fa696894df072
  • python-tools-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:fcaba9f6c4ae040e28c5cb4139fed9034891943a436ddfb2b7426c18e66343e3
  • tkinter-2.7.5-94.0.1.el7_9.tuxcare.els12.x86_64.rpm
    sha:5476d27090dd9a9bdaa1345d6666547def0546657b66b96e143f118732bdfdb8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.