[CLSA-2026:1784798883] Fix CVE(s): CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-23 09:28:34 UTC
Description:
* SECURITY UPDATE: quadratic-complexity denial of service in HTMLParser incremental parsing - debian/patches/CVE-2026-15308.patch: accumulate feed() data in a list in Lib/HTMLParser.py so an unterminated markup construct fed across many feed() calls is no longer rescanned and reconcatenated on every call; adds a regression test in Lib/test/test_htmlparser.py. - CVE-2026-15308
CVEs fixed:
Updated packages:
  • idle-python2.7_2.7.12-1ubuntu0~16.04.18+tuxcare.els20_all.deb
    sha:14829123b890ef7083e41f3a2c7fe0b3b2a59bd9
  • libpython2.7_2.7.12-1ubuntu0~16.04.18+tuxcare.els20_amd64.deb
    sha:e6475def4f541344f6c615752622accab6556ebc
  • libpython2.7-dev_2.7.12-1ubuntu0~16.04.18+tuxcare.els20_amd64.deb
    sha:f6bb0559ca6fa3526aa6ffa9a2f3d383683ef4b6
  • libpython2.7-minimal_2.7.12-1ubuntu0~16.04.18+tuxcare.els20_amd64.deb
    sha:1c82878f169ead1c50c67cd5621f44cf430ef76c
  • libpython2.7-stdlib_2.7.12-1ubuntu0~16.04.18+tuxcare.els20_amd64.deb
    sha:3a32ecf1d70ac4a4ab48ff8b9954638ff3f6f4aa
  • libpython2.7-testsuite_2.7.12-1ubuntu0~16.04.18+tuxcare.els20_all.deb
    sha:63192881e2fce11a4dc6a77302ff70e5179f776b
  • python2.7_2.7.12-1ubuntu0~16.04.18+tuxcare.els20_amd64.deb
    sha:71bf78697a63fb2ecf33dff0bac7f5b256651218
  • python2.7-dev_2.7.12-1ubuntu0~16.04.18+tuxcare.els20_amd64.deb
    sha:181831af267a324ff2328c61cdd58b3c0aefd1f9
  • python2.7-doc_2.7.12-1ubuntu0~16.04.18+tuxcare.els20_all.deb
    sha:b88da6687df9969442281b625e8573f3e20e2445
  • python2.7-examples_2.7.12-1ubuntu0~16.04.18+tuxcare.els20_all.deb
    sha:68309e41cf970fee91a25ed125c59be9fcdc75e5
  • python2.7-minimal_2.7.12-1ubuntu0~16.04.18+tuxcare.els20_amd64.deb
    sha:ab49daeea796ae1f3b25a95cc6b5cea5912a9640
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.