[CLSA-2026:1784798564] Fix CVE(s): CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-23 09:23:09 UTC
Description:
* SECURITY UPDATE: quadratic-complexity denial of service in HTMLParser incremental parsing - debian/patches/CVE-2026-15308.patch: accumulate feed() data in a list in Lib/HTMLParser.py so an unterminated markup construct fed across many feed() calls is no longer rescanned and reconcatenated on every call; adds a regression test in Lib/test/test_htmlparser.py. - CVE-2026-15308
CVEs fixed:
Updated packages:
  • idle-python2.7_2.7.17-1~18.04ubuntu1.11+tuxcare.els15_all.deb
    sha:b5f6ded84f2c79174ec5c15285cc724c1401b449
  • libpython2.7_2.7.17-1~18.04ubuntu1.11+tuxcare.els15_amd64.deb
    sha:4727d52bd959fba79d5f4bb3c58e20930bf72518
  • libpython2.7-dev_2.7.17-1~18.04ubuntu1.11+tuxcare.els15_amd64.deb
    sha:dd9e146e011725d976df632be8825836426b6404
  • libpython2.7-minimal_2.7.17-1~18.04ubuntu1.11+tuxcare.els15_amd64.deb
    sha:27d9536811c155e2e982765dd3d6d1587f0289e5
  • libpython2.7-stdlib_2.7.17-1~18.04ubuntu1.11+tuxcare.els15_amd64.deb
    sha:a75abb5797ea5cb8cce1ee030b7994ce8d774d63
  • libpython2.7-testsuite_2.7.17-1~18.04ubuntu1.11+tuxcare.els15_all.deb
    sha:38bb97526b867b4debcff76426625bfc4364ab8b
  • python2.7_2.7.17-1~18.04ubuntu1.11+tuxcare.els15_amd64.deb
    sha:ea6b5d738329b14a184a03526348f8534d382051
  • python2.7-dev_2.7.17-1~18.04ubuntu1.11+tuxcare.els15_amd64.deb
    sha:7daa1e755ba8868d41931f9e22d8af717ccf864a
  • python2.7-doc_2.7.17-1~18.04ubuntu1.11+tuxcare.els15_all.deb
    sha:b78c6d5d39597b34faa1dc5262034c318e2b7e2f
  • python2.7-examples_2.7.17-1~18.04ubuntu1.11+tuxcare.els15_all.deb
    sha:71eb334464244a08cbecf4d4bbd8c68f6a8e9d45
  • python2.7-minimal_2.7.17-1~18.04ubuntu1.11+tuxcare.els15_amd64.deb
    sha:d229e3205f6d59746e5c7e2123da073c0b84b07a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.