[CLSA-2026:1784886106] Fix of 9 CVEs
Type:
security
Severity:
Critical
Release date:
2026-07-24 09:42:33 UTC
Description:
* CVE-2026-15308: fix quadratic-complexity CPU denial-of-service in html.parser.HTMLParser incremental parsing. When an unterminated construct (tag or comment) spanned many feed() calls, the growing buffer was rescanned and concatenated on every call. New data is now accumulated in a list and only joined and parsed once enough has piled up; close() flushes any buffered data before the final parse. - debian/patches/CVE-2026-15308.patch: backport upstream bcf98ddbc40ec9b3ee87da0124a5660b19b7e606 (gh-153030 / gh-153031).
Updated packages:
  • alt-python38_3.8.20-23_amd64.deb
    sha:60b74b096a05f01ac93677bdea9d8af6326f5db6
  • alt-python38-debug_3.8.20-23_amd64.deb
    sha:e8b5f58308f5d51b0dc2e7e938c53a601d184db8
  • alt-python38-devel_3.8.20-23_amd64.deb
    sha:d7c4e36ce0c36c360e7ea088031cf4c72e23900f
  • alt-python38-idle_3.8.20-23_amd64.deb
    sha:570e210de28f7314b1fae2007fad536add0b1a5e
  • alt-python38-libs_3.8.20-23_amd64.deb
    sha:50be5bf72eccacd4c53e56c495e16789c4c7074f
  • alt-python38-test_3.8.20-23_amd64.deb
    sha:5bf9276d372e705a889f1875da77241707547aec
  • alt-python38-tkinter_3.8.20-23_amd64.deb
    sha:06e637f69f96ba9d75846f799f03a4bdde85dd03
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.