[CLSA-2026:1784707811] python: Fix of CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-22 08:18:30 UTC
Description:
- CVE-2026-15308: fix quadratic complexity in incremental parsing of long unterminated markup declarations in HTMLParser by buffering feed() input, preventing a CPU denial-of-service on uncontrolled data
CVEs fixed:
Updated packages:
  • python-2.7.18-1.amzn2.0.20.tuxcare.els2.x86_64.rpm
    sha:41a4d91000519883e8b9d7626219e33b18453b37efb09b328866959bed3553bf
  • python-debug-2.7.18-1.amzn2.0.20.tuxcare.els2.x86_64.rpm
    sha:0353996880856bc7d55525de51f8b381e137630f1a086e8f9dcd21787ebbeaf4
  • python-devel-2.7.18-1.amzn2.0.20.tuxcare.els2.x86_64.rpm
    sha:28196b9acd8d41ddcfbdd5959fc8df1de1ecbf1bcbfb1dae88d5b65c7f96dc57
  • python-libs-2.7.18-1.amzn2.0.20.tuxcare.els2.i686.rpm
    sha:ced21057b9257cba4a795216f0d6c032a138e43f3525c489c7baca812a21370d
  • python-libs-2.7.18-1.amzn2.0.20.tuxcare.els2.x86_64.rpm
    sha:82ff4015187c0fa97197ffc3ca9e62b733e0ec4b26564b44c85a61f19a323f32
  • python-test-2.7.18-1.amzn2.0.20.tuxcare.els2.x86_64.rpm
    sha:96d6ac041610288b1895309bffce114d1b87e591b94484e9d5f29b71b4b8a297
  • python-tools-2.7.18-1.amzn2.0.20.tuxcare.els2.x86_64.rpm
    sha:d5e33230fb840630951e08ebc1bd4b8cb3884d798d6f846a378d8303137f88fb
  • tkinter-2.7.18-1.amzn2.0.20.tuxcare.els2.x86_64.rpm
    sha:80f68f1b9932838f83238fb632c37d65677901758f9bdea212b376fedb5c55cb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.