Release date:
2026-07-16 08:02:39 UTC
Description:
* SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser via
repeated unterminated markup declarations
- debian/patches/CVE-2026-15308.patch: accumulate incrementally fed
data in a list and only join and rescan it once a growing threshold
is reached, so an unterminated construct (tag, comment, PI, doctype,
CDATA, RAWTEXT element) spread across many feed() calls no longer
makes both the buffer concatenation and the rescan quadratic in the
input size (backport of upstream commit bcf98ddbc40e, gh-153030 /
GH-153031).
- CVE-2026-15308
Updated packages:
-
idle-python3.7_3.7.3-2+deb10u7+tuxcare.els6_all.deb
sha:3fefaa52b391749971db566eb049a3780aab8840
-
libpython3.7_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb
sha:a5d5389ea819775cf3a517de1d5825132fee0047
-
libpython3.7-dev_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb
sha:0f280c10770bdda83094bb28c6724e4e4e9f4d1e
-
libpython3.7-minimal_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb
sha:9d3fd062c7bd96a42337d48d7ba72eaa4930ccde
-
libpython3.7-stdlib_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb
sha:e021821fa7b0a08190a713f3c6e29769792e8fec
-
libpython3.7-testsuite_3.7.3-2+deb10u7+tuxcare.els6_all.deb
sha:804ec50a1e56017c006268e1165f048e2d11dfd1
-
python3.7_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb
sha:71f44bba78caf014b95993cc6828a7e172c32883
-
python3.7-dev_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb
sha:2e513a5079a773e896da5d508ee7f074a277a401
-
python3.7-doc_3.7.3-2+deb10u7+tuxcare.els6_all.deb
sha:53ee504e2eb724bf8a033b5e5aed87cd21ae50f7
-
python3.7-examples_3.7.3-2+deb10u7+tuxcare.els6_all.deb
sha:136a424e2735d967c3ddd9a0157240ae7b4f9f55
-
python3.7-minimal_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb
sha:a5d7948cb3ce492a532bd6abe2fdbdcfc9a14e70
-
python3.7-venv_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb
sha:ac688797e5c6719791f324d23628a14eb22d41c9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.