[CLSA-2026:1784297320] Fix CVE(s): CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-17 14:09:05 UTC
Description:
* SECURITY UPDATE: CPU denial-of-service in the html.parser module via repeated unterminated markup declarations (quadratic complexity in the incremental HTMLParser) - debian/patches/CVE-2026-15308.patch: accumulate pending data in feed() and parse on a doubling threshold instead of rescanning the whole unparsed buffer each call, in Lib/html/parser.py - CVE-2026-15308
CVEs fixed:
Updated packages:
  • idle-python3.5_3.5.2-2ubuntu0~16.04.13+tuxcare.els27_all.deb
    sha:05aa4c9a8d9ca75479a24cb95ae7b5996fd5d546
  • libpython3.5_3.5.2-2ubuntu0~16.04.13+tuxcare.els27_amd64.deb
    sha:9d222a6fdc5484af0d9e37d901c7e6a75869c405
  • libpython3.5-dev_3.5.2-2ubuntu0~16.04.13+tuxcare.els27_amd64.deb
    sha:e67e9e3cd1845c18df58a0483cfcb62d06333144
  • libpython3.5-minimal_3.5.2-2ubuntu0~16.04.13+tuxcare.els27_amd64.deb
    sha:11f0cdb3d439653badb16482af71d1e78c9b1ebe
  • libpython3.5-stdlib_3.5.2-2ubuntu0~16.04.13+tuxcare.els27_amd64.deb
    sha:0478b542ad957ec7a732f7e5d163ae5f7417c920
  • libpython3.5-testsuite_3.5.2-2ubuntu0~16.04.13+tuxcare.els27_all.deb
    sha:e0568f1ed1d3a2a68378c8dba221e586e90823bb
  • python3.5_3.5.2-2ubuntu0~16.04.13+tuxcare.els27_amd64.deb
    sha:d5f4a52b30231a80fcb7a2e038d326845a273e45
  • python3.5-dev_3.5.2-2ubuntu0~16.04.13+tuxcare.els27_amd64.deb
    sha:a55625991cae391b68792ad74e792e493516ac28
  • python3.5-doc_3.5.2-2ubuntu0~16.04.13+tuxcare.els27_all.deb
    sha:cf18e1635eaf7eea2d73f415df743e57e2216d76
  • python3.5-examples_3.5.2-2ubuntu0~16.04.13+tuxcare.els27_all.deb
    sha:e0d0d91c622b35727c137bc26aff32c836549e75
  • python3.5-minimal_3.5.2-2ubuntu0~16.04.13+tuxcare.els27_amd64.deb
    sha:1fdb18f2781ffad2acd92ef8146e245118b90dd0
  • python3.5-venv_3.5.2-2ubuntu0~16.04.13+tuxcare.els27_amd64.deb
    sha:28fa91336c51a38680e964a856392fd91d8e5224
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.