Re: [LFS Trac] #5972: Python security fixes: CVE-2026-4360 and 15308

LFS Trac ([email protected] via lfs-book Mailing List) <[email protected]> Sun, 12 Jul 2026 04:51:18 -0000
Newsgroups gmane.linux.lfs.book
Message-ID <[email protected]>
#5972: Python security fixes: CVE-2026-4360 and 15308
-------------------------+-----------------------
 Reporter:  Joe Locash   |       Owner:  lfs-book
     Type:  enhancement  |      Status:  new
 Priority:  high         |   Milestone:  13.1
Component:  Book         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+-----------------------
Comment (by Bruce Dubbs):

 I grabbed the attachments above and they both applied with some offsets.
 However I'm not sure we should bother to add them to the book for the
 following reasons:

 1. The problems they fix appear to be somewhat esoteric.  The description
 of the 15308
    cve (the 'HIGH' problem) says "The incremental HTML parser
 (html.parser.HTMLParser)
    allows for CPU denial-of-service through repeated unterminated markup
    declarations when processing uncontrolled data."

 2. Checking upstream, both patches have been incorporated into the
 mainline
    repository.  According to https://peps.python.org/pep-0745/ the next
 point
    release of Python will be August 6th or about three weeks from now.  At
    that time the patches will be incorporated and not needed in LFS/BLFS.
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/lfs/ticket/5972#comment:1>
LFS Trac <https://wiki.linuxfromscratch.org/lfs/>
Linux From Scratch: Your Distro, Your Rules.

-- 
http://lists.linuxfromscratch.org/sympa/info/lfs-book
Unsubscribe: See the above information page