Re: [LFS Trac] #5972: Python security fixes: CVE-2026-4360 and 15308
LFS Trac ([email protected] via lfs-book Mailing List) <[email protected]> Sun, 12 Jul 2026 04:51:18 -0000
| Newsgroups | gmane.linux.lfs.book |
|---|---|
| Message-ID | <[email protected]> |
#5972: Python security fixes: CVE-2026-4360 and 15308
-------------------------+-----------------------
Reporter: Joe Locash | Owner: lfs-book
Type: enhancement | Status: new
Priority: high | Milestone: 13.1
Component: Book | Version: git
Severity: normal | Resolution:
Keywords: |
-------------------------+-----------------------
Comment (by Bruce Dubbs):
I grabbed the attachments above and they both applied with some offsets.
However I'm not sure we should bother to add them to the book for the
following reasons:
1. The problems they fix appear to be somewhat esoteric. The description
of the 15308
cve (the 'HIGH' problem) says "The incremental HTML parser
(html.parser.HTMLParser)
allows for CPU denial-of-service through repeated unterminated markup
declarations when processing uncontrolled data."
2. Checking upstream, both patches have been incorporated into the
mainline
repository. According to https://peps.python.org/pep-0745/ the next
point
release of Python will be August 6th or about three weeks from now. At
that time the patches will be incorporated and not needed in LFS/BLFS.
--
Ticket URL: <https://wiki.linuxfromscratch.org/lfs/ticket/5972#comment:1>
LFS Trac <https://wiki.linuxfromscratch.org/lfs/>
Linux From Scratch: Your Distro, Your Rules.
--
http://lists.linuxfromscratch.org/sympa/info/lfs-book
Unsubscribe: See the above information page