public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
* [rpms/python3.12] rawhide: Security fix for CVE-2026-15308
@ 2026-07-30 15:18 
  0 siblings, 0 replies; only message in thread
From:  @ 2026-07-30 15:18 UTC (permalink / raw)
  To: git-commits

            A new commit has been pushed.

            Repo   : rpms/python3.12
            Branch : rawhide
            Commit : 06f5d3454fc8d2b6950a9334598d833ee8aa292b
            Author : Lukáš Zachar <lzachar@redhat.com>
            Date   : 2026-07-30T13:20:32+02:00
            Stats  : +128/-1 in 2 file(s)
            URL    : https://src.fedoraproject.org/rpms/python3.12/c/06f5d3454fc8d2b6950a9334598d833ee8aa292b?branch=rawhide

            Log:
            Security fix for CVE-2026-15308

Resolves: rhbz#2498688

---
diff --git a/00490-cve-2026-15308.patch b/00490-cve-2026-15308.patch
new file mode 100644
index 0000000..942b18b
--- /dev/null
+++ b/00490-cve-2026-15308.patch
@@ -0,0 +1,114 @@
+From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
+From: Serhiy Storchaka <storchaka@gmail.com>
+Date: Sat, 4 Jul 2026 20:40:22 +0300
+Subject: 00490: gh-153030: Fix quadratic complexity in incremental parsing in
+ HTMLParser
+
+When an unterminated construct (e.g. a tag or comment) spanned many
+feed() calls, rescanning the growing buffer and concatenating new data
+onto it were both quadratic.  New data is now accumulated in a list and
+only joined and parsed once enough has piled up.
+(cherry picked from commit bcf98ddbc40ec9b3ee87da0124a5660b19b7e606)
+
+Co-authored-by: Serhiy Storchaka <storchaka@gmail.com>
+Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
+---
+ Lib/html/parser.py                            | 32 +++++++++++++++++--
+ Lib/test/test_htmlparser.py                   | 20 ++++++++++++
+ ...-07-04-17-00-00.gh-issue-153030.RovkP6.rst |  3 ++
+ 3 files changed, 53 insertions(+), 2 deletions(-)
+ create mode 100644 Misc/NEWS.d/next/Security/2026-07-04-17-00-00.gh-issue-153030.RovkP6.rst
+
+diff --git a/Lib/html/parser.py b/Lib/html/parser.py
+index bfab3e64cd..c5d2340b71 100644
+--- a/Lib/html/parser.py
++++ b/Lib/html/parser.py
+@@ -138,6 +138,9 @@ def reset(self):
+         self.cdata_elem = None
+         self._support_cdata = True
+         self._escapable = True
++        self._pending = []
++        self._pending_len = 0
++        self._parse_threshold = 1
+         super().reset()
+ 
+     def feed(self, data):
+@@ -146,11 +149,36 @@ def feed(self, data):
+         Call this as often as you want, with as little or as much text
+         as you want (may include '\n').
+         """
+-        self.rawdata = self.rawdata + data
+-        self.goahead(0)
++        # Accumulate new data in a list and only join and parse it once
++        # enough has piled up.  Rescanning an unparsed buffer (e.g. an
++        # unterminated tag) and concatenating onto it on every call would
++        # both be quadratic in the input size.
++        self._pending_len += len(data)
++        if self._pending_len < self._parse_threshold:
++            self._pending.append(data)
++        else:
++            if not self._pending:
++                self.rawdata += data
++            else:
++                self._pending.append(data)
++                self.rawdata += ''.join(self._pending)
++                self._pending.clear()
++            self._pending_len = 0
++            n = len(self.rawdata)
++            self.goahead(0)
++            if len(self.rawdata) < n:
++                # Some data was parsed; resume on the next call.
++                self._parse_threshold = 1
++            else:
++                # Nothing was parsed; wait until the buffer doubles.
++                self._parse_threshold = len(self.rawdata)
+ 
+     def close(self):
+         """Handle any buffered data."""
++        if self._pending:
++            self.rawdata += ''.join(self._pending)
++            self._pending.clear()
++            self._pending_len = 0
+         self.goahead(1)
+ 
+     __starttag_text = None
+diff --git a/Lib/test/test_htmlparser.py b/Lib/test/test_htmlparser.py
+index 303c0baa87..e6d92a7ec5 100644
+--- a/Lib/test/test_htmlparser.py
++++ b/Lib/test/test_htmlparser.py
+@@ -930,6 +930,26 @@ def check(source):
+         check("<![CDATA[" * 9 * n)
+         check("<!doctype" * 35 * n)
+ 
++    @support.requires_resource('cpu')
++    def test_incremental_no_quadratic_complexity(self):
++        # An unterminated construct fed in many small chunks used to take
++        # quadratic time, both to rescan and to concatenate the buffer.
++        # Now it takes a fraction of a second.
++        def check(prefix, chunk, suffix):
++            parser = html.parser.HTMLParser()
++            parser.feed(prefix)
++            for _ in range(200_000):
++                parser.feed(chunk)
++            parser.feed(suffix)
++            parser.close()
++        chunk = "a" * 64
++        check("<!--", chunk, "-->")       # comment
++        check("<?", chunk, ">")           # processing instruction
++        check("<!doctype ", chunk, ">")   # doctype
++        check("<![CDATA[", chunk, "]]>")  # CDATA section
++        check("<a href='", chunk, "'>")   # start tag
++        check("<script>", chunk, "</script>")  # RAWTEXT element
++
+ 
+ class AttributesTestCase(TestCaseBase):
+ 
+diff --git a/Misc/NEWS.d/next/Security/2026-07-04-17-00-00.gh-issue-153030.RovkP6.rst b/Misc/NEWS.d/next/Security/2026-07-04-17-00-00.gh-issue-153030.RovkP6.rst
+new file mode 100644
+index 0000000000..d1d60593f4
+--- /dev/null
++++ b/Misc/NEWS.d/next/Security/2026-07-04-17-00-00.gh-issue-153030.RovkP6.rst
+@@ -0,0 +1,3 @@
++Fixed quadratic complexity in incremental parsing of long unterminated
++constructs (such as tags or comments) in :class:`html.parser.HTMLParser`,
++which could be exploited for a denial of service.

diff --git a/python3.12.spec b/python3.12.spec
index e7e350c..c3b0ce6 100644
--- a/python3.12.spec
+++ b/python3.12.spec
@@ -17,7 +17,7 @@ URL: https://www.python.org/
 #global prerel ...
 %global upstream_version %{general_version}%{?prerel}
 Version: %{general_version}%{?prerel:~%{prerel}}
-Release: 5%{?dist}
+Release: 6%{?dist}
 License: Python-2.0.1
 
 
@@ -475,6 +475,15 @@ Patch484: 00484-cve-2026-3644.patch
 # Stack overflow parsing XML with deeply nested DTD content models
 Patch485: 00485-cve-2026-4224.patch
 
+# 00490 # 3e8c5ad70d6a515107352d8779269240a0553f54
+# gh-153030: Fix quadratic complexity in incremental parsing in HTMLParser
+#
+# When an unterminated construct (e.g. a tag or comment) spanned many
+# feed() calls, rescanning the growing buffer and concatenating new data
+# onto it were both quadratic.  New data is now accumulated in a list and
+# only joined and parsed once enough has piled up.
+Patch490: 00490-cve-2026-15308.patch
+
 # 00491 # 1ad95144c42a6933283352245c5df5a4c142e75f
 # gh-149776: Skip UDP Lite tests if it's not supported
 #
@@ -1818,6 +1827,10 @@ CheckPython optimized
 # ======================================================
 
 %changelog
+* Tue Jul 28 2026 Lukáš Zachar <lzachar@redhat.com> - 3.12.13-6
+- Security fix for CVE-2026-15308
+Resolves: rhbz#2498688
+
 * Tue Jul 28 2026 Miro Hrončok <mhroncok@redhat.com> - 3.12.13-5
 - Skip UDP Lite tests if it's not supported
 - Fixes FTBFS on Linux kernel 7.1 and newer

^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-07-30 15:18 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-07-30 15:18 [rpms/python3.12] rawhide: Security fix for CVE-2026-15308 

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox