[CLSA-2026:1781179629] python2: Fix of CVE-2026-7210
Type:
security
Severity:
Critical
Release date:
2026-06-11 12:07:25 UTC
Description:
- CVE-2026-7210: seed the libexpat parser with 16 bytes of entropy via XML_SetHashSalt16Bytes when hash randomization is enabled (bound as a weak symbol; falls back to the legacy XML_SetHashSalt when unavailable) to restore hash-flooding protection
CVEs fixed:
Updated packages:
  • python2-2.7.18-17.module_el8+2419+d95a22ce.tuxcare.els12.x86_64.rpm
    sha:8818896cb8806b26cdbebd79abaf40f71114ecaabe876b1a4d7e44697ba52420
  • python2-debug-2.7.18-17.module_el8+2419+d95a22ce.tuxcare.els12.x86_64.rpm
    sha:9cc5c2337692ab6e423ea83e50cf71c1d125af721bdf5b2642868909faf42533
  • python2-devel-2.7.18-17.module_el8+2419+d95a22ce.tuxcare.els12.x86_64.rpm
    sha:06ec52b2559c3ef61f40ff10101ad84dc9c859255e93a8ef23a6ac62fb6fa110
  • python2-libs-2.7.18-17.module_el8+2419+d95a22ce.tuxcare.els12.x86_64.rpm
    sha:6f9447106a8332061d2b136ce3da0d840c01103d63f3b34871e45965d44e35b0
  • python2-test-2.7.18-17.module_el8+2419+d95a22ce.tuxcare.els12.x86_64.rpm
    sha:78ecfd9fddbe1ce42d42cc13960314d25f26eca04519dde43923742e7b1bc38e
  • python2-tkinter-2.7.18-17.module_el8+2419+d95a22ce.tuxcare.els12.x86_64.rpm
    sha:88f688372518b04a913c30b1cad0785e8b187d1f16fc35186b9df1755b94fcc0
  • python2-tools-2.7.18-17.module_el8+2419+d95a22ce.tuxcare.els12.x86_64.rpm
    sha:7c0fe5e5f6fa82d6a3618fc4f08a89c239f38ec3120f3609fc24d6b2220244fb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.