[CLSA-2026:1780698006] Fix CVE(s): CVE-2026-7210
Type:
security
Severity:
Critical
Release date:
2026-06-08 08:51:39 UTC
Description:
* SECURITY UPDATE: insufficient entropy in pyexpat/_elementtree hash-flooding protection (CVE-2026-7210) - debian/patches/CVE-2026-7210.patch: bind XML_SetHashSalt16Bytes as a weak symbol to seed the parser with 16 bytes of entropy when hash randomization is enabled; falls back to the legacy XML_SetHashSalt when unavailable. - CVE-2026-7210
CVEs fixed:
Updated packages:
  • idle-python2.7_2.7.17-1~18.04ubuntu1.11+tuxcare.els13_all.deb
    sha:6847eb92c307b22d5fb93be4c0278e26599177f7
  • libpython2.7_2.7.17-1~18.04ubuntu1.11+tuxcare.els13_amd64.deb
    sha:b82084f8a74520d2ef1ae9a8e94eab422bf6fc00
  • libpython2.7-dev_2.7.17-1~18.04ubuntu1.11+tuxcare.els13_amd64.deb
    sha:3379e58e2f210c9c4eaa0edf30f37a01a001ab5e
  • libpython2.7-minimal_2.7.17-1~18.04ubuntu1.11+tuxcare.els13_amd64.deb
    sha:7e531ef8cae0d6c1bbcf94a5f63756150cbb069e
  • libpython2.7-stdlib_2.7.17-1~18.04ubuntu1.11+tuxcare.els13_amd64.deb
    sha:035cf5c5283dc4049639c3f3d47efa8f3020bac4
  • libpython2.7-testsuite_2.7.17-1~18.04ubuntu1.11+tuxcare.els13_all.deb
    sha:b674ccb678091cf6292fa43373613d3b1ce4481d
  • python2.7_2.7.17-1~18.04ubuntu1.11+tuxcare.els13_amd64.deb
    sha:6e38ab79f286b1f3be412c6cf9f4a9d49636850d
  • python2.7-dev_2.7.17-1~18.04ubuntu1.11+tuxcare.els13_amd64.deb
    sha:5b7096beb1e0440ebf21ca1afee060489138c26a
  • python2.7-doc_2.7.17-1~18.04ubuntu1.11+tuxcare.els13_all.deb
    sha:4468572286e2b162c7ccb2c26d4bbaf06906a164
  • python2.7-examples_2.7.17-1~18.04ubuntu1.11+tuxcare.els13_all.deb
    sha:e42a9b8476ff6bace01468dbaed7ec5ca5363431
  • python2.7-minimal_2.7.17-1~18.04ubuntu1.11+tuxcare.els13_amd64.deb
    sha:6637154d981d0ba39fa65851f1017ab7fd06e480
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.