[CLSA-2026:1780675586] Fix CVE(s): CVE-2026-7210
Type:
security
Severity:
Critical
Release date:
2026-06-08 08:55:17 UTC
Description:
* SECURITY UPDATE: insufficient entropy in pyexpat/_elementtree hash-flooding protection (CVE-2026-7210) - debian/patches/CVE-2026-7210.patch: bind XML_SetHashSalt16Bytes as a weak symbol to seed the parser with 16 bytes of entropy when hash randomization is enabled; falls back to the legacy XML_SetHashSalt when unavailable. - CVE-2026-7210
CVEs fixed:
Updated packages:
  • idle-python2.7_2.7.12-1ubuntu0~16.04.18+tuxcare.els18_all.deb
    sha:7705b51c9513ed76972a128ae1a7f26505281533
  • libpython2.7_2.7.12-1ubuntu0~16.04.18+tuxcare.els18_amd64.deb
    sha:ce073095adac16b8241c1d3342e5322ce93c7993
  • libpython2.7-dev_2.7.12-1ubuntu0~16.04.18+tuxcare.els18_amd64.deb
    sha:8424120f6353ad5b830c846c8322d332281d4514
  • libpython2.7-minimal_2.7.12-1ubuntu0~16.04.18+tuxcare.els18_amd64.deb
    sha:ecb3032b6d7e0d44ebbed8ac08d016f34c3f7ee3
  • libpython2.7-stdlib_2.7.12-1ubuntu0~16.04.18+tuxcare.els18_amd64.deb
    sha:840faab9d5f2dc68639f63de79181506cff7aad5
  • libpython2.7-testsuite_2.7.12-1ubuntu0~16.04.18+tuxcare.els18_all.deb
    sha:58df52c0f248e68e35e9e409b1885c8f888da6d8
  • python2.7_2.7.12-1ubuntu0~16.04.18+tuxcare.els18_amd64.deb
    sha:da184f587741aeeeaf01f9980866c43d1f4363e8
  • python2.7-dev_2.7.12-1ubuntu0~16.04.18+tuxcare.els18_amd64.deb
    sha:ad324eba7543d9ef2e3fbcabb27bdbb4bc56831a
  • python2.7-doc_2.7.12-1ubuntu0~16.04.18+tuxcare.els18_all.deb
    sha:2b49bafaf64311334957434f1caaaec13989de2a
  • python2.7-examples_2.7.12-1ubuntu0~16.04.18+tuxcare.els18_all.deb
    sha:a19ac53db939a7998f7139673d5f729a16a358b9
  • python2.7-minimal_2.7.12-1ubuntu0~16.04.18+tuxcare.els18_amd64.deb
    sha:ac028f873c63f529a62160ba7bcc39d3f4060eb6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.