[CLSA-2026:1780675974] Fix CVE(s): CVE-2026-7210
Type:
security
Severity:
Critical
Release date:
2026-06-08 09:07:23 UTC
Description:
* SECURITY UPDATE: insufficient entropy in pyexpat/_elementtree hash-flooding protection (CVE-2026-7210) - debian/patches/CVE-2026-7210.patch: bind XML_SetHashSalt16Bytes as a weak symbol to seed the parser with 16 bytes of entropy; falls back to the legacy 8-byte XML_SetHashSalt when libexpat lacks the symbol. - CVE-2026-7210
CVEs fixed:
Updated packages:
  • idle-python3.5_3.5.2-2ubuntu0~16.04.13+tuxcare.els25_all.deb
    sha:2151461977caf88f57401c456db7d983f272c99f
  • libpython3.5_3.5.2-2ubuntu0~16.04.13+tuxcare.els25_amd64.deb
    sha:52fa936d5eeb5fe039ee4f14e66763d90504d785
  • libpython3.5-dev_3.5.2-2ubuntu0~16.04.13+tuxcare.els25_amd64.deb
    sha:08b677effa3c07a63e1c3a25d7ab7a6264d72763
  • libpython3.5-minimal_3.5.2-2ubuntu0~16.04.13+tuxcare.els25_amd64.deb
    sha:e2e0551bd2656fda1392c5f8dcf3e1bf6a1916d2
  • libpython3.5-stdlib_3.5.2-2ubuntu0~16.04.13+tuxcare.els25_amd64.deb
    sha:392ccd08790ca94bc918d14354f24f8580bc2425
  • libpython3.5-testsuite_3.5.2-2ubuntu0~16.04.13+tuxcare.els25_all.deb
    sha:8e69dfe0918bfc58c21ab0830d0744a6536bee1a
  • python3.5_3.5.2-2ubuntu0~16.04.13+tuxcare.els25_amd64.deb
    sha:6c0a77ef0037c69e952bcfa430dc0780ac319dcb
  • python3.5-dev_3.5.2-2ubuntu0~16.04.13+tuxcare.els25_amd64.deb
    sha:baf8568df1a4a77a4e9f7eda9ca80ab82979aa08
  • python3.5-doc_3.5.2-2ubuntu0~16.04.13+tuxcare.els25_all.deb
    sha:ed5ddadd7c94d0861a617250494f2151de201b52
  • python3.5-examples_3.5.2-2ubuntu0~16.04.13+tuxcare.els25_all.deb
    sha:5d3d699be130c217799ab7cf3dd5bc7facbe3ed7
  • python3.5-minimal_3.5.2-2ubuntu0~16.04.13+tuxcare.els25_amd64.deb
    sha:92cc86245d26d96e6d574a959bd650c14f113eff
  • python3.5-venv_3.5.2-2ubuntu0~16.04.13+tuxcare.els25_amd64.deb
    sha:47db3f190c78dd4fce476c8ac097a2467dea0b0f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.