[CLSA-2026:1780705981] python: Fix of CVE-2026-7210
Type:
security
Severity:
Critical
Release date:
2026-06-08 09:23:35 UTC
Description:
- CVE-2026-7210: seed the libexpat parser with 16 bytes of entropy via XML_SetHashSalt16Bytes when hash randomization is enabled (bound as a weak symbol; falls back to the legacy XML_SetHashSalt when unavailable) to restore hash-flooding protection
CVEs fixed:
Updated packages:
  • python-2.7.18-1.amzn2.0.19.tuxcare.els2.x86_64.rpm
    sha:64161520e6ce0dec0e7e6fe9809689049bd3914964a89cc338468b1c2a536508
  • python-debug-2.7.18-1.amzn2.0.19.tuxcare.els2.x86_64.rpm
    sha:4169c947cb51584d9c20c8ebbefad9afd30db62515a2e30a5cf75f217714c7ce
  • python-devel-2.7.18-1.amzn2.0.19.tuxcare.els2.x86_64.rpm
    sha:bcf768791f01f36f5a89028ee15bcfd954c56defebfb2ede46a65a4f2c46d997
  • python-libs-2.7.18-1.amzn2.0.19.tuxcare.els2.i686.rpm
    sha:d6015f555d8348776579b183bce1bfc3ea7b8df0686a33a4b6edadb50d67037c
  • python-libs-2.7.18-1.amzn2.0.19.tuxcare.els2.x86_64.rpm
    sha:a191438bb903247b0f5713091cf9a238b661f7647d98bc7850afe474d80e0e66
  • python-test-2.7.18-1.amzn2.0.19.tuxcare.els2.x86_64.rpm
    sha:034734f92c4325ebd2652edb4608c2ac2b9af10900fbc339d17cbe3bdad4a821
  • python-tools-2.7.18-1.amzn2.0.19.tuxcare.els2.x86_64.rpm
    sha:ec7577ca2197c87e39b698ec68cb25e379feabfa87cb9d66146e4eaa9b2fa708
  • tkinter-2.7.18-1.amzn2.0.19.tuxcare.els2.x86_64.rpm
    sha:2e846fd4e6685bcb743641db663d0124edccb7b53f1b84b3d9a7641afa3630b0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.