[CLSA-2026:1780705975] Fix CVE(s): CVE-2026-7210
Type:
security
Severity:
Critical
Release date:
2026-06-08 09:13:19 UTC
Description:
* SECURITY UPDATE: insufficient entropy in pyexpat/_elementtree hash-flooding protection (CVE-2026-7210) - debian/patches/CVE-2026-7210.patch: bind XML_SetHashSalt16Bytes as a weak symbol to seed the parser with 16 bytes of entropy; falls back to the legacy 8-byte XML_SetHashSalt when libexpat lacks the symbol. - CVE-2026-7210
CVEs fixed:
Updated packages:
  • idle-python3.6_3.6.9-1~18.04ubuntu1.12+tuxcare.els22_all.deb
    sha:08e0f2281603919bd279f8da0c254e8a3dbedba8
  • libpython3.6_3.6.9-1~18.04ubuntu1.12+tuxcare.els22_amd64.deb
    sha:cba767af8521794e4658c5bee221511031cc8fef
  • libpython3.6-dev_3.6.9-1~18.04ubuntu1.12+tuxcare.els22_amd64.deb
    sha:c46d6a16d21c53fb57b55b61267e945e99f79e8d
  • libpython3.6-minimal_3.6.9-1~18.04ubuntu1.12+tuxcare.els22_amd64.deb
    sha:1dbd28a062cd510cacd7b65b1e7a9186b9cc22a2
  • libpython3.6-stdlib_3.6.9-1~18.04ubuntu1.12+tuxcare.els22_amd64.deb
    sha:785eb055d4c5359f6cdc3782fcb70a6bdf047da3
  • libpython3.6-testsuite_3.6.9-1~18.04ubuntu1.12+tuxcare.els22_all.deb
    sha:43c91a52fe22ca55bc969d9b4f42b21d2f572214
  • python3.6_3.6.9-1~18.04ubuntu1.12+tuxcare.els22_amd64.deb
    sha:6df77dc9cfcc8409483e9ccabab2b825af8cfaf7
  • python3.6-dev_3.6.9-1~18.04ubuntu1.12+tuxcare.els22_amd64.deb
    sha:4e158d29e0356eac857487bf7c96dd3f54020327
  • python3.6-doc_3.6.9-1~18.04ubuntu1.12+tuxcare.els22_all.deb
    sha:17c980267b2b3f3200472bd64576545359935794
  • python3.6-examples_3.6.9-1~18.04ubuntu1.12+tuxcare.els22_all.deb
    sha:ba360a4fd7f7f59461e8c0523a69da478418477a
  • python3.6-minimal_3.6.9-1~18.04ubuntu1.12+tuxcare.els22_amd64.deb
    sha:b4cee19689efdafcf4e1abf0994aa023f71cfc2f
  • python3.6-venv_3.6.9-1~18.04ubuntu1.12+tuxcare.els22_amd64.deb
    sha:1dd29d62f06cff73cd9e3bf6496a18c719c0f96d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.