[CLSA-2026:1781169880] python2: Fix of CVE-2026-7210
Type:
security
Severity:
Critical
Release date:
2026-06-11 09:26:13 UTC
Description:
- CVE-2026-7210: seed the libexpat parser with 16 bytes of entropy via XML_SetHashSalt16Bytes when hash randomization is enabled (bound as a weak symbol; falls back to the legacy XML_SetHashSalt when unavailable) to restore hash-flooding protection
CVEs fixed:
Updated packages:
  • python2-2.7.18-7.module_el8.5.0+2416+35499604.tuxcare.els22.x86_64.rpm
    sha:fe21dbcef18ec96163be2cb14e51c16afbada521cd43aa6443cb754c076d84a2
  • python2-debug-2.7.18-7.module_el8.5.0+2416+35499604.tuxcare.els22.x86_64.rpm
    sha:91f57d08c1c1813628ae0f4aa5d4280d18d8bd2d35adcb66d72a983b204b3e54
  • python2-devel-2.7.18-7.module_el8.5.0+2416+35499604.tuxcare.els22.x86_64.rpm
    sha:27095d8b198f057ab0bc182d004ada1b6c9f99cda4496d7a9eda95341afd2c51
  • python2-libs-2.7.18-7.module_el8.5.0+2416+35499604.tuxcare.els22.x86_64.rpm
    sha:86e45df0a442680d17635edfb59379c21ce49829366eb95ddd1a6fe6542920ef
  • python2-test-2.7.18-7.module_el8.5.0+2416+35499604.tuxcare.els22.x86_64.rpm
    sha:8c75192c796cf1674cc61f6bfaf0ec7329fcfaac4ea1999cdf7567ad57d63009
  • python2-tkinter-2.7.18-7.module_el8.5.0+2416+35499604.tuxcare.els22.x86_64.rpm
    sha:da6564b5e4d77626f20ba3d86d2b60962c36961b3980852c8642e718c5ffaa23
  • python2-tools-2.7.18-7.module_el8.5.0+2416+35499604.tuxcare.els22.x86_64.rpm
    sha:cfe8bac02295f986b2cfb3df3dc100b5c9ddea7525836358d68a032c7b99bb39
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.