[CLSA-2026:1780578419] expat: Fix of CVE-2026-41080
Type:
security
Severity:
Low
Release date:
2026-06-04 13:07:17 UTC
Description:
- CVE-2026-41080: fix hash-flooding DoS from insufficient salt entropy by extracting a full 16-byte hash salt and adding the XML_SetHashSalt16Bytes API
CVEs fixed:
Updated packages:
  • expat-2.5.0-1.el8.tuxcare.els5.i686.rpm
    sha:ba1959633e285c7651959d3ed9f732403fe90a961df3c5840473fe25514ba370
  • expat-2.5.0-1.el8.tuxcare.els5.x86_64.rpm
    sha:4ad678648ae37c69d6ebe3c3cef1a2826bc3343eeeb0b602f88265dec7fca260
  • expat-devel-2.5.0-1.el8.tuxcare.els5.i686.rpm
    sha:cb9178ad173e93ca97a7966866f034f2151dd47a901d3030b7022586af1ff9eb
  • expat-devel-2.5.0-1.el8.tuxcare.els5.x86_64.rpm
    sha:9dbe439be60dd36a0eac913e25763ee6233fa29f399005771b9e24504b339560
  • expat-static-2.5.0-1.el8.tuxcare.els5.x86_64.rpm
    sha:7bc08bebb0339a7e110071621c96c06d907b1bcf87674f76a03c896540173015
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.