[CLSA-2026:1781252611] python: Fix of CVE-2026-7210
Type:
security
Severity:
Critical
Release date:
2026-06-12 08:23:54 UTC
Description:
- CVE-2026-7210: when hash randomization is enabled, seed libexpat's hash-flooding protection in pyexpat with a full 16 bytes of entropy via XML_SetHashSalt16Bytes, detected at runtime through a weak symbol so it activates once the system libexpat exposes it, instead of the 4-8 byte XML_SetHashSalt
CVEs fixed:
Updated packages:
  • python-2.6.6-70.el6.tuxcare.els23.i686.rpm
    sha:28f2c0cb6bf0dca9ddd3d23cd304dbcd2bba4b37cc88e3ccbab81b4e2a94e860
  • python-2.6.6-70.el6.tuxcare.els23.x86_64.rpm
    sha:9b8706bb2ad9aa2914d7dd1bf67071cd2490804a52c606818bae979a6518bb5c
  • python-devel-2.6.6-70.el6.tuxcare.els23.i686.rpm
    sha:99db5d63760c8303efa408b145c9ed6bf1b8c4c7383fce640abe92dffd19004f
  • python-devel-2.6.6-70.el6.tuxcare.els23.x86_64.rpm
    sha:75722c8fd8f6c6ab2a43970da54c6f5f618a8ba5c9c27438c621425e1469fb8a
  • python-libs-2.6.6-70.el6.tuxcare.els23.i686.rpm
    sha:8f32342863b813901e2853786dd59c5114947f2391531c55af5455aa857a9af7
  • python-libs-2.6.6-70.el6.tuxcare.els23.x86_64.rpm
    sha:5b1e445fd7160101beec2a0858d09a10ecb94ca4b366ee41d5573b967343f696
  • python-test-2.6.6-70.el6.tuxcare.els23.x86_64.rpm
    sha:4294872b3a30a1f809174997fdda0dbcdb43cc94434f4abe3f4560c84575059b
  • python-tools-2.6.6-70.el6.tuxcare.els23.x86_64.rpm
    sha:158ffed8d5ac8c07f09bdc4ad8fe180e9c97a24daded912d6e15ddd3e2093447
  • tkinter-2.6.6-70.el6.tuxcare.els23.x86_64.rpm
    sha:114eb8c7a15d4614f1072df8fb7bed9295f3889b6958e0484e0fd2d89579170c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.