[CLSA-2026:1780647419] expat: Fix of CVE-2026-41080
Type:
security
Severity:
Low
Release date:
2026-06-05 08:17:15 UTC
Description:
- CVE-2026-41080: fix hash-flooding DoS caused by insufficient salt entropy by backporting SipHash-2-4 keyed hashing with a 16-byte salt sourced from /dev/urandom
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.amzn2.tuxcare.els3.i686.rpm
    sha:5985a216732bc9c4f6ba7dbc54c5b257277a39d8a514949a1512b98c96352014
  • expat-2.1.0-15.0.7.amzn2.tuxcare.els3.x86_64.rpm
    sha:ccfcd6a0366d8aedab1dea3068cfa797b1dbaf8aade736955687f405d858903c
  • expat-devel-2.1.0-15.0.7.amzn2.tuxcare.els3.x86_64.rpm
    sha:02324d102dfba3896d6eb1c4e7748e4bfe731a62b513a1f049300c7cfebd26a6
  • expat-static-2.1.0-15.0.7.amzn2.tuxcare.els3.x86_64.rpm
    sha:3a64992ca8c59fbed292321d2e5925d2e46b37681b15fce71e3c2aa928d567e7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.