[CLSA-2026:1780647967] expat: Fix of CVE-2026-41080
Type:
security
Severity:
Low
Release date:
2026-06-06 00:14:42 UTC
Description:
- CVE-2026-41080: fix hash-flooding DoS caused by insufficient salt entropy by backporting SipHash-2-4 keyed hashing with a 16-byte salt sourced from /dev/urandom
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els3.i686.rpm
    sha:8398c4e8cebf414dfefdce11c57bb28b873c28d31595dbf6de4dd41f9c5604d7
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els3.x86_64.rpm
    sha:8bbe962d597301a2c900643e4f3ba647d5ec6dba9c816835b0ba8ceef5c6bab7
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els3.i686.rpm
    sha:0a0234f34742108e22f06328949aabddf0389debdf40278f025f6ca51f301df4
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els3.x86_64.rpm
    sha:e959e52485477083217f689aa70f9044d3c03a70886d74dcfb41da6246b3e22a
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els3.i686.rpm
    sha:f46265ab63b271da1330126a7c150b013cf829b4be61e187d52a3d2cfe650454
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els3.x86_64.rpm
    sha:2dfb3a4c25064e81c1296a7621e2394761094321214197e452ca54ae98372bd5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.