[CLSA-2026:1780648384] expat: Fix of CVE-2026-41080
Type:
security
Severity:
Low
Release date:
2026-06-05 08:33:26 UTC
Description:
- CVE-2026-41080: fix hash-flooding DoS caused by insufficient salt entropy by backporting SipHash-2-4 keyed hashing with a 16-byte salt sourced from /dev/urandom
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els3.i686.rpm
    sha:c251def904968fa58df14a0ff5d92b275e00aa6f21ee1e2a99ccbd65ae69ee31
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els3.x86_64.rpm
    sha:7ed67c1867c7605e1a454ceae9fa13294b0431d7289226a0d9c476e8be77d7f2
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els3.i686.rpm
    sha:6fdf2e063af8cc927b287e1cd7815bee687fa4baec9169f9e7ee5de61ed34133
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els3.x86_64.rpm
    sha:83dd86a66bf59bf8027964124a42a601eb0146652b5b28a275d5fee3f0f55b07
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els3.i686.rpm
    sha:0147b83126b58201e492d2797979ac75030d9a994d878ae9b0e71c79706c0181
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els3.x86_64.rpm
    sha:99698deb1dcb3b87af138bbb8dd77054d75b20b16d4caa65004da4f89a7bb564
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.