[CLSA-2026:1780697020] expat: Fix of CVE-2026-41080
Type:
security
Severity:
Low
Release date:
2026-06-06 00:03:05 UTC
Description:
- CVE-2026-41080: fix hash-flooding DoS caused by insufficient salt entropy by backporting SipHash-2-4 keyed hashing with a 16-byte salt sourced from /dev/urandom
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els3.i686.rpm
    sha:8e96215c52e5f08c4a3e4831fd250b6bd9f76328c1c33248dfe55ae068d960db
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els3.x86_64.rpm
    sha:ded033927b9b64b5e6421c517411b45ae74bbed7e52ddad2437c2404f0dfef3d
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els3.i686.rpm
    sha:506c7925309eebfd47e0a19b04ee9e2fdff3f6f4e290c79c7fe8fe2914f10c18
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els3.x86_64.rpm
    sha:401f8914c3c9f333af7b9f3e928e0dc1f1a4368c92228c7052a7fb5f8846e94f
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els3.i686.rpm
    sha:0af5e1fcafac16df69934e0fc40eb1fff9d8715bd15d9b8e79e59d6dff3a238e
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els3.x86_64.rpm
    sha:5b58f9eb346d5cce188a10552852eb54f19b22d16adada2a4af10a3fa0a096f7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.