[CLSA-2026:1780648259] expat: Fix of CVE-2026-41080
Type:
security
Severity:
Low
Release date:
2026-06-05 08:31:21 UTC
Description:
- CVE-2026-41080: fix hash-flooding DoS caused by insufficient salt entropy by backporting SipHash-2-4 keyed hashing with a 16-byte salt sourced from /dev/urandom
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els3.i686.rpm
    sha:b4fa6619fc0a997941bb729596906266c778f37d396a804b1a2467ac16e05c98
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els3.x86_64.rpm
    sha:7449153ba3683cac0b1165d2f6f119ced88d2c19b5a915aa51112d5c2be119f2
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els3.i686.rpm
    sha:ef6e5ea24afdf3126b4ac81ed334b9dc83a57aaef4ed40bf76458df9d22b457b
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els3.x86_64.rpm
    sha:756f93453778fd6f540029ca7917a063f2151fedd8953697cf90df958067811b
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els3.i686.rpm
    sha:3b5deda76db117db1df3a20c7498c3f829d4f54d5bc2cdd929036351541bd18c
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els3.x86_64.rpm
    sha:581fdb661bc0021f1ca2da9b27fa6c0d99c79ea28cc683067798c588e479c269
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.