[CLSA-2026:1781624592] python3: Fix of CVE-2026-7210
Type:
security
Severity:
Important
Release date:
2026-06-16 15:43:27 UTC
Description:
- CVE-2026-7210: seed the libexpat parser with 16 bytes of entropy via XML_SetHashSalt16Bytes (bound as a weak symbol; falls back to the legacy 8-byte XML_SetHashSalt when unavailable) to restore hash-flooding protection - adapt XMLPullParser chunked-feed tests to the reparse-deferral behavior of the TuxCare libexpat backport (upstream gh-115133)
CVEs fixed:
Updated packages:
  • python3-3.7.16-1.amzn2.0.26.tuxcare.els1.i686.rpm
    sha:e314076a57cc9ad2e9a640d118e64be2dd62bfe7422e6caf6866b0a22ffc4997
  • python3-3.7.16-1.amzn2.0.26.tuxcare.els1.x86_64.rpm
    sha:0abde99e3f614202b9809079b5caea66ea2b48fac0bd599709563700cf259412
  • python3-debug-3.7.16-1.amzn2.0.26.tuxcare.els1.x86_64.rpm
    sha:c25649e47b9c64fc0ab1b537c77d102bf74f9ff74ded441b8a46c0ae9e558d66
  • python3-devel-3.7.16-1.amzn2.0.26.tuxcare.els1.x86_64.rpm
    sha:e51fcc8463f0a6460a58e55cbd2f9e72408dd1f3573634eb7d65cc2ceadbac44
  • python3-libs-3.7.16-1.amzn2.0.26.tuxcare.els1.i686.rpm
    sha:e0ce5e69700a2b7479b84429be100c634804c0b470cf74db3ceac782bf941d00
  • python3-libs-3.7.16-1.amzn2.0.26.tuxcare.els1.x86_64.rpm
    sha:f28cfb3b895f09fd01d08bb27c3bfc1d824d9f96992768dca425452b4e7b31a3
  • python3-test-3.7.16-1.amzn2.0.26.tuxcare.els1.x86_64.rpm
    sha:a4242c9702a4b0f274bf3235ddbd0682f82c00df6e4621d0f98587323ea51cb4
  • python3-tkinter-3.7.16-1.amzn2.0.26.tuxcare.els1.x86_64.rpm
    sha:1071005e5b5b628222ecb5c4fd50f4c11b6ce66a81330e28a3c1caeaca2adc19
  • python3-tools-3.7.16-1.amzn2.0.26.tuxcare.els1.x86_64.rpm
    sha:b955cdd2cd515da94c87c9763bf2faa9b1af6f65888d7d8067ff55787c1942f4
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.