[CLSA-2026:1789980999] Fix CVE(s): CVE-2026-41080
Type:
security
Severity:
Low
Release date:
2026-09-21 08:56:50 UTC
Description:
* SECURITY UPDATE: insufficient entropy in the hash-flooding protection - debian/patches/CVE-2026-41080.patch: store the hash secret salt as a full 128-bit struct sipkey instead of a single unsigned long, draw 16 bytes of entropy for it in generate_hash_secret_salt(), track whether it was set with the new m_hash_secret_salt_set flag, and add the XML_SetHashSalt16Bytes() API so callers can supply all 16 bytes, in expat/lib/xmlparse.c and expat/lib/expat.h. Previously the SipHash key was half a hardcoded zero and half an unsigned long, which is only four bytes on 32-bit architectures such as armel - CVE-2026-41080
CVEs fixed:
Updated packages:
  • expat_2.2.10-2+deb11u7+tuxcare.els3_amd64.deb
    sha:111b4043f03dd854d25c425e22fe171270839145
  • libexpat1_2.2.10-2+deb11u7+tuxcare.els3_amd64.deb
    sha:a3e51f21fec1bd080e8e3b7a5ccf868fa69c1277
  • libexpat1-dev_2.2.10-2+deb11u7+tuxcare.els3_amd64.deb
    sha:f27d26aa55c66587002bed1a19e11f2fd608e2d9
  • expat_2.2.10-2+deb11u7+tuxcare.els3_arm64.deb
    sha:b4ef7e7536d0c892e144f5581ca91111a21e39cd
  • libexpat1_2.2.10-2+deb11u7+tuxcare.els3_arm64.deb
    sha:24626eccb67c72f795e72a0e1198782b1a3f3673
  • libexpat1-dev_2.2.10-2+deb11u7+tuxcare.els3_arm64.deb
    sha:2259ef037b668ef020cec77a5868c178df489570
  • expat_2.2.10-2+deb11u7+tuxcare.els3_armel.deb
    sha:deaeeaa724752e7fbd13b3042c396ad4e007f227
  • libexpat1_2.2.10-2+deb11u7+tuxcare.els3_armel.deb
    sha:42062ceeb29b416a3166a4c1ef126cfc02bbc679
  • libexpat1-dev_2.2.10-2+deb11u7+tuxcare.els3_armel.deb
    sha:0037999fd2df76e2f5f6a98f9a35b7973b62cd61
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.