Release date:
2026-09-21 08:56:50 UTC
Description:
* SECURITY UPDATE: insufficient entropy in the hash-flooding protection
- debian/patches/CVE-2026-41080.patch: store the hash secret salt as a
full 128-bit struct sipkey instead of a single unsigned long, draw 16
bytes of entropy for it in generate_hash_secret_salt(), track whether
it was set with the new m_hash_secret_salt_set flag, and add the
XML_SetHashSalt16Bytes() API so callers can supply all 16 bytes, in
expat/lib/xmlparse.c and expat/lib/expat.h. Previously the SipHash key
was half a hardcoded zero and half an unsigned long, which is only
four bytes on 32-bit architectures such as armel
- CVE-2026-41080
Updated packages:
-
expat_2.2.10-2+deb11u7+tuxcare.els3_amd64.deb
sha:111b4043f03dd854d25c425e22fe171270839145
-
libexpat1_2.2.10-2+deb11u7+tuxcare.els3_amd64.deb
sha:a3e51f21fec1bd080e8e3b7a5ccf868fa69c1277
-
libexpat1-dev_2.2.10-2+deb11u7+tuxcare.els3_amd64.deb
sha:f27d26aa55c66587002bed1a19e11f2fd608e2d9
-
expat_2.2.10-2+deb11u7+tuxcare.els3_arm64.deb
sha:b4ef7e7536d0c892e144f5581ca91111a21e39cd
-
libexpat1_2.2.10-2+deb11u7+tuxcare.els3_arm64.deb
sha:24626eccb67c72f795e72a0e1198782b1a3f3673
-
libexpat1-dev_2.2.10-2+deb11u7+tuxcare.els3_arm64.deb
sha:2259ef037b668ef020cec77a5868c178df489570
-
expat_2.2.10-2+deb11u7+tuxcare.els3_armel.deb
sha:deaeeaa724752e7fbd13b3042c396ad4e007f227
-
libexpat1_2.2.10-2+deb11u7+tuxcare.els3_armel.deb
sha:42062ceeb29b416a3166a4c1ef126cfc02bbc679
-
libexpat1-dev_2.2.10-2+deb11u7+tuxcare.els3_armel.deb
sha:0037999fd2df76e2f5f6a98f9a35b7973b62cd61
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.