[LFS Trac] #5934: Fix CVE-2026-7210 in Python

"LFS Trac" ([email protected] via lfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.book
Message-ID <[email protected]>
#5934: Fix CVE-2026-7210 in Python
-----------------------------+----------------------
 Reporter:  Douglas R. Reno  |      Owner:  lfs-book
     Type:  enhancement      |     Status:  new
 Priority:  high             |  Milestone:  13.1
Component:  Book             |    Version:  git
 Severity:  normal           |   Keywords:
-----------------------------+----------------------
 While reviewing my email, I was greeted to another CPython security
 vulnerability, this time also valid for 3.14.5.

 {{{
 -------- Forwarded Message --------
 Subject:     [Security-announce][CVE-2026-7210] The expat and elementtree
 parsers use insufficient entropy for XML hash-flooding protection
 Date:     Mon, 11 May 2026 17:58:49 +0100
 From:     Stan Ulbrych via Security-announce <security-
 [email protected]>
 Reply-To:     [email protected]
 To:     [email protected]
 CC:     Stan Ulbrych <[email protected]>



 There is a MEDIUM severity vulnerability affecting CPython.

 `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy
 for Expat hash-flooding protection, which allows a crafted XML document to
 trigger hash flooding.

 Fully mitigating this vulnerability requires both updating libexpat to
 2.8.0 or later and applying this patch.

 Please see the linked CVE ID for the latest information on affected
 versions:

 * https://www.cve.org/CVERecord?id=CVE-2026-7210
 * https://github.com/python/cpython/pull/149023
 }}}

 an insufficient entropy problem that also requires users to update to
 Expat 2.8.0 or later.
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/lfs/ticket/5934>
LFS Trac <https://wiki.linuxfromscratch.org/lfs/>
Linux From Scratch: Your Distro, Your Rules.

-- 
http://lists.linuxfromscratch.org/sympa/info/lfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.