CVE-2018-14647: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 10.9% chance of exploitation in the next 30 days.

Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM. The vulnerability exists in Python versions 3.7.0, 3.6.0 through 3.6.6, 3.5.0 through 3.5.6, 3.4.0 through 3.4.9, 2.7.0 through 2.7.15.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Fedoraproject Fedora: version 30 only
  • Opensuse Leap: version 15.1 only
  • Python Python: from 2.7.0, up to and including 2.7.15; from 3.4.0, up to and including 3.4.9; from 3.5.0, up to and including 3.5.6; from 3.6.0, up to and including 3.6.6; version 3.7.0 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only

Published 2018-09-25. Last modified 2026-10-07.