From patchwork Wed Sep 23 11:45:01 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Adolf Belka X-Patchwork-Id: 10274 Return-Path: Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by web04.haj.ipfire.org (Postfix) with ESMTPS id 4hqZs22YvGz3wqK for ; Wed, 23 Sep 2026 11:45:10 +0000 (UTC) Received: from mail02.haj.ipfire.org (mail02.haj.ipfire.org [IPv6:2001:678:b28::201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail02.haj.ipfire.org", Issuer "YE1" (not verified)) by mail01.ipfire.org (Postfix) with ESMTPS id 4hqZs115Ztz7CL for ; Wed, 23 Sep 2026 11:45:09 +0000 (UTC) Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4hqZs10K6Bz2yT1 for ; Wed, 23 Sep 2026 11:45:09 +0000 (UTC) X-Original-To: development@lists.ipfire.org Received: from mail01.ipfire.org (mail01.haj.ipfire.org [IPv6:2001:678:b28::25]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4hqZry3F83z2xZv for ; Wed, 23 Sep 2026 11:45:06 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4hqZrx2Mhsz1mM; Wed, 23 Sep 2026 11:45:05 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1790163905; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=l/CdYVk4ojfZbz4YbL6cLn+38JmNksm6WE7irrLLi3o=; b=tJhJpn5Zb+O+y2drH5IIHs09tK4zyMQmRgiZDhpCYy8D3mEMOy8Mpc76IrrF+1LrXATgGi IUEJTB9a0UCdmUDg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1790163905; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=l/CdYVk4ojfZbz4YbL6cLn+38JmNksm6WE7irrLLi3o=; b=GuW5sUXbvJ9zXlnQDA+qTc6cNQdbRRr46Cg9r069ddwMcFhayfcsdrTxBYQ9jGEm94LZAg uvRru9lvshSk77SVl+b2TpiZ1RhzZxEMOq2bFA3s0TUVkcqU9wjT6UGE2FmfT2A92Uphj3 1DIv/TQH+c0Q97vY4cC4HN0Q/VOdHv0dMZBiSeR7wdWYGwEqhoZrwo0m5zZ7JeBVXnCiSv dNwkkL2dZpSWmbxWZv5t2aFfYO46aTyiCVX8g9nO0gI1kenKRVFpWqS5UbbCh3hNNoJIlV 2PtJnVrRbQt8qjB73sl6w95ZOizZrWtFrXQ+XyYcDv6/XcQT2+uryGJCERSVLw== From: Adolf Belka To: development@lists.ipfire.org Cc: Adolf Belka Subject: [PATCH] expat: Update to version 2.8.5 Date: Wed, 23 Sep 2026 13:45:01 +0200 Message-ID: <20260923114502.3455008-1-adolf.belka@ipfire.org> Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 - Update from version 2.8.4 to 2.8.5 - Update of rootfile - 1 fix for a CVE - Changelog 2.8.5 Security fixes: (#1282) CVE-2026-93990 -- Reject high surrogates not followed by a low surrogate during UTF-16 decoding; previously, malformed UTF-16 could be smuggled into the application using Expat and could cause arbitrary damage there, depending on how malformed UTF-16 was handled inside the application; validation was not their job but Expat's. This is similar to past vulnerability CVE-2022-25235. Upstream CVSS 3.1 vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (CVSS score: 9.8) Bug fixes: (#1346) lib: Fix OOM-related memory leak on a failed overflow check (#1371) lib: Fix memory alignment for architectures with 128bit pointers like CHERI-RISC-V (#1367) xmlwf: Handle errors when closing output files Other changes: (#1354) lib: Reject an XML declaration version other than `1.[0-9]+` (which is less strict than XML 1.0r4 (fourth edition) and matches XML 1.0r5 (fifth edition)) (#1362) lib: Make Clang, GCC and MSVC warn about use of function XML_SetHashSalt that is deprecated since Expat 2.8.0 (#1357) lib: Drop internal macros FASTCALL, PTRCALL, PTRFASTCALL (#1367) xmlwf: Document that with `-k` the last error determines the xmlwf exit code in `--help` output (#1367) xmlwf: Make exit code 3 documentation match exit code 2 more closely in `--help` output (#1352 #1353) CMake|Windows: Refrain from adding `/source-charset:utf-8` for MSVC (#1366 #1374) Autotools: Be explicit about the minimum required version of GNU Automake, currently version 1.13 of 2012-12-28 (#1351) Autotools|macOS: Sync CMake templates with CMake 4.4.3 (#1349) Replace some internal use of XML_Bool with standard bool (#1364) tests: Propagate xmltest.sh failures via exit status (#1360) tests|xmlwf: Add `#include "expat_config.h"` where missing (#1355) tests: Start covering hash table operation (#1350 #1369) tests: Drop __cplusplus leftovers (#1378) tests: Fix tail pointer when unlinking the last tracked allocation (#1376) docs: Emphasize that XML_StopParser is not immediate (#1381) docs: Sync XML_FeatureEnum value list in doc/reference.html (#1356 #1361) Version info bumped from 13:4:12 (libexpat*.so.1.12.4) to 13:5:12 (libexpat*.so.1.12.5); see https://verbump.de/ for what these numbers do Infrastructure: (#1347) Add missing .gitignore entries (#1360) CI: Detect missing `#include "expat_config.h"` (#1368) CI: Bump MinGW Clang from 23.0.1 to 23.1.1 (#1377) CI: Bump Fil-C from 0.684 to 0.685 (#1380) CI: Bump Cppcheck from 2.21.0 to 2.22.0 (#1372) CI: Extract helper script `apply-htmltidy.sh` (#1366 #1374) Autotools: Start to also produce .tar.bz3 release tarballs Signed-off-by: Adolf Belka --- config/rootfiles/common/expat | 20 ++++++++++---------- lfs/expat | 4 ++-- 2 files changed, 12 insertions(+), 12 deletions(-) diff --git a/config/rootfiles/common/expat b/config/rootfiles/common/expat index 575cbe1cb..a32adc876 100644 --- a/config/rootfiles/common/expat +++ b/config/rootfiles/common/expat @@ -2,21 +2,21 @@ #usr/include/expat.h #usr/include/expat_config.h #usr/include/expat_external.h -#usr/lib/cmake/expat-2.8.4 -#usr/lib/cmake/expat-2.8.4/expat-config-version.cmake -#usr/lib/cmake/expat-2.8.4/expat-config.cmake -#usr/lib/cmake/expat-2.8.4/expat-noconfig.cmake -#usr/lib/cmake/expat-2.8.4/expat.cmake +#usr/lib/cmake/expat-2.8.5 +#usr/lib/cmake/expat-2.8.5/expat-config-version.cmake +#usr/lib/cmake/expat-2.8.5/expat-config.cmake +#usr/lib/cmake/expat-2.8.5/expat-noconfig.cmake +#usr/lib/cmake/expat-2.8.5/expat.cmake #usr/lib/libexpat.la #usr/lib/libexpat.so usr/lib/libexpat.so.1 -usr/lib/libexpat.so.1.12.4 +usr/lib/libexpat.so.1.12.5 #usr/lib/pkgconfig/expat.pc #usr/share/doc/expat -#usr/share/doc/expat-2.8.4 -#usr/share/doc/expat-2.8.4/ok.min.css -#usr/share/doc/expat-2.8.4/reference.html -#usr/share/doc/expat-2.8.4/style.css +#usr/share/doc/expat-2.8.5 +#usr/share/doc/expat-2.8.5/ok.min.css +#usr/share/doc/expat-2.8.5/reference.html +#usr/share/doc/expat-2.8.5/style.css #usr/share/doc/expat/AUTHORS #usr/share/doc/expat/changelog #usr/share/man/man1/xmlwf.1 diff --git a/lfs/expat b/lfs/expat index 512cb5a76..b5f9466e4 100644 --- a/lfs/expat +++ b/lfs/expat @@ -24,7 +24,7 @@ include Config -VER = 2.8.4 +VER = 2.8.5 THISAPP = expat-$(VER) DL_FILE = $(THISAPP).tar.xz @@ -40,7 +40,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = bec06d3c3179115692edb5e9366412361abae5355b131a005ef91aaa041bf4ebf74a86cc2fac29c44730a07cba6fbda988a6bfdafafc9eeba25a00fb98e43d24 +$(DL_FILE)_BLAKE2 = 7d10459714722c6e4e858da92d3f7def6950240275ad5054b97f5d7612524f2813b8add75d6693698c8e7cdb4a64f73750346783e438ff6271dbc80643d51ee7 install : $(TARGET)