diff mbox series

[AUH] expat: upgrading to 2.8.5 SUCCEEDED

Message ID 010101a0ccf2e5a9-90494f28-4a70-4bd2-b272-b6ef9cd6e039-000000@us-west-2.amazonses.com
State New
Headers show
Series [AUH] expat: upgrading to 2.8.5 SUCCEEDED | expand

Commit Message

auh@yoctoproject.org Sept. 23, 2026, 6:27 a.m. UTC
Hello,

this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe(s) *expat* to *2.8.5* has Succeeded.

Next steps:
    - apply the patch: git am 0001-expat-upgrade-2.8.4-2.8.5.patch
    - check the changes to upstream patches and summarize them in the commit message,
    - compile an image that contains the package
    - perform some basic sanity tests
    - amend the patch and sign it off: git commit -s --reset-author --amend
    - send it to the appropriate mailing list

Alternatively, if you believe the recipe should not be upgraded at this time,
you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that
automatic upgrades would no longer be attempted.

Please review the attached files for further information and build/update failures.
Any problem please file a bug at https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler

Regards,
The Upgrade Helper

-- >8 --
From 0d6766a2a7a83dcef09be748809f8def0aaa74fd Mon Sep 17 00:00:00 2001
From: Upgrade Helper <auh@yoctoproject.org>
Date: Wed, 23 Sep 2026 05:39:14 +0000
Subject: [PATCH] expat: upgrade 2.8.4 -> 2.8.5
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

!!                                                                           !!
!! If your business relies on Expat beyond January 2027, please consider     !!
!! funding the maintenance of Expat to ensure its health and security for    !!
!! you and others. Thank you!                                                !!
!!                                                                           !!
!!                                   Sebastian Pipping -- Berlin, 2026-09-22 !!
Release 2.8.5 Tue September 22 2026
        Security fixes:
           #1282  CVE-2026-93990 -- Reject high surrogates not followed by a
                    low surrogate during UTF-16 decoding; previously, malformed
                    UTF-16 could be smuggled into the application using Expat
                    and could cause arbitrary damage there, depending on how
                    malformed UTF-16 was handled inside the application;
                    validation was not their job but Expat's. This is similar
                    to past vulnerability CVE-2022-25235.
                    Upstream CVSS 3.1 vector:
                    AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (CVSS score: 9.8)

///////////////////////////////////////////////////////////////////////////////
// The next release will drop two (disabled-by-default) features:            //
//                                                                           //
// - ATTR_INFO (-DXML_ATTR_INFO, -DEXPAT_ATTR_INFO, --enable-xml-attr-info,  //
//              function XML_GetAttributeInfo, struct XML_AttrInfo)          //
// - MIN_SIZE (-DXML_MIN_SIZE, -DEXPAT_MIN_SIZE)                             //
//                                                                           //
// If you need them in 2026 and beyond, please share your scenario at        //
// GitHub issues #1370 (for ATTR_INFO) and/or #1379 (for MIN_SIZE). Thanks!  //
///////////////////////////////////////////////////////////////////////////////

        Bug fixes:
           #1346  lib: Fix OOM-related memory leak on a failed overflow check
           #1371  lib: Fix memory alignment for architectures with 128bit
                    pointers like CHERI-RISC-V
           #1367  xmlwf: Handle errors when closing output files

        Other changes:
           #1354  lib: Reject an XML declaration version other than `1.[0-9]+`
                    (which is less strict than XML 1.0r4 (fourth edition)
                    and matches XML 1.0r5 (fifth edition))
           #1362  lib: Make Clang, GCC and MSVC warn about use of function
                    XML_SetHashSalt that is deprecated since Expat 2.8.0
           #1357  lib: Drop internal macros FASTCALL, PTRCALL, PTRFASTCALL
           #1367  xmlwf: Document that with `-k` the last error determines the
                    xmlwf exit code in `--help` output
           #1367  xmlwf: Make exit code 3 documentation match exit code 2 more
                    closely in `--help` output
     #1352 #1353  CMake|Windows: Refrain from adding `/source-charset:utf-8`
                    for MSVC
     #1366 #1374  Autotools: Be explicit about the minimum required version of
                    GNU Automake, currently version 1.13 of 2012-12-28
           #1351  Autotools|macOS: Sync CMake templates with CMake 4.4.3
           #1349  Replace some internal use of XML_Bool with standard bool
           #1364  tests: Propagate xmltest.sh failures via exit status
           #1360  tests|xmlwf: Add `#include "expat_config.h"` where missing
           #1355  tests: Start covering hash table operation
     #1350 #1369  tests: Drop __cplusplus leftovers
           #1378  tests: Fix tail pointer when unlinking the last tracked
                    allocation
           #1376  docs: Emphasize that XML_StopParser is not immediate
           #1381  docs: Sync XML_FeatureEnum value list in doc/reference.html
     #1356 #1361  Version info bumped from 13:4:12 (libexpat*.so.1.12.4)
                    to 13:5:12 (libexpat*.so.1.12.5); see https://verbump.de/
                    for what these numbers do

        Infrastructure:
           #1347  Add missing .gitignore entries
           #1360  CI: Detect missing `#include "expat_config.h"`
           #1368  CI: Bump MinGW Clang from 23.0.1 to 23.1.1
           #1377  CI: Bump Fil-C from 0.684 to 0.685
           #1380  CI: Bump Cppcheck from 2.21.0 to 2.22.0
           #1372  CI: Extract helper script `apply-htmltidy.sh`
     #1366 #1374  Autotools: Start to also produce .tar.bz3 release tarballs

        Special thanks to:
            Afonso Januário
            Braian Plaku
            Florian Schmaus
            Huang Wenbin
            Kamila Szewczyk
            Kartik Kenchi
            Leo Camus
            Matthew Fernandez
            Stan Ulbrych
                 and
            City of Munich Open Source Sabbatical
---
 meta/recipes-core/expat/{expat_2.8.4.bb => expat_2.8.5.bb} | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
 rename meta/recipes-core/expat/{expat_2.8.4.bb => expat_2.8.5.bb} (92%)
diff mbox series

Patch

diff --git a/meta/recipes-core/expat/expat_2.8.4.bb b/meta/recipes-core/expat/expat_2.8.5.bb
similarity index 92%
rename from meta/recipes-core/expat/expat_2.8.4.bb
rename to meta/recipes-core/expat/expat_2.8.5.bb
index 050f148b07..c032e18c77 100644
--- a/meta/recipes-core/expat/expat_2.8.4.bb
+++ b/meta/recipes-core/expat/expat_2.8.5.bb
@@ -15,7 +15,7 @@  SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2  \
 GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/"
 UPSTREAM_CHECK_REGEX = "releases/tag/R_(?P<pver>.+)"
 
-SRC_URI[sha256sum] = "963250a823c16a498582b4ad82ad0f88926be0769675d3b6956be4d769a1cd8f"
+SRC_URI[sha256sum] = "952c03c33a6b337f12dae7a9b0f9dee86f867550d35c994d6bdaaddd37dc8454"
 
 EXTRA_OECMAKE:class-native += "-DEXPAT_BUILD_DOCS=OFF"