https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296191

            Bug ID: 296191
           Summary: textproc/expat2: vulnerable to e.g. CVE-2026-56408
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
               URL: https://github.com/libexpat/libexpat/issues/1276
                OS: Any
            Status: New
          Keywords: security
          Severity: Affects Some People
          Priority: ---
         Component: Individual Port(s)
          Assignee: [email protected]
          Reporter: [email protected]
             Flags: maintainer-feedback?([email protected])
          Assignee: [email protected]

See https://github.com/libexpat/libexpat/issues/1276 for brief CVE list
(Release Expat 2.8.2 (no ETA)

Upstream still works on patching CVEs, e.g. this one was committed just an hour
ago:
https://github.com/libexpat/libexpat/commit/11cd58eb92dd8eb

One could either attempt backporting CVE fixes from master or wait for 2.8.2
release.

-- 
You are receiving this mail because:
You are the assignee for the bug.

Reply via email to