https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296191
Bug ID: 296191
Summary: textproc/expat2: vulnerable to e.g. CVE-2026-56408
Product: Ports & Packages
Version: Latest
Hardware: Any
URL: https://github.com/libexpat/libexpat/issues/1276
OS: Any
Status: New
Keywords: security
Severity: Affects Some People
Priority: ---
Component: Individual Port(s)
Assignee: [email protected]
Reporter: [email protected]
Flags: maintainer-feedback?([email protected])
Assignee: [email protected]
See https://github.com/libexpat/libexpat/issues/1276 for brief CVE list
(Release Expat 2.8.2 (no ETA)
Upstream still works on patching CVEs, e.g. this one was committed just an hour
ago:
https://github.com/libexpat/libexpat/commit/11cd58eb92dd8eb
One could either attempt backporting CVE fixes from master or wait for 2.8.2
release.
--
You are receiving this mail because:
You are the assignee for the bug.