Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package expat for openSUSE:Factory checked in at 2026-08-24 12:01:29 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/expat (Old) and /work/SRC/openSUSE:Factory/.expat.new.1258 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "expat" Mon Aug 24 12:01:29 2026 rev:87 rq:1372946 version:2.8.2 Changes: -------- --- /work/SRC/openSUSE:Factory/expat/expat.changes 2026-05-16 19:23:41.111974655 +0200 +++ /work/SRC/openSUSE:Factory/.expat.new.1258/expat.changes 2026-08-24 12:01:59.642441925 +0200 @@ -1,0 +2,39 @@ +Fri Aug 21 21:02:51 UTC 2026 - Dirk Müller <[email protected]> + +- update to 2.8.2 ( + bsc#1267631, CVE-2026-50219, + bsc#1268572, CVE-2026-56131, + bsc#1268573, CVE-2026-56132, + bsc#1275096, CVE-2026-56403, CVE-2026-56404, CVE-2026-56405, + CVE-2026-56406, CVE-2026-56407, CVE-2026-56408, + CVE-2026-56409, CVE-2026-56410, CVE-2026-56411, + CVE-2026-56412): + * #1246 CVE-2026-50219 -- Disallow calls to functions + * `XML_GetBuffer`, `XML_Parse`, `XML_ParseBuffer`, + * `XML_ParserFree`, `XML_ParserReset` to guard e.g. + * Expat bindings from memory corruption; + * #1267 CVE-2026-56131 -- Protect XML_ResumeParser from being + called from a handler, plugging a hole in the fix to CVE-2026-50219 + * #1272 CVE-2026-56132 -- Fix out-of-bound scaffolding index + store in `doProlog` + * #1229 #1232 CVE-2026-56403 -- Integer overflow in + `storeAtts` + * #1249 CVE-2026-56404 -- Integer overflow in `addBinding` + * #1251 CVE-2026-56405 -- Integer overflow in `getAttributeId` + * #1255 CVE-2026-56406 -- Integer overflow in + `XML_ParseBuffer` + * #1262 CVE-2026-56407 -- Integer overflow in `textLen` + handling + * #565 CVE-2026-56408 -- Integer overflow in `copyString` + * #1259 CVE-2026-56409 -- xmlwf: Integer overflow in output + path join + * #1252 CVE-2026-56410 -- xmlwf: Integer overflow in + `resolveSystemId` + * #1263 CVE-2026-56411 -- xmlwf: Integer overflow in notation + list allocation + * #1278 CVE-2026-56412 -- Guard XML_TOK_DATA_CHARS handler + calls in `doCdataSection`, plugging a hole in the fix to + CVE-2026-50219 + + +------------------------------------------------------------------- Old: ---- expat-2.8.1.tar.xz expat-2.8.1.tar.xz.asc New: ---- expat-2.8.2.tar.xz expat-2.8.2.tar.xz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ expat.spec ++++++ --- /var/tmp/diff_new_pack.wBbalX/_old 2026-08-24 12:02:01.137494670 +0200 +++ /var/tmp/diff_new_pack.wBbalX/_new 2026-08-24 12:02:01.139494740 +0200 @@ -17,10 +17,10 @@ # -%global unversion 2_8_1 +%global unversion 2_8_2 %define sover 1 Name: expat -Version: 2.8.1 +Version: 2.8.2 Release: 0 Summary: XML Parser Toolkit License: MIT ++++++ expat-2.8.1.tar.xz -> expat-2.8.2.tar.xz ++++++ ++++ 4633 lines of diff (skipped) ++++++ expat.keyring ++++++ --- /var/tmp/diff_new_pack.wBbalX/_old 2026-08-24 12:02:01.606511217 +0200 +++ /var/tmp/diff_new_pack.wBbalX/_new 2026-08-24 12:02:01.621511746 +0200 @@ -1,6 +1,6 @@ -----BEGIN PGP PUBLIC KEY BLOCK----- -Version: Hockeypuck 2.2 Comment: Hostname: +Version: Hockeypuck 2.2 xsFNBFzUcE0BEACzkr4qR9zoM63YCJU/oQTJEtt7SR9Hcvntk351O5QQbNJS55Za h+XfiAl1j45yrxP+ve3xU64Cl/GctZMLgkx8Qd3JECZCUkm72cvlBF1bJ0hkvcJR
