Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package expat for openSUSE:Factory checked 
in at 2026-08-24 12:01:29
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/expat (Old)
 and      /work/SRC/openSUSE:Factory/.expat.new.1258 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "expat"

Mon Aug 24 12:01:29 2026 rev:87 rq:1372946 version:2.8.2

Changes:
--------
--- /work/SRC/openSUSE:Factory/expat/expat.changes      2026-05-16 
19:23:41.111974655 +0200
+++ /work/SRC/openSUSE:Factory/.expat.new.1258/expat.changes    2026-08-24 
12:01:59.642441925 +0200
@@ -1,0 +2,39 @@
+Fri Aug 21 21:02:51 UTC 2026 - Dirk Müller <[email protected]>
+
+- update to 2.8.2 (
+      bsc#1267631, CVE-2026-50219,
+      bsc#1268572, CVE-2026-56131,
+      bsc#1268573, CVE-2026-56132,
+      bsc#1275096, CVE-2026-56403, CVE-2026-56404, CVE-2026-56405,
+      CVE-2026-56406, CVE-2026-56407, CVE-2026-56408,
+      CVE-2026-56409, CVE-2026-56410, CVE-2026-56411,
+      CVE-2026-56412):
+  * #1246  CVE-2026-50219 -- Disallow calls to functions
+  * `XML_GetBuffer`, `XML_Parse`, `XML_ParseBuffer`,
+  * `XML_ParserFree`, `XML_ParserReset` to guard e.g.
+  * Expat bindings from memory corruption;
+  * #1267  CVE-2026-56131 -- Protect XML_ResumeParser from being
+    called from a handler, plugging a hole in the fix to CVE-2026-50219
+  * #1272  CVE-2026-56132 -- Fix out-of-bound scaffolding index
+    store in `doProlog`
+  * #1229 #1232  CVE-2026-56403 -- Integer overflow in
+    `storeAtts`
+  * #1249  CVE-2026-56404 -- Integer overflow in `addBinding`
+  * #1251  CVE-2026-56405 -- Integer overflow in `getAttributeId`
+  * #1255  CVE-2026-56406 -- Integer overflow in
+    `XML_ParseBuffer`
+  * #1262  CVE-2026-56407 -- Integer overflow in `textLen`
+    handling
+  * #565  CVE-2026-56408 -- Integer overflow in `copyString`
+  * #1259  CVE-2026-56409 -- xmlwf: Integer overflow in output
+    path join
+  * #1252  CVE-2026-56410 -- xmlwf: Integer overflow in
+    `resolveSystemId`
+  * #1263  CVE-2026-56411 -- xmlwf: Integer overflow in notation
+    list allocation
+  * #1278  CVE-2026-56412 -- Guard XML_TOK_DATA_CHARS handler
+    calls in `doCdataSection`, plugging a hole in the fix to
+    CVE-2026-50219
+
+
+-------------------------------------------------------------------

Old:
----
  expat-2.8.1.tar.xz
  expat-2.8.1.tar.xz.asc

New:
----
  expat-2.8.2.tar.xz
  expat-2.8.2.tar.xz.asc

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ expat.spec ++++++
--- /var/tmp/diff_new_pack.wBbalX/_old  2026-08-24 12:02:01.137494670 +0200
+++ /var/tmp/diff_new_pack.wBbalX/_new  2026-08-24 12:02:01.139494740 +0200
@@ -17,10 +17,10 @@
 #
 
 
-%global unversion 2_8_1
+%global unversion 2_8_2
 %define sover 1
 Name:           expat
-Version:        2.8.1
+Version:        2.8.2
 Release:        0
 Summary:        XML Parser Toolkit
 License:        MIT

++++++ expat-2.8.1.tar.xz -> expat-2.8.2.tar.xz ++++++
++++ 4633 lines of diff (skipped)

++++++ expat.keyring ++++++
--- /var/tmp/diff_new_pack.wBbalX/_old  2026-08-24 12:02:01.606511217 +0200
+++ /var/tmp/diff_new_pack.wBbalX/_new  2026-08-24 12:02:01.621511746 +0200
@@ -1,6 +1,6 @@
 -----BEGIN PGP PUBLIC KEY BLOCK-----
-Version: Hockeypuck 2.2
 Comment: Hostname: 
+Version: Hockeypuck 2.2
 
 xsFNBFzUcE0BEACzkr4qR9zoM63YCJU/oQTJEtt7SR9Hcvntk351O5QQbNJS55Za
 h+XfiAl1j45yrxP+ve3xU64Cl/GctZMLgkx8Qd3JECZCUkm72cvlBF1bJ0hkvcJR

Reply via email to