Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package expat for openSUSE:Factory checked 
in at 2026-09-09 16:18:26
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/expat (Old)
 and      /work/SRC/openSUSE:Factory/.expat.new.1265 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "expat"

Wed Sep  9 16:18:26 2026 rev:88 rq:1376287 version:2.8.4

Changes:
--------
--- /work/SRC/openSUSE:Factory/expat/expat.changes      2026-08-24 
12:01:59.642441925 +0200
+++ /work/SRC/openSUSE:Factory/.expat.new.1265/expat.changes    2026-09-09 
16:18:27.599296620 +0200
@@ -1,0 +2,34 @@
+Fri Sep 04 10:10:50 UTC 2026 - David Anes <[email protected]>
+
+- update to 2.8.4:
+  * Security fixes:
+    * CVE-2026-66046, bsc#1275732: denial of service vulnerability
+      caused by quadratic algorithmic complexity in the storeAtts()
+      function in xmlparse.c
+    * CVE-2026-76641, bsc#1275915: out-of-bounds read vulnerability
+      that allows attackers to trigger memory corruption
+    * CVE-2026-76957, bsc#1275859: lacks handler call depth tracking
+      with custom encoding callbacks, use-after-free can occur
+    * CVE-2026-76956, bsc#1275860: misinterpretation of getentropy's
+      return code leads to insufficient entropy, vulnerable to hash
+      flooding denial of service
+  * Other fixes:
+    * CMake: only add /source-charset:utf-8 when /utf-8 is not present
+    * lib: resolve undefined behavior from overshifting a signed int
+    * lib: support read-only hash table lookup with non-zero-terminated
+      keys
+    * lib: use a C99 bool for ENTITY.open
+    * version info bumped from 13:3:12 to 13:4:12
+- update to 2.8.3:
+  * Security fixes:
+    * CVE-2026-72522, bsc#1275594: out-of-bounds read and resultant
+      infinite loop due to low surrogates being treated the same as
+      high surrogates during Unicode processing
+  * Other fixes:
+    * fix support for 2+ GiB documents (regression from 2.8.2)
+    * reject empty version in the XML declaration
+    * fix printf format for AIX
+    * CMake|AIX: enable EXPAT_DEV_URANDOM by default
+    * version info bumped from 13:2:12 to 13:3:12
+
+-------------------------------------------------------------------

Old:
----
  expat-2.8.2.tar.xz
  expat-2.8.2.tar.xz.asc

New:
----
  expat-2.8.4.tar.xz
  expat-2.8.4.tar.xz.asc

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ expat.spec ++++++
--- /var/tmp/diff_new_pack.i2NeLg/_old  2026-09-09 16:18:28.902350928 +0200
+++ /var/tmp/diff_new_pack.i2NeLg/_new  2026-09-09 16:18:28.904351011 +0200
@@ -17,10 +17,10 @@
 #
 
 
-%global unversion 2_8_2
+%global unversion 2_8_4
 %define sover 1
 Name:           expat
-Version:        2.8.2
+Version:        2.8.4
 Release:        0
 Summary:        XML Parser Toolkit
 License:        MIT

++++++ expat-2.8.2.tar.xz -> expat-2.8.4.tar.xz ++++++
++++ 2890 lines of diff (skipped)

Reply via email to