Bugzilla Automation <[email protected]> has asked freebsd-desktop (Team)
<[email protected]> for maintainer-feedback:
Bug 296191: textproc/expat2: vulnerable to e.g. CVE-2026-56408
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296191



--- Description ---
See https://github.com/libexpat/libexpat/issues/1276 for brief CVE list
(Release Expat 2.8.2 (no ETA)

Upstream still works on patching CVEs, e.g. this one was committed just an hour
ago:
https://github.com/libexpat/libexpat/commit/11cd58eb92dd8eb

One could either attempt backporting CVE fixes from master or wait for 2.8.2
release.

Reply via email to