Hello,

this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe(s) *expat* to *2.8.4* has 
Succeeded.

Next steps:
    - apply the patch: git am 0001-expat-upgrade-2.8.3-2.8.4.patch
    - check the changes to upstream patches and summarize them in the commit 
message,
    - compile an image that contains the package
    - perform some basic sanity tests
    - amend the patch and sign it off: git commit -s --reset-author --amend
    - send it to the appropriate mailing list

Alternatively, if you believe the recipe should not be upgraded at this time,
you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that
automatic upgrades would no longer be attempted.

Please review the attached files for further information and build/update 
failures.
Any problem please file a bug at 
https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler

Regards,
The Upgrade Helper

-- >8 --
From 201c6767d9a44110ec72deae5bef0a31e14d1430 Mon Sep 17 00:00:00 2001
From: Upgrade Helper <[email protected]>
Date: Tue, 1 Sep 2026 05:26:17 +0000
Subject: [PATCH] expat: upgrade 2.8.3 -> 2.8.4
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

Source: Changes

Release 2.8.4 Mon August 31 2026
        Security fixes:
     #1321 #1331  CVE-2026-66046, CVE-2026-76641 -- Fix quadratic runtime from
                    "attribute isCdata lookups" that allowed denial of service
                    attacks through moderately sized crafted XML input
                    (CWE-407).
                    The vulnerability is closely related to past CVE-2026-45186
                    that was fixed with Expat 2.8.1.
                    Please note that a layer of compression around XML can
                    significantly reduce the minimum attack payload size.
                    Upstream CVSS 3.1 vector:
                    AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (CVSS score: 7.5)
                    (Note the "AV:N" for network/remote.)
           #1322  CVE-2026-76957 -- Protect custom encoding callbacks from
                    parser re-entry. The vulnerability is closely related to
                    past issues CVE-2026-50219, CVE-2026-56131 and
                    CVE-2026-56412 that were all fixed with Expat 2.8.2.
           #1326  CVE-2026-76956 -- Fix inverted getentropy() return handling
                    Allows for hash flooding denial of services in
                    configurations where getentropy is configured or detected
                    as the only high quality entropy extractor.
                    Upstream CVSS 3.1 vector:
                    AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H (CVSS score: 5.9)
                    (Note the "AV:N" for network/remote.)

        Other changes:
     #1332 #1333  CMake: Only add `/source-charset:utf-8` when `/utf-8` is not
                    present
           #1315  lib: Resolve (currently unreachable) undefined behavior from
                    overshifting a signed int to the left
     #1325 #1334  lib: Support read-only hash table lookup with keys that are
                    not zero-terminated
           #1340  lib: Use a C99 bool for `ENTITY.open`
           #1319  Fix typo in comment
           #1320  Sync file headers
     #1328 #1329  Version info bumped from 13:3:12 (libexpat*.so.1.12.3)
                    to 13:4:12 (libexpat*.so.1.12.4); see https://verbump.de/
                    for what these numbers do

        Infrastructure:
     #1317 #1335  CI: Cover compilation and execution with Fil-C
           #1337  CI: Cover compilation and execution on riscv64
           #1338  CI: Cover compilation and execution with Clang-based MinGW
           #1339  CI: Cover compilation and execution on (big-endian) s390x
           #1316  CI: Run test suite with musl, also
           #1336  CI: Bump WASI SDK from 33 to 34
           #1345  CI: Bump Clang from 22 to 23

        Special thanks to:
            Alberto Maschietto
            Alexander Bluhm
            Berkay Eren Ürün
            Darren Carreras
            Fabian Wahle (Hap Security)
            Matteo Forzan
            Matthew Fernandez
            Sorrashut Kaewtaworn

[Changelog truncated as it exceeds 3000 characters;
the full changelog can be found in an attachment to the AUH email]
---
 meta/recipes-core/expat/{expat_2.8.3.bb => expat_2.8.4.bb} | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
 rename meta/recipes-core/expat/{expat_2.8.3.bb => expat_2.8.4.bb} (92%)

diff --git a/meta/recipes-core/expat/expat_2.8.3.bb 
b/meta/recipes-core/expat/expat_2.8.4.bb
similarity index 92%
rename from meta/recipes-core/expat/expat_2.8.3.bb
rename to meta/recipes-core/expat/expat_2.8.4.bb
index 79e8c15227..050f148b07 100644
--- a/meta/recipes-core/expat/expat_2.8.3.bb
+++ b/meta/recipes-core/expat/expat_2.8.4.bb
@@ -15,7 +15,7 @@ SRC_URI = 
"${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2  \
 GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/";
 UPSTREAM_CHECK_REGEX = "releases/tag/R_(?P<pver>.+)"
 
-SRC_URI[sha256sum] = 
"b4cc2483927d5e90bf8c40b44a6b95b368b42a8a96e25883fce188b48a92b670"
+SRC_URI[sha256sum] = 
"963250a823c16a498582b4ad82ad0f88926be0769675d3b6956be4d769a1cd8f"
 
 EXTRA_OECMAKE:class-native += "-DEXPAT_BUILD_DOCS=OFF"
 
-- 
2.47.1

packages/x86-64-v3-poky-linux/expat/expat-bin: PV changed from "2.8.3" to 
"2.8.4"
packages/x86-64-v3-poky-linux/expat/expat-bin: PKGV changed from 2.8.3 
[default] to 2.8.4 [default]
packages/x86-64-v3-poky-linux/expat/expat-dbg: FILELIST: removed 
"/usr/lib/.debug/libexpat.so.1.12.3", added "/usr/lib/.debug/libexpat.so.1.12.4"
packages/x86-64-v3-poky-linux/expat/expat-dbg: PV changed from "2.8.3" to 
"2.8.4"
packages/x86-64-v3-poky-linux/expat/expat-dbg: PKGSIZE changed from 1789352 to 
1826736 (+2%)
packages/x86-64-v3-poky-linux/expat/expat-dbg: PKGV changed from 2.8.3 
[default] to 2.8.4 [default]
packages/x86-64-v3-poky-linux/expat/expat-dev: FILELIST: directory renamed 
/usr/lib/cmake/expat-2.8.3 -> /usr/lib/cmake/expat-2.8.4
packages/x86-64-v3-poky-linux/expat/expat-dev: PV changed from "2.8.3" to 
"2.8.4"
packages/x86-64-v3-poky-linux/expat/expat-dev: PKGV changed from 2.8.3 
[default] to 2.8.4 [default]
packages/x86-64-v3-poky-linux/expat/expat-doc: PV changed from "2.8.3" to 
"2.8.4"
packages/x86-64-v3-poky-linux/expat/expat-doc: PKGSIZE changed from 120656 to 
123821 (+3%)
packages/x86-64-v3-poky-linux/expat/expat-doc: PKGV changed from 2.8.3 
[default] to 2.8.4 [default]
packages/x86-64-v3-poky-linux/expat/expat-locale: PV changed from "2.8.3" to 
"2.8.4"
packages/x86-64-v3-poky-linux/expat/expat-locale: PKGV changed from 2.8.3 
[default] to 2.8.4 [default]
packages/x86-64-v3-poky-linux/expat/expat-ptest: PV changed from "2.8.3" to 
"2.8.4"
packages/x86-64-v3-poky-linux/expat/expat-ptest: PKGV changed from 2.8.3 
[default] to 2.8.4 [default]
packages/x86-64-v3-poky-linux/expat/expat-src: FILELIST: directory renamed 
/usr/src/debug/expat/2.8.3/lib -> /usr/src/debug/expat/2.8.4/lib, directory 
renamed /usr/src/debug/expat/2.8.3/tests/benchmark -> 
/usr/src/debug/expat/2.8.4/tests/benchmark, directory renamed 
/usr/src/debug/expat/2.8.3/xmlwf -> /usr/src/debug/expat/2.8.4/xmlwf, directory 
renamed /usr/src/debug/expat/2.8.3/tests -> /usr/src/debug/expat/2.8.4/tests
packages/x86-64-v3-poky-linux/expat/expat-src: PV changed from "2.8.3" to 
"2.8.4"
packages/x86-64-v3-poky-linux/expat/expat-src: PKGSIZE changed from 1359558 to 
1370126 (+1%)
packages/x86-64-v3-poky-linux/expat/expat-src: PKGV changed from 2.8.3 
[default] to 2.8.4 [default]
packages/x86-64-v3-poky-linux/expat/expat-staticdev: PV changed from "2.8.3" to 
"2.8.4"
packages/x86-64-v3-poky-linux/expat/expat-staticdev: PKGV changed from 2.8.3 
[default] to 2.8.4 [default]
packages/x86-64-v3-poky-linux/expat/expat: FILELIST: removed 
"/usr/lib/libexpat.so.1.12.3", added "/usr/lib/libexpat.so.1.12.4"
packages/x86-64-v3-poky-linux/expat/expat: PV changed from "2.8.3" to "2.8.4"
packages/x86-64-v3-poky-linux/expat/expat: PKGV changed from 2.8.3 [default] to 
2.8.4 [default]
packages/x86-64-v3-poky-linux/expat: SRC_URI changed from 
"https://github.com/libexpat/libexpat/releases//download/R_2_8_3/expat-2.8.3.tar.bz2
 file://run-ptest" to 
"https://github.com/libexpat/libexpat/releases//download/R_2_8_4/expat-2.8.4.tar.bz2
 file://run-ptest"
packages/x86-64-v3-poky-linux/expat: PV changed from "2.8.3" to "2.8.4"
packages/x86-64-v3-poky-linux/expat: PKGV changed from 2.8.3 [default] to 2.8.4 
[default]
Changes to packages/x86-64-v3-poky-linux/expat (sysroot):
  /usr/lib/libexpat.so.1 changed symlink target from libexpat.so.1.12.3 to 
libexpat.so.1.12.4
  /usr/lib/cmake/expat-2.8.3 moved to /usr/lib/cmake/expat-2.8.4
  /usr/lib/libexpat.so.1.12.3 moved to /usr/lib/libexpat.so.1.12.4
Changes to packages/x86_64-linux/expat-native (sysroot):
  /usr/lib/libexpat.so.1 changed symlink target from libexpat.so.1.12.3 to 
libexpat.so.1.12.4
  /usr/lib/cmake/expat-2.8.3 moved to /usr/lib/cmake/expat-2.8.4
  /usr/lib/libexpat.so.1.12.3 moved to /usr/lib/libexpat.so.1.12.4
Changelog for expat: 2.8.3 -> 2.8.4
Source: Changes

Release 2.8.4 Mon August 31 2026
        Security fixes:
     #1321 #1331  CVE-2026-66046, CVE-2026-76641 -- Fix quadratic runtime from
                    "attribute isCdata lookups" that allowed denial of service
                    attacks through moderately sized crafted XML input
                    (CWE-407).
                    The vulnerability is closely related to past CVE-2026-45186
                    that was fixed with Expat 2.8.1.
                    Please note that a layer of compression around XML can
                    significantly reduce the minimum attack payload size.
                    Upstream CVSS 3.1 vector:
                    AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (CVSS score: 7.5)
                    (Note the "AV:N" for network/remote.)
           #1322  CVE-2026-76957 -- Protect custom encoding callbacks from
                    parser re-entry. The vulnerability is closely related to
                    past issues CVE-2026-50219, CVE-2026-56131 and
                    CVE-2026-56412 that were all fixed with Expat 2.8.2.
           #1326  CVE-2026-76956 -- Fix inverted getentropy() return handling
                    Allows for hash flooding denial of services in
                    configurations where getentropy is configured or detected
                    as the only high quality entropy extractor.
                    Upstream CVSS 3.1 vector:
                    AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H (CVSS score: 5.9)
                    (Note the "AV:N" for network/remote.)

        Other changes:
     #1332 #1333  CMake: Only add `/source-charset:utf-8` when `/utf-8` is not
                    present
           #1315  lib: Resolve (currently unreachable) undefined behavior from
                    overshifting a signed int to the left
     #1325 #1334  lib: Support read-only hash table lookup with keys that are
                    not zero-terminated
           #1340  lib: Use a C99 bool for `ENTITY.open`
           #1319  Fix typo in comment
           #1320  Sync file headers
     #1328 #1329  Version info bumped from 13:3:12 (libexpat*.so.1.12.3)
                    to 13:4:12 (libexpat*.so.1.12.4); see https://verbump.de/
                    for what these numbers do

        Infrastructure:
     #1317 #1335  CI: Cover compilation and execution with Fil-C
           #1337  CI: Cover compilation and execution on riscv64
           #1338  CI: Cover compilation and execution with Clang-based MinGW
           #1339  CI: Cover compilation and execution on (big-endian) s390x
           #1316  CI: Run test suite with musl, also
           #1336  CI: Bump WASI SDK from 33 to 34
           #1345  CI: Bump Clang from 22 to 23

        Special thanks to:
            Alberto Maschietto
            Alexander Bluhm
            Berkay Eren Ürün
            Darren Carreras
            Fabian Wahle (Hap Security)
            Matteo Forzan
            Matthew Fernandez
            Sorrashut Kaewtaworn
            Wade Sparks III
            Zeyou Liu
                 and
            City of Munich Open Source Sabbatical
            Moonshot AI
            VulnCheck
            Z.ai
packages/x86-64-v3-poky-linux/expat/expat-dev: FILELIST: directory renamed 
/usr/lib/cmake/expat-2.8.3 -> /usr/lib/cmake/expat-2.8.4
packages/x86-64-v3-poky-linux/expat/expat: FILELIST: removed 
"/usr/lib/libexpat.so.1.12.3", added "/usr/lib/libexpat.so.1.12.4"
Changes to packages/x86-64-v3-poky-linux/expat (sysroot):
  /usr/lib/libexpat.so.1 changed symlink target from libexpat.so.1.12.3 to 
libexpat.so.1.12.4
  /usr/lib/cmake/expat-2.8.3 moved to /usr/lib/cmake/expat-2.8.4
  /usr/lib/libexpat.so.1.12.3 moved to /usr/lib/libexpat.so.1.12.4
Changes to packages/x86_64-linux/expat-native (sysroot):
  /usr/lib/libexpat.so.1 changed symlink target from libexpat.so.1.12.3 to 
libexpat.so.1.12.4
  /usr/lib/cmake/expat-2.8.3 moved to /usr/lib/cmake/expat-2.8.4
  /usr/lib/libexpat.so.1.12.3 moved to /usr/lib/libexpat.so.1.12.4

Attachment: 0001-expat-upgrade-2.8.3-2.8.4.patch
Description: Binary data

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#244786): 
https://lists.openembedded.org/g/openembedded-core/message/244786
Mute This Topic: https://lists.openembedded.org/mt/121027525/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to