On Wed, 2026-08-26 at 01:14 -0700, Jakub Szczudlo (Nokia) wrote:
> Hi,
> 
> I understand this CVE is bigger than I thought CVE patch can be.
> Maybe we can think about updating expat beyond the fixed version?
> I now it's not the best because it is stable branch but I can't think about 
> correct solution.

Hi,

Upgrading expat on wrynose & scarthgap may be possible. We are carrying
a *lot* of patches for expat, especially on scarthgap, so it's worth
considering.

It would need a few things:

- Review of the delta between the current version on these branches,
  including the patches we're carrying, and the latest version. Check
  that there are no features removed or other backwards-incompatible
  changes.

- Confirmation that the SONAME changes won't break anything.

- Testing.

- RFC patch on the mailing list with a clear subject so people can see
  it's an exception to the usual stable upgrade policy, explain the
  review and testing done. This gives chance for people to object if it
  will cause issues for them.

- Agreement from the Yocto TSC, based on the above info.

That all needs some time investment beyond what we currently have
available, so if you have the bandwidth to look in to it then that would
be welcome.

Best regards,

-- 
Paul Barker

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#244391): 
https://lists.openembedded.org/g/openembedded-core/message/244391
Mute This Topic: https://lists.openembedded.org/mt/120905189/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to