On 8/27/26 13:05, Jakub Szczudlo (Nokia) via lists.openembedded.org wrote:
Hi,
some words also from me:
There is no deleting of functions in expat version from 2.6.4 to 2.8.3
Backwards compatibility should be intact.
There is a deprecation of one of hash function XML_SetHashSalt but it is
still possible to be used
The biggest change that could potentially break some unsafe code is the
fix for CVE-2026-50219 it makes parser rejecting free/reset/re-entry
when it is already in used, so it is defending against possible memory
corruption. As it is a fix for security vulnerability I think we can
take that risk.
I have also tested it using ptest from packages that use expat it in
runtime like python-xml or libxml-parser-perl and all tests passed.
Best regards,
Jakub Szczudlo
Hi Jakub,
Thanks for this, since you already did some analysis for scartgap, is it
possible for you to work on the scarthgap branch, and I can work on
wrynose (So, we don't accidentally push the same patch)?
Thanks!
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#244478):
https://lists.openembedded.org/g/openembedded-core/message/244478
Mute This Topic: https://lists.openembedded.org/mt/120905189/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-