On 8/27/26 13:05, Jakub Szczudlo (Nokia) via lists.openembedded.org wrote:
Hi,

some words also from me:
There is no deleting of functions in expat version from 2.6.4 to 2.8.3
Backwards compatibility should be intact.
There is a deprecation of one of hash function XML_SetHashSalt but it is still possible to be used The biggest change that could potentially break some unsafe code is the fix for CVE-2026-50219 it makes parser rejecting free/reset/re-entry when it is already in used, so it is defending against possible memory corruption. As it is a fix for security vulnerability I think we can take that risk.

I have also tested it using ptest from packages that use expat it in runtime like python-xml or libxml-parser-perl and all tests passed.

Best regards,
Jakub Szczudlo




Hi Jakub,
Thanks for this, since you already did some analysis for scartgap, is it possible for you to work on the scarthgap branch, and I can work on wrynose (So, we don't accidentally push the same patch)?

Thanks!
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#244478): 
https://lists.openembedded.org/g/openembedded-core/message/244478
Mute This Topic: https://lists.openembedded.org/mt/120905189/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to