Opened 56 minutes ago
#6027 new enhancement
expat-2.8.5
| Reported by: | Joe Locash | Owned by: | lfs-book |
|---|---|---|---|
| Priority: | high | Milestone: | 13.2 |
| Component: | Book | Version: | git |
| Severity: | normal | Keywords: | |
| Cc: |
Description
Release 2.8.5 Tue September 22 2026
Security fixes:
#1282 CVE-2026-93990 -- Reject high surrogates not followed by a
low surrogate during UTF-16 decoding; previously, malformed
UTF-16 could be smuggled into the application using Expat
and could cause arbitrary damage there, depending on how
malformed UTF-16 was handled inside the application;
validation was not their job but Expat's. This is similar
to past vulnerability CVE-2022-25235.
Upstream CVSS 3.1 vector:
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (CVSS score: 9.8)
///////////////////////////////////////////////////////////////////////////////
// The next release will drop two (disabled-by-default) features: //
// //
// - ATTR_INFO (-DXML_ATTR_INFO, -DEXPAT_ATTR_INFO, --enable-xml-attr-info, //
// function XML_GetAttributeInfo, struct XML_AttrInfo) //
// - MIN_SIZE (-DXML_MIN_SIZE, -DEXPAT_MIN_SIZE) //
// //
// If you need them in 2026 and beyond, please share your scenario at //
// GitHub issues #1370 (for ATTR_INFO) and/or #1379 (for MIN_SIZE). Thanks! //
///////////////////////////////////////////////////////////////////////////////
Bug fixes:
#1346 lib: Fix OOM-related memory leak on a failed overflow check
#1371 lib: Fix memory alignment for architectures with 128bit
pointers like CHERI-RISC-V
#1367 xmlwf: Handle errors when closing output files
Other changes:
#1354 lib: Reject an XML declaration version other than `1.[0-9]+`
(which is less strict than XML 1.0r4 (fourth edition)
and matches XML 1.0r5 (fifth edition))
#1362 lib: Make Clang, GCC and MSVC warn about use of function
XML_SetHashSalt that is deprecated since Expat 2.8.0
#1357 lib: Drop internal macros FASTCALL, PTRCALL, PTRFASTCALL
#1367 xmlwf: Document that with `-k` the last error determines the
xmlwf exit code in `--help` output
#1367 xmlwf: Make exit code 3 documentation match exit code 2 more
closely in `--help` output
#1352 #1353 CMake|Windows: Refrain from adding `/source-charset:utf-8`
for MSVC
#1366 #1374 Autotools: Be explicit about the minimum required version of
GNU Automake, currently version 1.13 of 2012-12-28
#1351 Autotools|macOS: Sync CMake templates with CMake 4.4.3
#1349 Replace some internal use of XML_Bool with standard bool
#1364 tests: Propagate xmltest.sh failures via exit status
#1360 tests|xmlwf: Add `#include "expat_config.h"` where missing
#1355 tests: Start covering hash table operation
#1350 #1369 tests: Drop __cplusplus leftovers
#1378 tests: Fix tail pointer when unlinking the last tracked
allocation
#1376 docs: Emphasize that XML_StopParser is not immediate
#1381 docs: Sync XML_FeatureEnum value list in doc/reference.html
#1356 #1361 Version info bumped from 13:4:12 (libexpat*.so.1.12.4)
to 13:5:12 (libexpat*.so.1.12.5); see https://verbump.de/
for what these numbers do
Infrastructure:
#1347 Add missing .gitignore entries
#1360 CI: Detect missing `#include "expat_config.h"`
#1368 CI: Bump MinGW Clang from 23.0.1 to 23.1.1
#1377 CI: Bump Fil-C from 0.684 to 0.685
#1380 CI: Bump Cppcheck from 2.21.0 to 2.22.0
#1372 CI: Extract helper script `apply-htmltidy.sh`
#1366 #1374 Autotools: Start to also produce .tar.bz3 release tarballs
Note:
See TracTickets
for help on using tickets.
