#6027 new enhancement

expat-2.8.5

Reported by: Joe Locash Owned by: lfs-book
Priority: high Milestone: 13.2
Component: Book Version: git
Severity: normal Keywords:
Cc:

Description

Release 2.8.5 Tue September 22 2026
        Security fixes:
           #1282  CVE-2026-93990 -- Reject high surrogates not followed by a
                    low surrogate during UTF-16 decoding; previously, malformed
                    UTF-16 could be smuggled into the application using Expat
                    and could cause arbitrary damage there, depending on how
                    malformed UTF-16 was handled inside the application;
                    validation was not their job but Expat's. This is similar
                    to past vulnerability CVE-2022-25235.
                    Upstream CVSS 3.1 vector:
                    AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (CVSS score: 9.8)

///////////////////////////////////////////////////////////////////////////////
// The next release will drop two (disabled-by-default) features:            //
//                                                                           //
// - ATTR_INFO (-DXML_ATTR_INFO, -DEXPAT_ATTR_INFO, --enable-xml-attr-info,  //
//              function XML_GetAttributeInfo, struct XML_AttrInfo)          //
// - MIN_SIZE (-DXML_MIN_SIZE, -DEXPAT_MIN_SIZE)                             //
//                                                                           //
// If you need them in 2026 and beyond, please share your scenario at        //
// GitHub issues #1370 (for ATTR_INFO) and/or #1379 (for MIN_SIZE). Thanks!  //
///////////////////////////////////////////////////////////////////////////////

        Bug fixes:
           #1346  lib: Fix OOM-related memory leak on a failed overflow check
           #1371  lib: Fix memory alignment for architectures with 128bit
                    pointers like CHERI-RISC-V
           #1367  xmlwf: Handle errors when closing output files

        Other changes:
           #1354  lib: Reject an XML declaration version other than `1.[0-9]+`
                    (which is less strict than XML 1.0r4 (fourth edition)
                    and matches XML 1.0r5 (fifth edition))
           #1362  lib: Make Clang, GCC and MSVC warn about use of function
                    XML_SetHashSalt that is deprecated since Expat 2.8.0
           #1357  lib: Drop internal macros FASTCALL, PTRCALL, PTRFASTCALL
           #1367  xmlwf: Document that with `-k` the last error determines the
                    xmlwf exit code in `--help` output
           #1367  xmlwf: Make exit code 3 documentation match exit code 2 more
                    closely in `--help` output
     #1352 #1353  CMake|Windows: Refrain from adding `/source-charset:utf-8`
                    for MSVC
     #1366 #1374  Autotools: Be explicit about the minimum required version of
                    GNU Automake, currently version 1.13 of 2012-12-28
           #1351  Autotools|macOS: Sync CMake templates with CMake 4.4.3
           #1349  Replace some internal use of XML_Bool with standard bool
           #1364  tests: Propagate xmltest.sh failures via exit status
           #1360  tests|xmlwf: Add `#include "expat_config.h"` where missing
           #1355  tests: Start covering hash table operation
     #1350 #1369  tests: Drop __cplusplus leftovers
           #1378  tests: Fix tail pointer when unlinking the last tracked
                    allocation
           #1376  docs: Emphasize that XML_StopParser is not immediate
           #1381  docs: Sync XML_FeatureEnum value list in doc/reference.html
     #1356 #1361  Version info bumped from 13:4:12 (libexpat*.so.1.12.4)
                    to 13:5:12 (libexpat*.so.1.12.5); see https://verbump.de/
                    for what these numbers do

        Infrastructure:
           #1347  Add missing .gitignore entries
           #1360  CI: Detect missing `#include "expat_config.h"`
           #1368  CI: Bump MinGW Clang from 23.0.1 to 23.1.1
           #1377  CI: Bump Fil-C from 0.684 to 0.685
           #1380  CI: Bump Cppcheck from 2.21.0 to 2.22.0
           #1372  CI: Extract helper script `apply-htmltidy.sh`
     #1366 #1374  Autotools: Start to also produce .tar.bz3 release tarballs

Change History (0)

Note: See TracTickets for help on using tickets.