From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Thu, 19 Mar 2026 18:16:35 +0100 Received: from metis.whiteo.stw.pengutronix.de ([2a0a:edc0:2:b01:1d::104]) by lore.white.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1w3Gz5-002j6K-2i for lore@lore.pengutronix.de; Thu, 19 Mar 2026 18:16:35 +0100 Received: from [127.0.0.1] (helo=metis.whiteo.stw.pengutronix.de) by metis.whiteo.stw.pengutronix.de with esmtp (Exim 4.92) (envelope-from ) id 1w3Gz5-0001YE-Nm; Thu, 19 Mar 2026 18:16:35 +0100 Received: from mail-westeuropeazon11020074.outbound.protection.outlook.com ([52.101.69.74] helo=AM0PR83CU005.outbound.protection.outlook.com) by metis.whiteo.stw.pengutronix.de with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1w3Gyz-0001XX-B5 for ptxdist@pengutronix.de; Thu, 19 Mar 2026 18:16:30 +0100 ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=yvFoeB8RLuRUJEAxDupM6LiYoJGbFf88BvoyAOe2aDE/xnP75OH5H8BQ3lrXqtm3CeY+LO8+bs1HbK7yyxDXnSn32HS5X5U2budV8ifUkSkCecphzg7Qc7hvcybzOqYZKdkfMhCMKRt9JB9mwJk0flhRUO2pQsw0drRYGkI3fbfQqD9nSFNKKmj6sPtj+mYsyFDZ1V8cZmLiz6i/bRLAiQ4nPSEM9OzFjkggejtJKxCGsaONTXmRor+Wmxwj/JaOYQNtAv0aK1FSbqjknL2SQ6RB4z8vqfRaWyhHbE2+CrEpxCTolUugcsKk+PLAAIcoG9v4NgedrYQlgxs2uJBPJg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=j/kNPht0xFMchIVi/hbtJgiN9KFbUvl+egQqqoumEyY=; b=HJ83C2mgDyjuALxyiEMTem0hQNWEOfWQZ7iW5reITDq1Q1+nYN3rrmd7uPtLsloVlxbGkzV398OY9Qj6hxlmIkLneucBbEeo4eBj4mBruv28o6o42vGpOHXX0gnf+JFs7jt6MHJDBOiRsPeZZHNj73+hfUZhK5wFrlYLRH7pJuQWpNkJLs7XzYp3nLiyRor69v1gnuw+X6utQ6KG7AVC8/giG8/QGkpFuMVJJbbfM0P2W8fl38WS6BwzHh634ZQ+dxiP3cqgcrVt5JPMkOGYJL+x+LRRI4fVxEeZo9Qf6/RGULC+OPoq3ORuUpUHNkrXYOAjZUV0L+2O3HMu3DrIFQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=t2data.com; dmarc=pass action=none header.from=t2data.com; dkim=pass header.d=t2data.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=t2datacom.onmicrosoft.com; s=selector1-t2datacom-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=j/kNPht0xFMchIVi/hbtJgiN9KFbUvl+egQqqoumEyY=; b=lnZe7ukU57EDDGUj9H8e827zpIvN8070uaUlfe7PjQCqJnyjoSpolKlo6ZZVP9R9+hAz8VKlHRwYUKg8yut6sWuAL93fMppA7c6GrvIaCYR2cZBnbKmXi5xw+QuAHKShE1hwtHPTZGBPhuEuec7R6LaDHLQhT5DTAnaHwsPwChA= Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=t2data.com; Received: from DB9P251MB0618.EURP251.PROD.OUTLOOK.COM (2603:10a6:10:334::22) by GV1P251MB1026.EURP251.PROD.OUTLOOK.COM (2603:10a6:150:96::18) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9723.19; Thu, 19 Mar 2026 17:16:26 +0000 Received: from DB9P251MB0618.EURP251.PROD.OUTLOOK.COM ([fe80::a4b2:58d7:8549:4b19]) by DB9P251MB0618.EURP251.PROD.OUTLOOK.COM ([fe80::a4b2:58d7:8549:4b19%4]) with mapi id 15.20.9723.018; Thu, 19 Mar 2026 17:16:26 +0000 From: Christian Melki To: ptxdist@pengutronix.de Date: Thu, 19 Mar 2026 18:16:20 +0100 Message-ID: <20260319171620.511377-1-christian.melki@t2data.com> X-Mailer: git-send-email 2.43.0 Content-Transfer-Encoding: 8bit Content-Type: text/plain X-ClientProxiedBy: MM0P280CA0098.SWEP280.PROD.OUTLOOK.COM (2603:10a6:190:9::30) To DB9P251MB0618.EURP251.PROD.OUTLOOK.COM (2603:10a6:10:334::22) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DB9P251MB0618:EE_|GV1P251MB1026:EE_ X-MS-Office365-Filtering-Correlation-Id: 5aa1c0f8-cc54-4136-6993-08de85db40a2 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; ARA:13230040|376014|52116014|1800799024|366016|38350700014|56012099003|18002099003; X-Microsoft-Antispam-Message-Info: t4NecpseYVz5LKutZ0566TVVL7nI5H1qA/LQDL/zQM3F8hwtBKdbSeEyrd17nTunaH8dr8uvaRz/D4KmJJIgkCxF5FRgc10w3IjrLFj22soOgQLyMr+0zy00yt+X3hLZwfmiT98FCTbO8drju40kVcsMl/x7Uyz2tl1FNz0R4wsZVg7I4JW8JQ/Uaup+wpUEYXyW072GJGdJvfGUhoQlnv4RMAus40KyahAlN801PW3c2kFC3TNAYVOt+zIyE349tD3nthtchaWlCbqmRNhBfjxw1EiUWwKTCrDKCoxY4+u2jXZ8I5BVMcax/sYadvVJfHx78pRsfqbNrsiCnEtUdYxLm8We1oQuOdY5SLarc/hXUDDqjZURvg2GCgzGUcrHAJGWds5UyDbRNPWR4zVda5/PfFLGFDMkmB7U1Op6cZXC62jqVIr7GN/2MXgxL954Rcjyc+Tf64/xsL4ZMAHUI3auZVFgsLAndTYpfJA9cAlw562xtm+uLD9uJjvzxfynV8H0fPeLJhgvrrGO020p3FweOtBCOmXhHSip85AzsWl4cI05z3VCqTQb4EVuHMFKuLUXKpMW24aJwIyg9hK3Vtid4LmS49ZXH13N3Ibl5ZAfUgdhGMt7dNdHA97xZDqoqgtS+N8LuGAxa5i8PUx6E2Bsa6iPQ6LkLx8n/88NWtPk8LQSK/QWSurq/UFmRRw+eFc3df7jTLeC1bXg2mX1j1msvps9kwF93mYozfb7OS9r8uEg4LNrgMFRikv/QXfy X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB9P251MB0618.EURP251.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230040)(376014)(52116014)(1800799024)(366016)(38350700014)(56012099003)(18002099003); DIR:OUT; SFP:1102; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?jk3vp40rf5HUTKrnrmNTQJvzMfqtPLdgCLiLHmV6ss1w0mj17V+MgiXV6pjo?= =?us-ascii?Q?W7s+3/su0zHjaYHFUHSY+N1OjXTZj9bYVZ3/RIguybuh05HJdHHQY/CzdjlO?= =?us-ascii?Q?/puXMCPX0rRhHP7k8V+HDy6lcINKbxmxE4IM2fiBlEfVDEibwdLNytY88hxq?= =?us-ascii?Q?GiYGw7eLKPmVwu3tPipUS7emd1H29rwtsYIbBQkSBHTJGHtTsO3J/Wz0vMHF?= =?us-ascii?Q?o9Rw8+Mo0dWRJ9Ngzq2GVGUTOfuRZBcXtP2MrCjljGPr10pp0074ew4lrp8x?= =?us-ascii?Q?/WubWLPtwajFeXDUSg5Bwy1nOOlkChkcW/gp1OYMcSSOpRMq+Z/q+5oxZKvz?= =?us-ascii?Q?Bkvh3rf70k2SFlbU0TRr3ZfNS30YPxfo+N9p8eDaWs4YI7jHJn2d0xFuv9eY?= =?us-ascii?Q?i4xiG0v02qxfArdx7znFPz6IWq1PR01aXCMwVH3vEKw8GH/Qhas8c0GOdZn6?= =?us-ascii?Q?Lb3+Qjf8r461Zkth9uelXQrM+W3yuRueWhmefb7V+UxXZF2r+DN7ZShbeWJY?= =?us-ascii?Q?pGTAoGkKqGsMpp8rgxtwbqEU/ZtWDdDa0L5ykhaqzZSSfpJ/2v8Y52F1HlcZ?= =?us-ascii?Q?UmM63rD+LB64DwuT75oUA42XjDNmIcSCWN8up5x9EubatRg8k96t5Xhsi0oN?= =?us-ascii?Q?fgNC49drhzeP7aCLvDr3BDXWXYgL+DF9artbSFV4qh/PLl75J+CXgkULgvEW?= =?us-ascii?Q?HCNfIBMyjlD+9pYGkUGP22eXSzP+gI4ju25ziS7jZnIS1y8g/88gocmYE5cj?= =?us-ascii?Q?6PSjSPpbY+0nzJwKRxektGtAtTV8gMIqwvxiqEh+ldbW6MuQTPh0LAfrHUtA?= =?us-ascii?Q?9buMbOTLno1E0ekUMykeMdWs5L8J3CxqvwFYUiICjIE7wdejiQzmoOyPho8S?= =?us-ascii?Q?3JuzAk75lT1qNZQIcX9D3S8IkTabRWRV7qwj7lVTSZAzSwp4cT1tlSrFO3jL?= =?us-ascii?Q?gliZ7gd6iQ6ZPBFU4mdMwb6SKE6gWphgpSfVwRh1aU0u181dKXa8xmDpqTY2?= =?us-ascii?Q?njcmywtfk/kOOBtOzZROWHduOVeGdPqIwLXMrsLPmirTaKCO1ZyyaBifCuXu?= =?us-ascii?Q?WBd/N/gzioZ8S9a3kFPgjVwOvLTz9T7HJhRCEN0Dm7ik1OuS848aUkdiMeXa?= =?us-ascii?Q?dWdEy0ErFTdAfmO6wRTk0wLr7i1Q4r0IeYd1ekVfKk7OUZXixW4I5KGwR9Yf?= =?us-ascii?Q?Pj/lEDCJ1XPARp0SRznzHFFXhSddblcrzjSqap5SOC+yI7eMIncYOtnv1cHb?= =?us-ascii?Q?+1hZYqYAci8CzogbA5RViNabqi2+FIOzXdNkcl60E1iH1gaEdTXrMZYt6iYO?= =?us-ascii?Q?tl1MPV2s7Y+cNhCFozbiqRMv7UNaOit4tr2mdkonNZrzUQsicWJeNYkv1iy/?= =?us-ascii?Q?tZwCzddJEQdVbrl9bp0Otj4ABCwzOF+hI1PGgP2S/OynqLoWY4MQ2LBgeFFz?= =?us-ascii?Q?iFVtk3eVJJRt/894NGfK4YzaoK7aQSKuiuZl9TlP08XuaZOT2DXkbCruXBUF?= =?us-ascii?Q?xB39TZjArfDReyAuuByEIVt22nqbbt1SsJ7O3awOHJMeoU+/dnLsqhLjneLw?= =?us-ascii?Q?SWzrGn6eLKyJBpzac94r/Eki5/d/iVj+5eV3+yD+zt9Y7naDQ/HahpW+N1pW?= =?us-ascii?Q?7TI3CzEF67HRb4Ud71xj0k7GMU37+YEKdf+rmCJtNisEDsZWTZfYJs3zcZUJ?= =?us-ascii?Q?32RbC3NqVHz+0+QpGixmVR6Mvl7+Cl95I1RD9vnQvv7hqLB9T73Ns5dma9RS?= =?us-ascii?Q?2ChLFi4D0rUmZxCsVxIZTNEaDUGR3vg=3D?= X-OriginatorOrg: t2data.com X-MS-Exchange-CrossTenant-Network-Message-Id: 5aa1c0f8-cc54-4136-6993-08de85db40a2 X-MS-Exchange-CrossTenant-AuthSource: DB9P251MB0618.EURP251.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 19 Mar 2026 17:16:26.3308 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 27928da5-aacd-4ba1-9566-c748a6863e6c X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: a9utCU2Zkb8gKt4vmP0m+i4JzwpXRzNAxghBAc2y3okIhGQKPtRf7q36jZ/4WXDuhZR1LE6jL+pboFHDLAPI/NsJAIB94MNe48WIhPiD65U= X-MS-Exchange-Transport-CrossTenantHeadersStamped: GV1P251MB1026 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on metis.whiteo.stw.pengutronix.de X-Spam-Level: X-Spam-Status: No, score=-1.2 required=4.0 tests=AWL,BAYES_00,DKIM_SIGNED, DKIM_VALID,PDS_BTC_ID,RCVD_IN_DNSWL_NONE,RCVD_IN_MSPIKE_H2, RCVD_IN_VALIDITY_RPBL_BLOCKED,RCVD_IN_VALIDITY_SAFE_BLOCKED, SPF_HELO_PASS,SPF_PASS autolearn=no autolearn_force=no version=3.4.2 Subject: [ptxdist] [PATCH] expat: Version bump. 2.7.4 -> 2.7.5 X-BeenThere: ptxdist@pengutronix.de X-Mailman-Version: 2.1.29 Precedence: list List-Id: PTXdist Development Mailing List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: ptxdist@pengutronix.de Sender: "ptxdist" X-SA-Exim-Connect-IP: 127.0.0.1 X-SA-Exim-Mail-From: ptxdist-bounces@pengutronix.de X-SA-Exim-Scanned: No (on metis.whiteo.stw.pengutronix.de); SAEximRunCond expanded to false Mostly security fixes. https://github.com/libexpat/libexpat/blob/R_2_7_5/expat/Changes Plugs CVE: CVE-2026-32776: Fix NULL pointer dereference for empty external parameter entities CVE-2026-32777: Protect from XML_TOK_INSTANCE_START infinite loop in function entityValueProcessor CVE-2026-32778: Fix NULL dereference in function setContext Signed-off-by: Christian Melki --- rules/expat.make | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/rules/expat.make b/rules/expat.make index 11278aae8..58c7339aa 100644 --- a/rules/expat.make +++ b/rules/expat.make @@ -16,8 +16,8 @@ PACKAGES-$(PTXCONF_EXPAT) += expat # # Paths and names # -EXPAT_VERSION := 2.7.4 -EXPAT_MD5 := d8c3327b7e10e75582873a0d97e7a538 +EXPAT_VERSION := 2.7.5 +EXPAT_MD5 := 39ccac48bfbb1b39ad19914a63f2588c EXPAT := expat-$(EXPAT_VERSION) EXPAT_SUFFIX := tar.bz2 EXPAT_RELEASE := R_$(subst .,_,$(EXPAT_VERSION)) -- 2.43.0