Skip to content

Upgrade bundled expat to 2.5.0 #98739

Description

@scdub

Upgrade the bundled libexpat version to 2.5.0 which includes a fix for CVE-2022-43680. I haven't evaluated whether CPython is directly impacted by this CVE, but can confirm that it is detected by binary analysis tools such as Black Duck.

Related libexpat changelog includes additional fixes and details.

Activity

  1. added
    type-bugAn unexpected behavior, bug, or error
    on Oct 26, 2022
  2. added a commit that references this issue on Oct 27, 2022
  3. added 5 commits that reference this issue on Oct 27, 2022
  4. self-assigned this
    on Oct 27, 2022
  5. gpshead commented on Oct 27, 2022

    @gpshead
    Member

    Thanks for making the PR! Release branch merges will happen but are pending figuring out why the CLA bot is mistakenly not accepting those on our end.

  6. moved this from Todo to In Progress in Release and Deferred blockers 🚫on Oct 27, 2022
  7. added 2 commits that reference this issue on Oct 27, 2022
  8. assigned and unassigned on Oct 27, 2022
  9. added 3 commits that reference this issue on Oct 28, 2022
  10. added a commit that references this issue on Oct 28, 2022
  11. ned-deily commented on Dec 5, 2022

    @ned-deily
    Member

    I believe all the backports have been merged and thus we can close this issue.

  12. Repository owner moved this from In Progress to Done in Release and Deferred blockers 🚫on Dec 5, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions