-
-
Notifications
You must be signed in to change notification settings - Fork 30.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade bundled expat to 2.5.0 #98739
Labels
3.7 (EOL)
end of life
3.8 (EOL)
end of life
3.9
only security fixes
release-blocker
type-bug
An unexpected behavior, bug, or error
type-security
A security issue
Comments
27 tasks
This was referenced Oct 27, 2022
gpshead
pushed a commit
that referenced
this issue
Oct 27, 2022
* Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680. Co-authored-by: Shaun Walbridge <[email protected]>
miss-islington
pushed a commit
to miss-islington/cpython
that referenced
this issue
Oct 27, 2022
* Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680. Co-authored-by: Shaun Walbridge <[email protected]> (cherry picked from commit 3e07f82) Co-authored-by: Shaun Walbridge <[email protected]>
miss-islington
pushed a commit
to miss-islington/cpython
that referenced
this issue
Oct 27, 2022
* Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680. Co-authored-by: Shaun Walbridge <[email protected]> (cherry picked from commit 3e07f82) Co-authored-by: Shaun Walbridge <[email protected]>
miss-islington
pushed a commit
to miss-islington/cpython
that referenced
this issue
Oct 27, 2022
* Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680. Co-authored-by: Shaun Walbridge <[email protected]> (cherry picked from commit 3e07f82) Co-authored-by: Shaun Walbridge <[email protected]>
This was referenced Oct 27, 2022
miss-islington
pushed a commit
to miss-islington/cpython
that referenced
this issue
Oct 27, 2022
* Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680. Co-authored-by: Shaun Walbridge <[email protected]> (cherry picked from commit 3e07f82) Co-authored-by: Shaun Walbridge <[email protected]>
miss-islington
pushed a commit
to miss-islington/cpython
that referenced
this issue
Oct 27, 2022
* Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680. Co-authored-by: Shaun Walbridge <[email protected]> (cherry picked from commit 3e07f82) Co-authored-by: Shaun Walbridge <[email protected]>
Thanks for making the PR! Release branch merges will happen but are pending figuring out why the CLA bot is mistakenly not accepting those on our end. |
miss-islington
added a commit
that referenced
this issue
Oct 27, 2022
* Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680. Co-authored-by: Shaun Walbridge <[email protected]> (cherry picked from commit 3e07f82) Co-authored-by: Shaun Walbridge <[email protected]>
miss-islington
added a commit
that referenced
this issue
Oct 27, 2022
* Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680. Co-authored-by: Shaun Walbridge <[email protected]> (cherry picked from commit 3e07f82) Co-authored-by: Shaun Walbridge <[email protected]>
gpshead
added
3.9
only security fixes
3.8 (EOL)
end of life
3.7 (EOL)
end of life
labels
Oct 27, 2022
ambv
pushed a commit
that referenced
this issue
Oct 28, 2022
Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680. Co-authored-by: Shaun Walbridge <[email protected]> (cherry picked from commit 3e07f82)
ambv
pushed a commit
that referenced
this issue
Oct 28, 2022
Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680. Co-authored-by: Shaun Walbridge <[email protected]> (cherry picked from commit 3e07f82)
ambv
pushed a commit
that referenced
this issue
Oct 28, 2022
Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680. Co-authored-by: Shaun Walbridge <[email protected]> (cherry picked from commit 3e07f82)
gvanrossum
pushed a commit
to gvanrossum/cpython
that referenced
this issue
Oct 28, 2022
* Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680. Co-authored-by: Shaun Walbridge <[email protected]>
I believe all the backports have been merged and thus we can close this issue. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
3.7 (EOL)
end of life
3.8 (EOL)
end of life
3.9
only security fixes
release-blocker
type-bug
An unexpected behavior, bug, or error
type-security
A security issue
Upgrade the bundled libexpat version to 2.5.0 which includes a fix for CVE-2022-43680. I haven't evaluated whether CPython is directly impacted by this CVE, but can confirm that it is detected by binary analysis tools such as Black Duck.
Related libexpat changelog includes additional fixes and details.
The text was updated successfully, but these errors were encountered: