Openembedded Core Discussions
 help / color / mirror / Atom feed
From: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech>
To: "paul@pbarker.dev" <paul@pbarker.dev>
Cc: "openembedded-core@lists.openembedded.org"
	<openembedded-core@lists.openembedded.org>,
	"yoann.congal@smile.fr" <yoann.congal@smile.fr>,
	jakub.szczudlo@nokia.com,
	Daniel Turull <daniel.turull@ericsson.com>,
	"david.partain@est.tech" <david.partain@est.tech>
Subject: Re: [OE-core] [wrynose][PATCH 1/3] expat: fix CVE-2026-50219
Date: Thu, 27 Aug 2026 12:54:16 +0200	[thread overview]
Message-ID: <b8b848b9-81ec-4a9e-bb4c-d1e196eeb479@est.tech> (raw)
In-Reply-To: <a801b816ecbff66fc39732801eec691af21ce3ac.camel@pbarker.dev>

On 8/27/26 09:27, Daniel Turull wrote:
> On Wed, 2026-08-26 at 01:14 -0700, Jakub Szczudlo (Nokia) wrote:
>> Hi,
>>
>> I understand this CVE is bigger than I thought CVE patch can be.
>> Maybe we can think about updating expat beyond the fixed version?
>> I now it's not the best because it is stable branch but I can't think about correct solution.
> 
> Hi,
> 
> Upgrading expat on wrynose & scarthgap may be possible. We are carrying
> a *lot* of patches for expat, especially on scarthgap, so it's worth
> considering.
> 
> It would need a few things:
> 
> - Review of the delta between the current version on these branches,
>    including the patches we're carrying, and the latest version. Check
>    that there are no features removed or other backwards-incompatible
>    changes.
> 
> - Confirmation that the SONAME changes won't break anything.
> 
> - Testing.
> 
> - RFC patch on the mailing list with a clear subject so people can see
>    it's an exception to the usual stable upgrade policy, explain the
>    review and testing done. This gives chance for people to object if it
>    will cause issues for them.
> 
> - Agreement from the Yocto TSC, based on the above info.
> 
> That all needs some time investment beyond what we currently have
> available, so if you have the bandwidth to look in to it then that would
> be welcome.
> 
> Best regards,
> 

Hi all,
I agree that expat should be uplifted to 2.8.3.

I have some comments/suggestions regarding this.
To verify ABI compatibility, I ran abidiff 
(https://sourceware.org/libabigail/manual/abidiff.html) for expat 2.7.5 
and 2.8.3, and can conclude that there is no ABI break, and can also 
confirm that there has not been a major bump in the SONAME.

I want to point to our fork of 
meta-binaryaudit(https://github.com/nordix/meta-binaryaudit), which 
wraps abidw and abidiff into a Yocto layer, which then can be used to 
compare ABI breaks in the packages.

I have also analysed the Changelog as suggested, there has not been any 
feature removal, but there are some opt-in feature additions (disabled 
by default), and new Autotools flags. I don't see any 
backward-incompatible changes.

I will prepare a patch to uplift to expat 2.8.3, test it, and include 
these results, and mark it RFC as mentioned.

Thanks!
Adarsh Jagadish Kamini
Ericsson Software Technology AB


  reply	other threads:[~2026-08-27 10:54 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-24 15:20 [wrynose][PATCH 1/3] expat: fix CVE-2026-50219 Jakub Szczudlo (Nokia)
2026-08-24 15:20 ` [wrynose][PATCH 2/3] expat: fix CVE-2026-56131 Jakub Szczudlo (Nokia)
2026-08-24 15:20 ` [wrynose][PATCH 3/3] expat: fix CVE-2026-56412 Jakub Szczudlo (Nokia)
2026-08-24 17:15 ` [wrynose][PATCH 1/3] expat: fix CVE-2026-50219 Paul Barker
2026-08-26  8:14   ` Jakub Szczudlo (Nokia)
2026-08-26  9:56     ` Paul Barker
2026-08-27 10:54       ` Adarsh Jagadish Kamini [this message]
2026-08-27 11:05         ` Jakub Szczudlo (Nokia)
2026-08-27 11:45           ` [OE-core] " Adarsh Jagadish Kamini
2026-08-27 11:57             ` Jakub Szczudlo (Nokia)

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=b8b848b9-81ec-4a9e-bb4c-d1e196eeb479@est.tech \
    --to=adarsh.jagadish.kamini@est.tech \
    --cc=daniel.turull@ericsson.com \
    --cc=david.partain@est.tech \
    --cc=jakub.szczudlo@nokia.com \
    --cc=openembedded-core@lists.openembedded.org \
    --cc=paul@pbarker.dev \
    --cc=yoann.congal@smile.fr \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox