From: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech>
To: "paul@pbarker.dev" <paul@pbarker.dev>
Cc: "openembedded-core@lists.openembedded.org"
<openembedded-core@lists.openembedded.org>,
"yoann.congal@smile.fr" <yoann.congal@smile.fr>,
jakub.szczudlo@nokia.com,
Daniel Turull <daniel.turull@ericsson.com>,
"david.partain@est.tech" <david.partain@est.tech>
Subject: Re: [OE-core] [wrynose][PATCH 1/3] expat: fix CVE-2026-50219
Date: Thu, 27 Aug 2026 12:54:16 +0200 [thread overview]
Message-ID: <b8b848b9-81ec-4a9e-bb4c-d1e196eeb479@est.tech> (raw)
In-Reply-To: <a801b816ecbff66fc39732801eec691af21ce3ac.camel@pbarker.dev>
On 8/27/26 09:27, Daniel Turull wrote:
> On Wed, 2026-08-26 at 01:14 -0700, Jakub Szczudlo (Nokia) wrote:
>> Hi,
>>
>> I understand this CVE is bigger than I thought CVE patch can be.
>> Maybe we can think about updating expat beyond the fixed version?
>> I now it's not the best because it is stable branch but I can't think about correct solution.
>
> Hi,
>
> Upgrading expat on wrynose & scarthgap may be possible. We are carrying
> a *lot* of patches for expat, especially on scarthgap, so it's worth
> considering.
>
> It would need a few things:
>
> - Review of the delta between the current version on these branches,
> including the patches we're carrying, and the latest version. Check
> that there are no features removed or other backwards-incompatible
> changes.
>
> - Confirmation that the SONAME changes won't break anything.
>
> - Testing.
>
> - RFC patch on the mailing list with a clear subject so people can see
> it's an exception to the usual stable upgrade policy, explain the
> review and testing done. This gives chance for people to object if it
> will cause issues for them.
>
> - Agreement from the Yocto TSC, based on the above info.
>
> That all needs some time investment beyond what we currently have
> available, so if you have the bandwidth to look in to it then that would
> be welcome.
>
> Best regards,
>
Hi all,
I agree that expat should be uplifted to 2.8.3.
I have some comments/suggestions regarding this.
To verify ABI compatibility, I ran abidiff
(https://sourceware.org/libabigail/manual/abidiff.html) for expat 2.7.5
and 2.8.3, and can conclude that there is no ABI break, and can also
confirm that there has not been a major bump in the SONAME.
I want to point to our fork of
meta-binaryaudit(https://github.com/nordix/meta-binaryaudit), which
wraps abidw and abidiff into a Yocto layer, which then can be used to
compare ABI breaks in the packages.
I have also analysed the Changelog as suggested, there has not been any
feature removal, but there are some opt-in feature additions (disabled
by default), and new Autotools flags. I don't see any
backward-incompatible changes.
I will prepare a patch to uplift to expat 2.8.3, test it, and include
these results, and mark it RFC as mentioned.
Thanks!
Adarsh Jagadish Kamini
Ericsson Software Technology AB
next prev parent reply other threads:[~2026-08-27 10:54 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-24 15:20 [wrynose][PATCH 1/3] expat: fix CVE-2026-50219 Jakub Szczudlo (Nokia)
2026-08-24 15:20 ` [wrynose][PATCH 2/3] expat: fix CVE-2026-56131 Jakub Szczudlo (Nokia)
2026-08-24 15:20 ` [wrynose][PATCH 3/3] expat: fix CVE-2026-56412 Jakub Szczudlo (Nokia)
2026-08-24 17:15 ` [wrynose][PATCH 1/3] expat: fix CVE-2026-50219 Paul Barker
2026-08-26 8:14 ` Jakub Szczudlo (Nokia)
2026-08-26 9:56 ` Paul Barker
2026-08-27 10:54 ` Adarsh Jagadish Kamini [this message]
2026-08-27 11:05 ` Jakub Szczudlo (Nokia)
2026-08-27 11:45 ` [OE-core] " Adarsh Jagadish Kamini
2026-08-27 11:57 ` Jakub Szczudlo (Nokia)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=b8b848b9-81ec-4a9e-bb4c-d1e196eeb479@est.tech \
--to=adarsh.jagadish.kamini@est.tech \
--cc=daniel.turull@ericsson.com \
--cc=david.partain@est.tech \
--cc=jakub.szczudlo@nokia.com \
--cc=openembedded-core@lists.openembedded.org \
--cc=paul@pbarker.dev \
--cc=yoann.congal@smile.fr \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox