Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <9849f703-9b30-4159-8c91-92365dbe5148@pipping.org>
Date: Wed, 24 Sep 2025 23:43:46 +0200
From: Sebastian Pipping <sebastian@...ping.org>
To: oss-security@...ts.openwall.com
Subject: libexpat 2.7.3 improves fixes to CVE-2024-8176 and CVE-2025-59375

Hello oss-security,


just a quick note that libexpat 2.7.3 (or "Expat 2.7.3") released
today is improving upon the original fixes to CVE-2024-8176 and
CVE-2025-59375. So if you backported the original fixes, please be sure
to update/extend these backports as needed.

Some key links are:

- The change log of release 2.7.3
   https://github.com/libexpat/libexpat/blob/R_2_7_3/expat/Changes

- The two key pull requests:
   https://github.com/libexpat/libexpat/pull/1048
   https://github.com/libexpat/libexpat/pull/1059

Best



Sebastian

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.