-
-
Notifications
You must be signed in to change notification settings - Fork 30.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Please upgrade bundled Expat to 2.6.2 (e.g. for the fix to CVE-2024-28757) #116741
Labels
type-bug
An unexpected behavior, bug, or error
Comments
hartwork
changed the title
Please upgrade bundled Expat to 2.6.2 (e.g. for the fix toCVE-2024-28757)
Please upgrade bundled Expat to 2.6.2 (e.g. for the fix to CVE-2024-28757)
Mar 13, 2024
28 tasks
@sethmlarson any chance we could team up on this once more? |
@hartwork Sorry for not replying, I was gone for the past 2 weeks on vacation. Here's a PR upgrading 2.6.2, please take a look. |
@sethmlarson looks good, thank you! 👍 |
miss-islington
pushed a commit
to miss-islington/cpython
that referenced
this issue
Apr 23, 2024
Upgrade libexpat to 2.6.2 (cherry picked from commit c9829ee) Co-authored-by: Seth Michael Larson <[email protected]>
gpshead
pushed a commit
that referenced
this issue
Apr 23, 2024
sethmlarson
added a commit
to sethmlarson/cpython
that referenced
this issue
Apr 23, 2024
Upgrade libexpat to 2.6.2 (cherry picked from commit c9829ee) Co-authored-by: Seth Michael Larson <[email protected]>
sethmlarson
added a commit
to sethmlarson/cpython
that referenced
this issue
Apr 23, 2024
Upgrade libexpat to 2.6.2 (cherry picked from commit c9829ee) Co-authored-by: Seth Michael Larson <[email protected]>
sethmlarson
added a commit
to sethmlarson/cpython
that referenced
this issue
Apr 23, 2024
Upgrade libexpat to 2.6.2 (cherry picked from commit c9829ee) Co-authored-by: Seth Michael Larson <[email protected]>
sethmlarson
added a commit
to sethmlarson/cpython
that referenced
this issue
Apr 23, 2024
Upgrade libexpat to 2.6.2 (cherry picked from commit c9829ee) Co-authored-by: Seth Michael Larson <[email protected]>
Is this fully implemented now? |
it looks like all of the backports are in. yes. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Bug report
Bug description:
Hi! 👋
Please upgrade bundled Expat to 2.6.2 (e.g. for the fix to CVE-2024-28757).
The CPython issue for previous 2.6.0 was #115399 and the related merged main pull request was #115431, in case you want to have a look. Comment #115431 (comment) could be of help by raising confidence in the bump pull request when going forward.
Thanks in advance!
CPython versions tested on:
3.8, 3.9, 3.10, 3.11, 3.12, 3.13, CPython main branch
Operating systems tested on:
Linux, macOS, Windows, Other
Linked PRs
The text was updated successfully, but these errors were encountered: