Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade bundled expat to 2.5.0 #98739

Closed
scdub opened this issue Oct 26, 2022 · 2 comments
Closed

Upgrade bundled expat to 2.5.0 #98739

scdub opened this issue Oct 26, 2022 · 2 comments
Assignees
Labels
3.7 (EOL) end of life 3.8 only security fixes 3.9 only security fixes release-blocker type-bug An unexpected behavior, bug, or error type-security A security issue

Comments

@scdub
Copy link
Contributor

scdub commented Oct 26, 2022

Upgrade the bundled libexpat version to 2.5.0 which includes a fix for CVE-2022-43680. I haven't evaluated whether CPython is directly impacted by this CVE, but can confirm that it is detected by binary analysis tools such as Black Duck.

Related libexpat changelog includes additional fixes and details.

@scdub scdub added the type-bug An unexpected behavior, bug, or error label Oct 26, 2022
@gpshead gpshead added the type-security A security issue label Oct 27, 2022
gpshead pushed a commit that referenced this issue Oct 27, 2022
* Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680.

Co-authored-by: Shaun Walbridge <shaun.walbridge@gmail.com>
miss-islington pushed a commit to miss-islington/cpython that referenced this issue Oct 27, 2022
* Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680.

Co-authored-by: Shaun Walbridge <shaun.walbridge@gmail.com>
(cherry picked from commit 3e07f82)

Co-authored-by: Shaun Walbridge <46331011+scdub@users.noreply.github.com>
miss-islington pushed a commit to miss-islington/cpython that referenced this issue Oct 27, 2022
* Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680.

Co-authored-by: Shaun Walbridge <shaun.walbridge@gmail.com>
(cherry picked from commit 3e07f82)

Co-authored-by: Shaun Walbridge <46331011+scdub@users.noreply.github.com>
miss-islington pushed a commit to miss-islington/cpython that referenced this issue Oct 27, 2022
* Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680.

Co-authored-by: Shaun Walbridge <shaun.walbridge@gmail.com>
(cherry picked from commit 3e07f82)

Co-authored-by: Shaun Walbridge <46331011+scdub@users.noreply.github.com>
miss-islington pushed a commit to miss-islington/cpython that referenced this issue Oct 27, 2022
* Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680.

Co-authored-by: Shaun Walbridge <shaun.walbridge@gmail.com>
(cherry picked from commit 3e07f82)

Co-authored-by: Shaun Walbridge <46331011+scdub@users.noreply.github.com>
miss-islington pushed a commit to miss-islington/cpython that referenced this issue Oct 27, 2022
* Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680.

Co-authored-by: Shaun Walbridge <shaun.walbridge@gmail.com>
(cherry picked from commit 3e07f82)

Co-authored-by: Shaun Walbridge <46331011+scdub@users.noreply.github.com>
@gpshead gpshead self-assigned this Oct 27, 2022
@gpshead
Copy link
Member

gpshead commented Oct 27, 2022

Thanks for making the PR! Release branch merges will happen but are pending figuring out why the CLA bot is mistakenly not accepting those on our end.

miss-islington added a commit that referenced this issue Oct 27, 2022
* Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680.

Co-authored-by: Shaun Walbridge <shaun.walbridge@gmail.com>
(cherry picked from commit 3e07f82)

Co-authored-by: Shaun Walbridge <46331011+scdub@users.noreply.github.com>
miss-islington added a commit that referenced this issue Oct 27, 2022
* Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680.

Co-authored-by: Shaun Walbridge <shaun.walbridge@gmail.com>
(cherry picked from commit 3e07f82)

Co-authored-by: Shaun Walbridge <46331011+scdub@users.noreply.github.com>
@gpshead gpshead added 3.9 only security fixes 3.8 only security fixes 3.7 (EOL) end of life labels Oct 27, 2022
@gpshead gpshead assigned ambv and ned-deily and unassigned gpshead Oct 27, 2022
ambv pushed a commit that referenced this issue Oct 28, 2022
Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680.

Co-authored-by: Shaun Walbridge <shaun.walbridge@gmail.com>
(cherry picked from commit 3e07f82)
ambv pushed a commit that referenced this issue Oct 28, 2022
Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680.

Co-authored-by: Shaun Walbridge <shaun.walbridge@gmail.com>
(cherry picked from commit 3e07f82)
ambv pushed a commit that referenced this issue Oct 28, 2022
Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680.

Co-authored-by: Shaun Walbridge <shaun.walbridge@gmail.com>
(cherry picked from commit 3e07f82)
gvanrossum pushed a commit to gvanrossum/cpython that referenced this issue Oct 28, 2022
* Update libexpat from 2.4.9 to 2.5.0 to address CVE-2022-43680.

Co-authored-by: Shaun Walbridge <shaun.walbridge@gmail.com>
@ned-deily
Copy link
Member

I believe all the backports have been merged and thus we can close this issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
3.7 (EOL) end of life 3.8 only security fixes 3.9 only security fixes release-blocker type-bug An unexpected behavior, bug, or error type-security A security issue
Projects
Development

No branches or pull requests

4 participants