diff --git a/SPECS/expat/expat.signatures.json b/SPECS/expat/expat.signatures.json index faaee12cd64..f3d9d05b7e9 100644 --- a/SPECS/expat/expat.signatures.json +++ b/SPECS/expat/expat.signatures.json @@ -1,5 +1,5 @@ { "Signatures": { - "expat-2.6.4.tar.bz2": "8dc480b796163d4436e6f1352e71800a774f73dbae213f1860b60607d2a83ada" + "expat-2.8.0.tar.bz2": "586494499ac3ad46d87f3beda7b1f770c1c8026a9b60e151593f8b29089a52ca" } } \ No newline at end of file diff --git a/SPECS/expat/expat.spec b/SPECS/expat/expat.spec index 59f199cb0e4..3b9a86903a2 100644 --- a/SPECS/expat/expat.spec +++ b/SPECS/expat/expat.spec @@ -1,22 +1,14 @@ %define underscore_version %(echo %{version} | cut -d. -f1-3 --output-delimiter="_") Summary: An XML parser library Name: expat -Version: 2.6.4 -Release: 6%{?dist} +Version: 2.8.0 +Release: 1%{?dist} License: MIT Vendor: Microsoft Corporation Distribution: Azure Linux Group: System Environment/GeneralLibraries URL: https://libexpat.github.io/ Source0: https://github.com/libexpat/libexpat/releases/download/R_%{underscore_version}/%{name}-%{version}.tar.bz2 -Patch0: CVE-2024-8176.patch -Patch1: CVE-2025-59375.patch -Patch2: CVE-2026-24515.patch -Patch3: CVE-2026-25210.patch -Patch4: Stop-updating-event-pointer-on-exit-for-reentry.patch -Patch5: CVE-2026-32776.patch -Patch6: CVE-2026-32777.patch -Patch7: CVE-2026-32778.patch Requires: %{name}-libs = %{version}-%{release} %description @@ -74,6 +66,9 @@ rm -rf %{buildroot}/%{_docdir}/%{name} %{_libdir}/libexpat.so.1* %changelog +* Wed May 27 2026 BinduSri Adabala - 2.8.0-1 +- Upgrade to 2.8.0 to fix CVE-2026-7210 + * Wed Apr 15 2026 Azure Linux Security Servicing Account - 2.6.4-6 - Patch for CVE-2026-32778, CVE-2026-32777, CVE-2026-32776 diff --git a/cgmanifest.json b/cgmanifest.json index b6a61a49716..b222abe77d2 100644 --- a/cgmanifest.json +++ b/cgmanifest.json @@ -3508,8 +3508,8 @@ "type": "other", "other": { "name": "expat", - "version": "2.6.4", - "downloadUrl": "https://github.com/libexpat/libexpat/releases/download/R_2_6_4/expat-2.6.4.tar.bz2" + "version": "2.8.0", + "downloadUrl": "https://github.com/libexpat/libexpat/releases/download/R_2_8_0/expat-2.8.0.tar.bz2" } } }, diff --git a/toolkit/resources/manifests/package/pkggen_core_aarch64.txt b/toolkit/resources/manifests/package/pkggen_core_aarch64.txt index be154837446..e09c10537d8 100644 --- a/toolkit/resources/manifests/package/pkggen_core_aarch64.txt +++ b/toolkit/resources/manifests/package/pkggen_core_aarch64.txt @@ -99,9 +99,9 @@ elfutils-libelf-0.189-6.azl3.aarch64.rpm elfutils-libelf-devel-0.189-6.azl3.aarch64.rpm elfutils-libelf-devel-static-0.189-6.azl3.aarch64.rpm elfutils-libelf-lang-0.189-6.azl3.aarch64.rpm -expat-2.6.4-6.azl3.aarch64.rpm -expat-devel-2.6.4-6.azl3.aarch64.rpm -expat-libs-2.6.4-6.azl3.aarch64.rpm +expat-2.8.0-1.azl3.aarch64.rpm +expat-devel-2.8.0-1.azl3.aarch64.rpm +expat-libs-2.8.0-1.azl3.aarch64.rpm libpipeline-1.5.7-1.azl3.aarch64.rpm libpipeline-devel-1.5.7-1.azl3.aarch64.rpm gdbm-1.23-1.azl3.aarch64.rpm diff --git a/toolkit/resources/manifests/package/pkggen_core_x86_64.txt b/toolkit/resources/manifests/package/pkggen_core_x86_64.txt index ea28ddbf634..b4d333d8541 100644 --- a/toolkit/resources/manifests/package/pkggen_core_x86_64.txt +++ b/toolkit/resources/manifests/package/pkggen_core_x86_64.txt @@ -99,9 +99,9 @@ elfutils-libelf-0.189-6.azl3.x86_64.rpm elfutils-libelf-devel-0.189-6.azl3.x86_64.rpm elfutils-libelf-devel-static-0.189-6.azl3.x86_64.rpm elfutils-libelf-lang-0.189-6.azl3.x86_64.rpm -expat-2.6.4-6.azl3.x86_64.rpm -expat-devel-2.6.4-6.azl3.x86_64.rpm -expat-libs-2.6.4-6.azl3.x86_64.rpm +expat-2.8.0-1.azl3.x86_64.rpm +expat-devel-2.8.0-1.azl3.x86_64.rpm +expat-libs-2.8.0-1.azl3.x86_64.rpm libpipeline-1.5.7-1.azl3.x86_64.rpm libpipeline-devel-1.5.7-1.azl3.x86_64.rpm gdbm-1.23-1.azl3.x86_64.rpm diff --git a/toolkit/resources/manifests/package/toolchain_aarch64.txt b/toolkit/resources/manifests/package/toolchain_aarch64.txt index 0b6c7843bea..bab575b5562 100644 --- a/toolkit/resources/manifests/package/toolchain_aarch64.txt +++ b/toolkit/resources/manifests/package/toolchain_aarch64.txt @@ -94,10 +94,10 @@ elfutils-libelf-0.189-6.azl3.aarch64.rpm elfutils-libelf-devel-0.189-6.azl3.aarch64.rpm elfutils-libelf-devel-static-0.189-6.azl3.aarch64.rpm elfutils-libelf-lang-0.189-6.azl3.aarch64.rpm -expat-2.6.4-6.azl3.aarch64.rpm -expat-debuginfo-2.6.4-6.azl3.aarch64.rpm -expat-devel-2.6.4-6.azl3.aarch64.rpm -expat-libs-2.6.4-6.azl3.aarch64.rpm +expat-2.8.0-1.azl3.aarch64.rpm +expat-debuginfo-2.8.0-1.azl3.aarch64.rpm +expat-devel-2.8.0-1.azl3.aarch64.rpm +expat-libs-2.8.0-1.azl3.aarch64.rpm file-5.45-1.azl3.aarch64.rpm file-debuginfo-5.45-1.azl3.aarch64.rpm file-devel-5.45-1.azl3.aarch64.rpm diff --git a/toolkit/resources/manifests/package/toolchain_x86_64.txt b/toolkit/resources/manifests/package/toolchain_x86_64.txt index 46fd57f67aa..a9550e732b0 100644 --- a/toolkit/resources/manifests/package/toolchain_x86_64.txt +++ b/toolkit/resources/manifests/package/toolchain_x86_64.txt @@ -99,10 +99,10 @@ elfutils-libelf-0.189-6.azl3.x86_64.rpm elfutils-libelf-devel-0.189-6.azl3.x86_64.rpm elfutils-libelf-devel-static-0.189-6.azl3.x86_64.rpm elfutils-libelf-lang-0.189-6.azl3.x86_64.rpm -expat-2.6.4-6.azl3.x86_64.rpm -expat-debuginfo-2.6.4-6.azl3.x86_64.rpm -expat-devel-2.6.4-6.azl3.x86_64.rpm -expat-libs-2.6.4-6.azl3.x86_64.rpm +expat-2.8.0-1.azl3.x86_64.rpm +expat-debuginfo-2.8.0-1.azl3.x86_64.rpm +expat-devel-2.8.0-1.azl3.x86_64.rpm +expat-libs-2.8.0-1.azl3.x86_64.rpm file-5.45-1.azl3.x86_64.rpm file-debuginfo-5.45-1.azl3.x86_64.rpm file-devel-5.45-1.azl3.x86_64.rpm