oss-sec mailing list archives

libexpat 2.7.3 improves fixes to CVE-2024-8176 and CVE-2025-59375


From: Sebastian Pipping <sebastian () pipping org>
Date: Wed, 24 Sep 2025 23:43:46 +0200

Hello oss-security,


just a quick note that libexpat 2.7.3 (or "Expat 2.7.3") released
today is improving upon the original fixes to CVE-2024-8176 and
CVE-2025-59375. So if you backported the original fixes, please be sure
to update/extend these backports as needed.

Some key links are:

- The change log of release 2.7.3
  https://github.com/libexpat/libexpat/blob/R_2_7_3/expat/Changes

- The two key pull requests:
  https://github.com/libexpat/libexpat/pull/1048
  https://github.com/libexpat/libexpat/pull/1059

Best



Sebastian


Current thread: