[Buildroot] [PATCH v2,1/1] package/expat: fix CVE-2022-40674

Peter Korsgaard peter at korsgaard.com
Thu Sep 29 13:52:29 UTC 2022


>>>>> "Fabrice" == Fabrice Fontaine <fontaine.fabrice at gmail.com> writes:

 > libexpat before 2.4.9 has a use-after-free in the doContent function in
 > xmlparse.c.

 > Signed-off-by: Fabrice Fontaine <fontaine.fabrice at gmail.com>
 > ---
 > Changes v1 -> v2:
 >  - Fix path in patch

Committed to 2022.02.x, 2022.05.x and 2022.08.x, thanks.

-- 
Bye, Peter Korsgaard



More information about the buildroot mailing list