The new XML library's CVE may not apply to OpenBSD
Brief
The importer listed other bugfixes as what matters for OpenBSD.
Notes
2d225ad45d42506d4068f43c0f3f4af6f3c799d0 landed Wednesday in -current (bluhm, OK deraadt@ tb@). “Update libexpat to version 2.8.3.” It names bug fixes #1297 #1300 #1286 #1305 #1306 and other changes #1303 as relevant for OpenBSD, then writes CVE-2026-72522. Official log: source-changes, MARC, Codeberg.
oss-security (Sebastian Pipping, 2026-08-11) says CVE-2026-72522 is in the UTF-16 conversion path and needs 16-bit character support. Upstream security fix is #1296. That number is not in Bluhm’s “relevant for OpenBSD” list. No library bump. Not on errata79 or errata78.
Unknown: whether any OpenBSD base consumer builds 16-bit XML.
Commit 2d225ad45d42506d4068f43c0f3f4af6f3c799d0