Feed
OpenBSD

The new XML library's CVE may not apply to OpenBSD

Brief

The importer listed other bugfixes as what matters for OpenBSD.

Notes

2d225ad45d42506d4068f43c0f3f4af6f3c799d0 landed Wednesday in -current (bluhm, OK deraadt@ tb@). “Update libexpat to version 2.8.3.” It names bug fixes #1297 #1300 #1286 #1305 #1306 and other changes #1303 as relevant for OpenBSD, then writes CVE-2026-72522. Official log: source-changes, MARC, Codeberg.

oss-security (Sebastian Pipping, 2026-08-11) says CVE-2026-72522 is in the UTF-16 conversion path and needs 16-bit character support. Upstream security fix is #1296. That number is not in Bluhm’s “relevant for OpenBSD” list. No library bump. Not on errata79 or errata78.

Unknown: whether any OpenBSD base consumer builds 16-bit XML.

Commit 2d225ad45d42506d4068f43c0f3f4af6f3c799d0

Sources