Feed
Breaking OpenBSD

OpenBSD 7.8 and 7.9 pick up the XML parser fixes from 2.8.3

Brief

Sources come from 2.8.3. Headers stay on the older 2.7 line.

Notes

msg162848 (bluhm@, 2026-08-20). lib/libexpat on OPENBSD_7_8. “Backport all changes from libexpat 2.8.3.” Sources from 2.8.3, header from 2.7.3, no ABI change. Named errata/7.8/050_expat.patch.sig.

msg162849 is the same backport on OPENBSD_7_9, header from 2.7.5, named errata/7.9/014_expat.patch.sig.

The mail lists fifteen CVEs and does not name a class for the pile: CVE-2026-45186, CVE-2026-50219, CVE-2026-56131, CVE-2026-56132, CVE-2026-56403, CVE-2026-56404, CVE-2026-56405, CVE-2026-56406, CVE-2026-56407, CVE-2026-56408, CVE-2026-56409, CVE-2026-56410, CVE-2026-56411, CVE-2026-56412, CVE-2026-72522.

This is not a recast of 8ef28736, which is the -current import and the “may not apply” 16-bit-character note.

No OpenBSD src SHA on GitHub or Codeberg. Do not invent one.

Official errata79 014 and errata78 050 are SECURITY FIX, dated August 22, 2026. Pages Last-Modified Sun 23 Aug 2026 07:08:33 GMT.

Commit msg162848

Sources