expat: bump to 2.7.1 to fix several CVEs
authorGeorge Sapkin <[email protected]>
Fri, 4 Apr 2025 16:30:59 +0000 (19:30 +0300)
committerJosef Schlehofer <[email protected]>
Sun, 6 Apr 2025 20:11:26 +0000 (23:11 +0300)
Addresses CVE-2024-8176 and CVE-2024-50602.

Full changelog linked below.

Changelog: https://github.com/libexpat/libexpat/blob/R_2_7_1/expat/Changes
Fixes: https://github.com/openwrt/packages/issues/26255
Fixes: https://github.com/advisories/GHSA-9hcv-xw76-m4h6
Fixes: https://github.com/advisories/GHSA-79wf-qgrg-2p6c
Signed-off-by: George Sapkin <[email protected]>
libs/expat/Makefile

index 2e80c62fe118ef8e6f3fcd8e05f3c034e6456013..51c77c130d2cc0ebce6a94f68524766b7ef6aead 100644 (file)
@@ -6,12 +6,12 @@
 include $(TOPDIR)/rules.mk
 
 PKG_NAME:=expat
-PKG_VERSION:=2.6.3
+PKG_VERSION:=2.7.1
 PKG_RELEASE:=1
 
 PKG_SOURCE:=$(PKG_NAME)-$(PKG_VERSION).tar.gz
 PKG_SOURCE_URL:=https://github.com/libexpat/libexpat/releases/download/R_$(subst .,_,$(PKG_VERSION))
-PKG_HASH:=17aa6cfc5c4c219c09287abfc10bc13f0c06f30bb654b28bfe6f567ca646eb79
+PKG_HASH:=0cce2e6e69b327fc607b8ff264f4b66bdf71ead55a87ffd5f3143f535f15cfa2
 
 PKG_MAINTAINER:=Ted Hess <[email protected]>
 PKG_LICENSE:=MIT