- Please see URL field for the blog post with details. - Bump to 2.7.0 coming up in a minute…
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=bbe241ea7747494b118969bf2cf4e03118a0267a commit bbe241ea7747494b118969bf2cf4e03118a0267a Author: Sebastian Pipping <sping@gentoo.org> AuthorDate: 2025-03-13 21:37:23 +0000 Commit: Sebastian Pipping <sping@gentoo.org> CommitDate: 2025-03-13 21:43:16 +0000 dev-libs/expat: 2.7.0 (CVE-2024-8176) Bug: https://bugs.gentoo.org/951316 Signed-off-by: Sebastian Pipping <sping@gentoo.org> dev-libs/expat/Manifest | 1 + dev-libs/expat/expat-2.7.0.ebuild | 100 ++++++++++++++++++++++++++++++++++++++ 2 files changed, 101 insertions(+)
I have taken the issue to CERT/CC VINCE also to notify more vendors of the issue. Gentoo Linux was added as a vendor by the coordinator. Could someone with permissions in VINCE mark vendor Gentoo Linux as "affected" for not-yet- public case https://kb.cert.org/vince/comm/case/2322/ ? Thanks!
I'll do that now, thanks
(In reply to Sam James from comment #3) > I'll do that now, thanks Thank you!