python / cpython

The Python programming language
https://www.python.org
Other
63.83k stars 30.56k forks source link

Please upgrade bundled Expat to 2.6.3 (e.g. for the fixes to CVE-2024-45490, CVE-2024-45491 and CVE-2024-45492) #123678

Closed hartwork closed 2 months ago

hartwork commented 2 months ago

Bug report

Bug description:

Hi! :wave:

Please upgrade bundled Expat to 2.6.3 (e.g. for the fixes to CVE-2024-45490, CVE-2024-45491 and CVE-2024-45492).

The CPython issue for previous 2.6.2 was #116741 and the related merged main pull request was #117296, in case you want to have a look. The Dockerfile from comment https://github.com/python/cpython/pull/117296#pullrequestreview-1964486079 could be of help with raising confidence in a bump pull request when going forward.

Thanks in advance!

CPython versions tested on:

3.8, 3.9, 3.10, 3.11, 3.12, 3.13, CPython main branch

Operating systems tested on:

Linux, macOS, Windows, Other

Linked PRs

sobolevn commented 2 months ago

cc @sethmlarson

sethmlarson commented 2 months ago

Thanks for the ping @sobolevn, I'll work with release managers to get this update out.

sethmlarson commented 2 months ago

I've created a PR, please take a look: https://github.com/python/cpython/pull/123689

sethmlarson commented 2 months ago

All pull requests have been merged