Skip to content

Conversation

@LeSuisse
Copy link
Contributor

@LeSuisse LeSuisse commented Mar 18, 2025

@LeSuisse LeSuisse requested review from a team as code owners March 18, 2025 21:27
@linux-foundation-easycla
Copy link

linux-foundation-easycla bot commented Mar 18, 2025

CLA Signed

The committers listed above are authorized under a signed CLA.

  • ✅ login: LeSuisse / name: Thomas Gerbet (87722e9)

@zwass
Copy link
Member

zwass commented Mar 25, 2025

Thanks @LeSuisse! Did you do any testing to verify things are still working as expected? We just discussed in office hours and think the relevant tables are systemd_units and startup_items.

@LeSuisse
Copy link
Contributor Author

I did make a quick functional tests with systemd_units which seemed fine. In any case a new expat release is expected to be cut by the end of the week to include a regression fix. At a glance I do not think it directly affects osquery but waiting until then is probably the safe play.

libexpat/libexpat#980 (comment)

I'm putting the PR in draft until then and I will test again with the new version.

@LeSuisse LeSuisse marked this pull request as draft March 25, 2025 18:37
@hartwork
Copy link

FYI the bump from 2.6.0 to 2.7.0 also fixes CVE-2024-50602.

@zwass
Copy link
Member

zwass commented Mar 27, 2025

I see they merged the linked PR in the expat repo. Please lmk when this is ready for review again!

@hartwork
Copy link

@zwass FYI release Expat 2.7.1 is coming up in the next few hours

@hartwork
Copy link

Expat 2.7.1 with a fix has been released.

@LeSuisse LeSuisse changed the title libs: expat bump from 2.6.0 to 2.7.0 libs: expat bump from 2.6.0 to 2.7.1 Mar 28, 2025
@LeSuisse LeSuisse marked this pull request as ready for review March 28, 2025 07:47
@LeSuisse
Copy link
Contributor Author

Bumped to 2.7.1, I played a bit with startup_items and systemd_units with no issue. This should be good to go.

Copy link
Member

@zwass zwass left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@LeSuisse can you please merge/rebase master? That will fix the mdfind CI issue.

@zwass zwass closed this Apr 9, 2025
@zwass zwass reopened this Apr 9, 2025
@LeSuisse LeSuisse closed this Apr 9, 2025
@LeSuisse
Copy link
Contributor Author

LeSuisse commented Apr 9, 2025

Sorry for the noise, it looks like I failed to push the appropriate branch and it closed the PR without giving me the possibility to re-open it. See #8595 for the rebased change.

zwass pushed a commit that referenced this pull request Apr 10, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Library expat has vulnerability CVE-2024-28757

3 participants