This version bump includes fixes for the following CVEs:
- CVE-2026-66046
- CVE-2026-72522
- CVE-2026-76641
- CVE-2026-76956
- CVE-2026-76957
Full release notes:
https://github.com/libexpat/libexpat/blob/master/expat/Changes
Signed-off-by: Wei-Ting Yang <redacted>
include $(TOPDIR)/rules.mk
PKG_NAME:=expat
-PKG_VERSION:=2.8.2
+PKG_VERSION:=2.8.4
PKG_RELEASE:=1
PKG_SOURCE:=$(PKG_NAME)-$(PKG_VERSION).tar.gz
PKG_SOURCE_URL:=https://github.com/libexpat/libexpat/releases/download/R_$(subst .,_,$(PKG_VERSION))
-PKG_HASH:=ef7d1994f533c9e7343d6c19f31064fc8ebbcbcaa144be3812b4f43052a05f4c
+PKG_HASH:=b8ece2437692dad44d851c4532723390a5a330990007706be9c8d2b90d294f36
PKG_LICENSE:=MIT
PKG_LICENSE_FILES:=COPYING