From Newsgroup: muc.lists.freebsd.ports
--000000000000ed06f706519e160b
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
On Tue, May 12, 2026 at 12:05=E2=80=AFPM Piotr Smyrak <
ps.ports@smyrak.com>=
wrote:
On Tue, 12 May 2026 13:00:50 +0200
Fernando Apestegu=C3=ADa <fernando.apesteguia@gmail.com> wrote:
On Tue, May 12, 2026 at 10:51=E2=80=AFAM Ronald Klop <ronald-lists@klop=
wrote:
Hi,
Last entry is of yesterday.
https://vuxml.freebsd.org/freebsd/
So I guess it is generated regularly.
Regards,
Ronald.
*Van:* Piotr Smyrak <ps.ports@smyrak.com>
*Datum:* dinsdag, 12 mei 2026 10:31
*Aan:* freebsd-ports@freebsd.org
*Onderwerp:* expat2 2.8 vulnerability report
Hello,
The URL to expat2 vulnerability report regarding CVE-2026-45186
returns 404 error:
https://vuxml.freebsd.org/freebsd/bacc1417-4d82-11f1-87f3-18dbf25a98c6.ht=
ml
Is it expected and that page shall be generated soon, or some system needs a nudge?
It was pushed today:
commit 9f22d11e50796885e308d61156253b9c29ffb3f6
Author: Thierry Thomas <thierry@FreeBSD.org>
Date: Tue May 12 00:09:38 2026 +0200 <--------
security/vuxml: adding an entry for expat
See https://blog.hartwork.org/posts/expat-2-8-1-released/
and https://nvd.nist.gov/vuln/detail/CVE-2026-45186
Security: CVE-2026-45186
If you see entries by date: https://vuxml.freebsd.org/freebsd/index-date.html
you'll see the most recent one is from yesterday (for appropriate
values of "yesterday").
Give it some time.
I have gathered the info needed from git-log, still I was wondering
whether something got stuck in process as it has not been published on
WWW, yet available through pkg-audit.
That's weird since pkg-audit should fetch the info from VULNXML_SITE which
by default is
https://vuxml.freebsd.org/freebsd/vuln.xml.xz
$ fetch
https://vuxml.freebsd.org/freebsd/vuln.xml.xz
vuln.xml.xz 1203 kB 2595 kBps
00s
$ unxz vuln.xml.xz
$ grep -A10 -B10 CVE-2026-45186 vuln.xml
<name>expat</name>
<name>linux-c7-expat</name>
<name>linux-rl9-expat</name>
<range><lt>2.8.1</lt></range>
</package>
</affects>
<description>
<body xmlns=3D"
http://www.w3.org/1999/xhtml">
<blockquote cite=3D"
https://blog.hartwork.org/posts/expat-2-8-1-released/">
<p>Expat 2.8.1 was released yesterday. The key motivation for
cutting a release and doing so now was:</p>
<p>Fixing vulnerability CVE-2026-45186 that allows easy denial of service.</p>
<p>See also
https://github.com/libexpat/libexpat/pull/1216</p>
</blockquote>
</body>
</description>
<references>
<cvename>CVE-2026-45186</cvename>
<url>
https://nvd.nist.gov/vuln/detail/CVE-2026-45186</url>
</references>
<dates>
<discovery>2025-10-01</discovery>
<entry>2026-05-11</entry>
</dates>
</vuln>
Certainly the information is there, but the page is not rendering all the entries.
It is probably a cron job that hasn't run yet.
Cheers.
Thanks guys,
--
Piotr Smyrak
--000000000000ed06f706519e160b
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
<div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote g= mail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Tue, May 12,=
2026 at 12:05=E2=80=AFPM Piotr Smyrak <<a href=3D"mailto:ps.ports@smyra= k.com">
ps.ports@smyrak.com</a>> wrote:<br></div><blockquote class=3D"gma= il_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,2= 04,204);padding-left:1ex">On Tue, 12 May 2026 13:00:50 +0200<br>
Fernando Apestegu=C3=ADa <<a href=3D"mailto:
fernando.apesteguia@gmail.co=
m" target=3D"_blank">
fernando.apesteguia@gmail.com</a>> wrote:<br>
> On Tue, May 12, 2026 at 10:51=E2=80=AFAM Ronald Klop <<a href=3D"ma= ilto:
ronald-lists@klop.ws" target=3D"_blank">
ronald-lists@klop.ws</a>><b=
> wrote:<br>
> <br>
> > Hi,<br>
> ><br>
> > Last entry is of yesterday.<br>
> ><br>
> > <a href=3D"
https://vuxml.freebsd.org/freebsd/" rel=3D"noreferrer"=
target=3D"_blank">
https://vuxml.freebsd.org/freebsd/</a><br>
> ><br>
> > So I guess it is generated regularly.<br>
> ><br>
> > Regards,<br>
> > Ronald.<br>
> ><br>
> ><br>
> ><br>
> > *Van:* Piotr Smyrak <<a href=3D"mailto:
ps.ports@smyrak.com" ta= rget=3D"_blank">
ps.ports@smyrak.com</a>><br>
> > *Datum:* dinsdag, 12 mei 2026 10:31<br>
> > *Aan:* <a href=3D"mailto:
freebsd-ports@freebsd.org" target=3D"_bl= ank">
freebsd-ports@freebsd.org</a><br>
> > *Onderwerp:* expat2 2.8 vulnerability report<br>
> ><br>
> > Hello,<br>
> ><br>
> > The URL to expat2 vulnerability report regarding CVE-2026-45186<b=
> > returns 404 error:<br>
> > <a href=3D"
https://vuxml.freebsd.org/freebsd/bacc1417-4d82-11f1-8= 7f3-18dbf25a98c6.html" rel=3D"noreferrer" target=3D"_blank">
https://vuxml.f= reebsd.org/freebsd/bacc1417-4d82-11f1-87f3-18dbf25a98c6.html</a><br>
> ><br>
> > Is it expected and that page shall be generated soon, or some sys= tem<br>
> > needs a nudge?<br>
> ><br>
> >=C2=A0 <br>
> It was pushed today:<br>
> commit 9f22d11e50796885e308d61156253b9c29ffb3f6<br>
> Author: Thierry Thomas <
thierry@FreeBSD.org><br>
> Date:=C2=A0 =C2=A0Tue May 12 00:09:38 2026 +0200 <--------<br>
> <br>
>=C2=A0 =C2=A0 =C2=A0security/vuxml: adding an entry for expat<br>
> <br>
>=C2=A0 =C2=A0 =C2=A0See <a href=3D"
https://blog.hartwork.org/posts/expa= t-2-8-1-released/" rel=3D"noreferrer" target=3D"_blank">
https://blog.hartwo= rk.org/posts/expat-2-8-1-released/</a><br>
>=C2=A0 =C2=A0 =C2=A0and <a href=3D"
https://nvd.nist.gov/vuln/detail/CVE= -2026-45186" rel=3D"noreferrer" target=3D"_blank">
https://nvd.nist.gov/vuln= /detail/CVE-2026-45186</a><br>
> <br>
>=C2=A0 =C2=A0 =C2=A0Security:=C2=A0 =C2=A0 =C2=A0 =C2=A0CVE-2026-45186<=
> <br>
> If you see entries by date:<br>
> <a href=3D"
https://vuxml.freebsd.org/freebsd/index-date.html" rel=3D"n= oreferrer" target=3D"_blank">
https://vuxml.freebsd.org/freebsd/index-date.h= tml</a><br>
> you'll see the most recent one is from yesterday (for appropriate<=
> values of "yesterday").<br>
> <br>
>=C2=A0 Give it some time.<br>
I have gathered the info needed from git-log, still I was wondering<br>
whether something got stuck in process as it has not been published on<br>
WWW, yet available through pkg-audit. <br></blockquote><div><br></div><div>= That's weird since pkg-audit should fetch the info from VULNXML_SITE wh= ich by default is=C2=A0<a href=3D"
https://vuxml.freebsd.org/freebsd/vuln.xm= l.xz">
https://vuxml.freebsd.org/freebsd/vuln.xml.xz</a></div><div><br></div= ><div>$ fetch <a href=3D"
https://vuxml.freebsd.org/freebsd/vuln.xml.xz">htt= ps://vuxml.freebsd.org/freebsd/vuln.xml.xz</a><br>vuln.xml.xz =C2=A0 =C2=A0=
=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 1203 kB 2595 kB=
ps =C2=A0 =C2=A000s<br>$ unxz vuln.xml.xz <br>$ grep -A10 -B10 CVE-2026-451=
86 vuln.xml <br><name>expat</name><br><name>linux-c7-expa= t</name><br><name>linux-rl9-expat</name><br><range>= <lt>2.8.1</lt></range><br></package><br>=C2=A0 =C2=
=A0 </affects><br>=C2=A0 =C2=A0 <description><br>=C2=A0 =C2=A0 = =C2=A0 =C2=A0 <body xmlns=3D"<a href=3D"
http://www.w3.org/1999/xhtm= l">
http://www.w3.org/1999/xhtml</a>"><br>=C2=A0 =C2=A0 =C2=A0 =C2=
=A0 <blockquote cite=3D"<a href=3D"
https://blog.hartwork.org/posts/= expat-2-8-1-released/">
https://blog.hartwork.org/posts/expat-2-8-1-released= /</a>"><br>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 <p>Expat 2.8.1 = was released yesterday. The key motivation for cutting a release and doing =
so now was:</p><br>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 <p>Fixing=
vulnerability CVE-2026-45186 that allows easy denial of service.</p>= <br>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 <p>See also <a href=3D"https:/= /github.com/libexpat/libexpat/pull/1216">
https://github.com/libexpat/libexp= at/pull/1216</a></p><br>=C2=A0 =C2=A0 =C2=A0 =C2=A0 </blockquote&g= t;<br>=C2=A0 =C2=A0 =C2=A0 =C2=A0 </body><br>=C2=A0 =C2=A0 </descr= iption><br>=C2=A0 =C2=A0 <references><br>=C2=A0 =C2=A0 =C2=A0 <= cvename>CVE-2026-45186</cvename><br>=C2=A0 =C2=A0 =C2=A0 <url&g= t;<a href=3D"
https://nvd.nist.gov/vuln/detail/CVE-2026-45186">https://nvd.n= ist.gov/vuln/detail/CVE-2026-45186</a></url><br>=C2=A0 =C2=A0 </re= ferences><br>=C2=A0 =C2=A0 <dates><br>=C2=A0 =C2=A0 =C2=A0 <dis= covery>2025-10-01</discovery><br>=C2=A0 =C2=A0 =C2=A0 <entry>= ;2026-05-11</entry><br>=C2=A0 =C2=A0 </dates><br>=C2=A0 </vu= ln><br><br></div><div>Certainly the information is there, but the page i=
s not rendering all the entries.</div><div>It is probably a cron job that h= asn't run yet.</div><div><br></div><div>Cheers.</div><div><br></div><di= v>=C2=A0</div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px=
0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
Thanks guys,<br>
-- <br>
=C2=A0Piotr Smyrak<br>
</blockquote></div></div>
--000000000000ed06f706519e160b--
--
Posted automagically by a mail2news gateway at muc.de e.V.
Please direct questions, flames, donations, etc. to
news-admin@muc.de
--- Synchronet 3.22a-Linux NewsLink 1.2