An update for mingw-expat is now available for Rocky Linux 8. Rocky Enterprise Software Foundation Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Expat is a C library for parsing XML documents. The mingw-expat packages provide a port of the Expat library for MinGW. The following packages have been upgraded to a later upstream version: mingw-expat (2.4.8). (BZ#2057023, BZ#2057037, BZ#2057127) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Rocky Linux 8.7 Release Notes linked from the References section.
No References
https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23990.json
https://bugzilla.redhat.com/show_bug.cgi?id=2048356
https://bugzilla.redhat.com/show_bug.cgi?id=2056350
https://bugzilla.redhat.com/show_bug.cgi?id=2056354
https://bugzilla.redhat.com/show_bug.cgi?id=2056363
https://bugzilla.redhat.com/show_bug.cgi?id=2056366
https://bugzilla.redhat.com/show_bug.cgi?id=2056370