Full changelog available here.
CVE-2017-9233 -- External entity infinite loop DoS. Details: https://libexpat.github.io/doc/cve-2017-9233/ CVE-2016-9063 -- Detect integer overflow; (Fixed version of existing downstream patches!) Fix regression from fix to CVE-2016-0718 cutting off longer tag names; Detect overflow from len=INT_MAX call to XML_Parse;
libexpat is moving to GitHub, however downloads remain on SF for now.