• Bug#1106038: unblock: libxml2/2.12.7+dfsg+really2.9.14-1

    From Aron Xu@21:1/5 to All on Mon May 19 08:50:01 2025
    XPost: linux.debian.devel.release

    Package: release.debian.org
    Control: affects -1 + src:libxml2
    X-Debbugs-Cc: libxml2@packages.debian.org
    User: release.debian.org@packages.debian.org
    Usertags: unblock
    Severity: normal

    Please unblock package libxml2

    libxml2/2.12.7+dfsg+really2.9.14-1 in unstable is an update for security fixes:

    - CVE-2023-39615: out-of-bounds read via the xmlSAX2StartElement()
    (Closes: #1051230)
    - CVE-2023-45322: use-after-free in xmlUnlinkNode() (Closes: #1053629)
    - CVE-2024-25062: use-after-free in xmlValidatePopElement() (Closes: #1063234) - CVE-2025-32414: out-of-bounds read in Python bindings (Closes: #1102521)
    - CVE-2025-32415: heap-based buffer under-read via
    xmlSchemaIDCFillNodeTables() (Closes: #1103511)

    unblock libxml2/2.12.7+dfsg+really2.9.14-1

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)