-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 27 Jul 2025 01:15:48 +0200 Source: libxml2 Binary: libxml2 libxml2-dbgsym libxml2-dev libxml2-utils libxml2-utils-dbgsym python3-libxml2 python3-libxml2-dbgsym Architecture: armhf Version: 2.9.14+dfsg-1.3~deb12u3 Distribution: bookworm Urgency: high Maintainer: arm Build Daemon (arm-conova-04) Changed-By: Guilhem Moulin Description: libxml2 - GNOME XML library libxml2-dev - GNOME XML library - development files libxml2-utils - GNOME XML library - utilities python3-libxml2 - GNOME XML library - Python3 bindings Closes: 1107720 1107752 1107755 1107938 Changes: libxml2 (2.9.14+dfsg-1.3~deb12u3) bookworm; urgency=high . * Non-maintainer upload. * Fix CVE-2025-6021: Integer overflow issue in xmlBuildQName. (Closes: #1107720). * Fix CVE-2025-6170: Potential buffer overflows in the interactive shell (Closes: #1107938). * Fix CVE-2025-49794: Use-after-free issue in xmlSchematronReportOutput (Closes: #1107755). * Fix CVE-2025-49796: Type confusion issue in xmlSchematronReportOutput (Closes: #1107752). Checksums-Sha1: d6d1523030854536998a753c32ea3bd25e75875c 1869104 libxml2-dbgsym_2.9.14+dfsg-1.3~deb12u3_armhf.deb 8c3c50db401bd3d60c73a8bf74c5f6cb86d23a9a 709156 libxml2-dev_2.9.14+dfsg-1.3~deb12u3_armhf.deb c8c2cd551d886acba3d5e39a5d10d7fb21fe40f1 77256 libxml2-utils-dbgsym_2.9.14+dfsg-1.3~deb12u3_armhf.deb 04c4f716ddbe60d947086d206c20a93134433a2c 98016 libxml2-utils_2.9.14+dfsg-1.3~deb12u3_armhf.deb 881bd9d55d66f0a7c80988684aed513670bda064 9030 libxml2_2.9.14+dfsg-1.3~deb12u3_armhf-buildd.buildinfo 07ee8af07fb2ca10f16570be25a3aa66ea1bd5bb 591948 libxml2_2.9.14+dfsg-1.3~deb12u3_armhf.deb 1b384d85ad5c2448216410ed9ef9f7134a45ef10 244884 python3-libxml2-dbgsym_2.9.14+dfsg-1.3~deb12u3_armhf.deb 2fbf0cd7970c8cad9b1264481c76130fd649a1bd 178096 python3-libxml2_2.9.14+dfsg-1.3~deb12u3_armhf.deb Checksums-Sha256: b0f001df7ef9a557dcf104a5590c870c1994b2d5b2cc6ca0da29f5c844820b84 1869104 libxml2-dbgsym_2.9.14+dfsg-1.3~deb12u3_armhf.deb 91d1dde2777c443ddf4b37cdcb01a485867cef1796c371c50734d62ab387e294 709156 libxml2-dev_2.9.14+dfsg-1.3~deb12u3_armhf.deb a6132c8ce2c9aba17eac77c429d762781d4611a59cbee54e9ae2f956a47ec36d 77256 libxml2-utils-dbgsym_2.9.14+dfsg-1.3~deb12u3_armhf.deb a4b6c2c7b313b5dfadf3c653848ced5fedcd0cce83c535ff3d26afa7208b1879 98016 libxml2-utils_2.9.14+dfsg-1.3~deb12u3_armhf.deb 86de9e768251ce2db6bed7bd3ca9ca361358cd73bb55bd2fe59d75dd453de825 9030 libxml2_2.9.14+dfsg-1.3~deb12u3_armhf-buildd.buildinfo 32d5ba9874e8b06ae28a82ccb07525e9b54a24d7c788b831c77c68ff81843057 591948 libxml2_2.9.14+dfsg-1.3~deb12u3_armhf.deb db5c020c67690445e27ce21084b678ad3bfcfb08485d8f1ff358b424fa7920b9 244884 python3-libxml2-dbgsym_2.9.14+dfsg-1.3~deb12u3_armhf.deb ad7c65d36a20ec8fd11e8191bbea101f697b779361150868d4572a1c5ae3a37b 178096 python3-libxml2_2.9.14+dfsg-1.3~deb12u3_armhf.deb Files: 87c5784c9ccee850f779fe2ddd35cff3 1869104 debug optional libxml2-dbgsym_2.9.14+dfsg-1.3~deb12u3_armhf.deb 7fe6afda8dec328f6c55580d5902d7ae 709156 libdevel optional libxml2-dev_2.9.14+dfsg-1.3~deb12u3_armhf.deb 2d1c84b0195f481372b40acdb57c122d 77256 debug optional libxml2-utils-dbgsym_2.9.14+dfsg-1.3~deb12u3_armhf.deb b93b5354da35cded9e2a34625d303f02 98016 text optional libxml2-utils_2.9.14+dfsg-1.3~deb12u3_armhf.deb 8b4de899b7ceca4ee54785d8e3b7aa84 9030 libs optional libxml2_2.9.14+dfsg-1.3~deb12u3_armhf-buildd.buildinfo 742e9e9e4ab61b541f658cb49a722962 591948 libs optional libxml2_2.9.14+dfsg-1.3~deb12u3_armhf.deb a03e28509242af1464c1687e266295ca 244884 debug optional python3-libxml2-dbgsym_2.9.14+dfsg-1.3~deb12u3_armhf.deb 3d153de4dd773730eba692591fdea65c 178096 python optional python3-libxml2_2.9.14+dfsg-1.3~deb12u3_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEvEwFZ4bqkVI+Rh6t+N4VxR6LZYEFAmiH79cACgkQ+N4VxR6L ZYEPrw/+OzAOFTKvmIEifGIQ45RoOpEPC9FCQdQD0CSC10P4neFRw35ahKiWuIgg WACL+43vefi0kTKmCWUjQqzYxzzR3uRMWPVtWdOdA/Zpm1lAz3HDXOzNXdcBkbx2 JDXqWi2pETt8QynCMa9kc10EpywPTbbxJWrzNjGb0ANtwlvQt2RDxvSyqMb1bvO7 omwudn5rEWaC74haWBig1O4cU9o0OZtnf7Lfa4SoYoOuRFrC8NLdN+qn810Yruhp Flr5CJQVHbxQntZulgp90ZpaMd1eq+DmnAjUe6qh+HJiGU78razC84A3RbiSSTGy mxGLhqGQTIdu618f3PtN4ceDOS3DrFwI+G0CPI6buI1lIWCb7cswyma6lzDyz/FF FiaafE9wtgsjyqdWR3eelU1jpibYa5PbOB2sODN1ztkWAszA5ctCdeFJGmxgDOqL yYKdwodWynGH/9qmZgQINjGHiHk1DOVnICoqoE9oWR2m35mFjna2G7G29yCOGk+W 0UuhHOw/1wtDwLPZjExTvzWmI1hC17GKIF8Ngy11xkUKQ54n+uE7Q09ZY0lRdIMo PhWZO2Ap5/9K/B2bsnwy5sf4awL0Fw5gsgBIrR0iSBvr6WSI5on3VfsJWp5/spt5 UkDbSLKUoDICRvoRnJiAIAOdEjs9V03MVjRnOThGuHHYOQ0fE7Y= =gJMG -----END PGP SIGNATURE-----