[xml/sgml-pkgs] libxml2_2.15.4+dfsg-1_source.changes ACCEPTED into unstable

Debian FTP Masters ftpmaster at ftp-master.debian.org
Sat Sep 5 19:34:31 BST 2026


Thank you for your contribution to Debian.



Accepted:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 06 Sep 2026 01:58:14 +0800
Source: libxml2
Architecture: source
Version: 2.15.4+dfsg-1
Distribution: unstable
Urgency: high
Maintainer: Debian XML/SGML Group <debian-xml-sgml-pkgs at lists.alioth.debian.org>
Changed-By: Aron Xu <aron at debian.org>
Closes: 1146744
Changes:
 libxml2 (2.15.4+dfsg-1) unstable; urgency=high
 .
   * New upstream bug fix release. Closes: #1146744.
     Security fixes:
     - CVE-2026-86137: xmlregexp: out-of-bounds read in the NXT macro
       (xmlFAParsePosCharGroup).
     - CVE-2026-86138: dict: integer overflow in xmlDictAddQString leading
       to a heap-based buffer overflow.
     - CVE-2026-86139: uri: integer overflow in xmlURIEscapeStr.
     - CVE-2026-86140: valid: stack-based buffer overflow through unchecked
       strcat in xmlSnprintfElements.
     - CVE-2026-86141: xmlregexp: NULL pointer dereference in
       xmlRegNewParserCtxt.
     - CVE-2026-86142: xpointer: heap-based buffer overflow in
       xmlXPtrEvalXPtrPart.
     - CVE-2026-86143: xmlIO: missing integer overflow check before calling
       the write callback.
     - CVE-2026-86144: xinclude: parse flags such as XML_PARSE_NONET were
       not propagated by xmlXIncludeProcess and xmlXIncludeProcessTree.
     - CVE-2026-11979: xmlcatalog: stack-based buffer overflows in --shell
       command handling.
   * d/control: bump Standards-Version to 4.7.4, no changes needed.
Checksums-Sha1:
 3f75c5cdec4a3777bec31c9af5feb52d725647ec 2738 libxml2_2.15.4+dfsg-1.dsc
 d5d2954d7e9e7f4501f6d96469a9c6475232e76a 2367580 libxml2_2.15.4+dfsg.orig.tar.xz
 99106d472c022fc3d0aa6a917900dcca3549ab4a 36420 libxml2_2.15.4+dfsg-1.debian.tar.xz
 b006ae929d73e1ee4793e4fc25d1eee03fb8369f 5904 libxml2_2.15.4+dfsg-1_source.buildinfo
Checksums-Sha256:
 430fa25d8bb4a31eaf3f314c40fe12a1d0ea19d15576d90c95490e79fcc1d5d1 2738 libxml2_2.15.4+dfsg-1.dsc
 5868d20db42ee21e4881bc53050c7fa226286a277cb3d0543f76b81f7571e934 2367580 libxml2_2.15.4+dfsg.orig.tar.xz
 a125823450895c0785596a6fce26931ab0a369c82da4d6cfa6bbdac782ed9010 36420 libxml2_2.15.4+dfsg-1.debian.tar.xz
 79deddde8b8d83a8d4dfb2e3f2d7bf6ae1a067dcaac88496cc6bde8dc48e1496 5904 libxml2_2.15.4+dfsg-1_source.buildinfo
Files:
 cbdf4a3815ac31cd5ec1b1dac11717eb 2738 libs optional libxml2_2.15.4+dfsg-1.dsc
 0a853c709c8a11e695f7e34e000aa0c2 2367580 libs optional libxml2_2.15.4+dfsg.orig.tar.xz
 dda75bd7e9a40bdd95173c914662548d 36420 libs optional libxml2_2.15.4+dfsg-1.debian.tar.xz
 2e007b227ff9676d03b0eee87f88861e 5904 libs optional libxml2_2.15.4+dfsg-1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEExq6D0hxncEPaPayX+GQ1dHE8m64FAmqcXLgACgkQ+GQ1dHE8
m65DCgf/UqWbYJpUcujM0us5rJFOTB+ezXYIF0CJB57bU/WCpX+WxRvdSYWv5A49
jCccGObWixHr4NoHZL/jYIwUXEv3/8l3sWJLpxcDP1K14PdjOzlmP8N6sddCOpzA
aKn27J9Xd7JN0UeVRkE6an0O/M6etwz5I7B40P7ibYD4UJAPVYKt38+lGIZGTecy
jAEh6et38QIQhpY8C8lZajQb1jJfcedqRMKqC3YHsCq/uAnKca0YXRk7lRw/AOR3
fiqDYyrn7lUoI2uoAYy4UjZvUZnbLiDVSz9pDlnJt3ycKzLBiiIVUAd3h5YdS4Au
kqkQ3zoysMh0xMCWWEcWx9Qxuxe8zw==
=64UA
-----END PGP SIGNATURE-----

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/debian-xml-sgml-pkgs/attachments/20260905/8adc9546/attachment.sig>


More information about the debian-xml-sgml-pkgs mailing list