Opened 7 months ago

Closed 7 months ago

#22905 closed enhancement (fixed)

libxml2-2.15.2

Reported by: Bruce Dubbs Owned by: Douglas R. Reno
Priority: elevated Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (3)

comment:1 by Xi Ruoyao, 7 months ago

Priority: normal → elevated

Security

  • CVE-2026-1757 fix: Memory leak in xmllint Shell - shell.c
  • CVE-2026-0990 fix: Prevent infinite recursion in xmlCatalogListXMLResolve
  • CVE-2026-0992 fix: Exponential behavior when handling
  • parser: Fix infinite loop in xmlCtxtParseContent
  • CVE-2025-10911 libxslt related: Ignore next/prev of documents when traversing XPath
  • CVE-2026-0989 fix: Add RelaxNG include limit
  • xmlIO: use size_t for buffer size reallocation
  • uri: fix signed integer overflow in xmlBuildRelativeURISafe
  • schematron: fix memory leaks on error paths in xmlSchematronParseRule
  • catalog: fix stack overflow from self-referencing SGML CATALOG entries

Improvements

  • fuzz: Make fuzzy encoding match more lenient
  • Fix C14N type confusion
  • meson: Fix build with Meson < 1.3
  • xmllint: Use zlib directly
  • xmllint: New option to separate xpath results using null, --xpath0
  • autotools: Make valgrind actually check for leaks
  • meson: Add valgrind test setup
  • Fix xmlOutputBufferGetContent output when encoder is set
  • threads: don't force _WIN32_WINNT to Vista if it's set to a higher value
  • dist: Add generated documentation to the dist as "dist-doc" folder to simplify downstream packaging of doc
  • Fix xmlRemoveEntity removing from wrong hash table
  • use duplicating variant in relaxng to mitigate UAF
  • Fix memory leak in xmlTextWriterStartAttributeNS on OOM
  • meson: remove hardcoded buildtype=debug default
  • Fix memory leak of prefix in xmlTextWriterStartElementNS()
  • writer: Add a few extra NULL checks to avoid memory leaks on corrupt writer path.

comment:2 by Douglas R. Reno, 7 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:3 by Douglas R. Reno, 7 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at 1bd2adaa26884b9c16fc6cad1f6bfa4cdcd5cb97

SA-13.0-005 issued.

Note: See TracTickets for help on using tickets.