Opened 6 months ago

Closed 5 months ago

#23157 closed enhancement (fixed)

libxml2-2.15.3

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: elevated Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (4)

comment:1 by Douglas R. Reno, 6 months ago

Priority: normal → elevated

comment:2 by Joe Locash, 6 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:3 by Joe Locash, 6 months ago

Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new
v2.15.3: Apr 15 2026

### Security

- parser: Pass userData to SAX text callbacks in xmlParseReference (type-confusion)
- entities: copy children in xmlCopyEntity
- c14n: Fix Type confusion in xmlC14NProcessAttrsAxis
- python: Do not decref string after adding to the list (double-free / use-after-free)
- c14n: Reuse tmp_str, xmlStrcat reallocates *cur (double-free)

### Improvements

- schemas: Fix relative schemaLocation resolution in XSI assembly in streaming mode
- xmlreader: propagate reader resource loaders to validator parsers
- python: Make python bindings python2 compatible
- xmlregexp: Fix escape-sequence character range matching
- xmlreader: Free input in xmlReaderForFd (memory-leak)
- xmlstring: Free cur on every error for xmlStrncat (memory-leak)
- catalog: Free xmlCatalogResolveCache on cleanup (memory leak)
- Fix nanohttp.c build when --without-output
- test: fix mismatched signed/unsigned comparison

Fixed at 80f414c7f1. Leaving open for SA.

comment:4 by Douglas R. Reno, 5 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-057 issued. It was really annoying that there were no CVEs for this one as it's hard to describe the impact of type confusion vulnerabilities without them. I generated what I could though with what I could find, I suspect it's part of the GNOME security team's ToDo list given that there are several libxml2 issues that were reported before this update was released but aren't available to the public according to ​https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home#libxml2

Note: See TracTickets for help on using tickets.