Re: [BLFS Trac] #23157: libxml2-2.15.3

"BLFS Trac" ([email protected] via blfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23157: libxml2-2.15.3
-------------------------+-------------------------------
 Reporter:  Bruce Dubbs  |       Owner:  SecurityAdvisory
     Type:  enhancement  |      Status:  new
 Priority:  elevated     |   Milestone:  13.1
Component:  BOOK         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+-------------------------------
Changes (by Joe Locash):

 * owner:  Joe Locash => SecurityAdvisory
 * status:  assigned => new

Comment:

 {{{
 v2.15.3: Apr 15 2026

 ### Security

 - parser: Pass userData to SAX text callbacks in xmlParseReference (type-
 confusion)
 - entities: copy children in xmlCopyEntity
 - c14n: Fix Type confusion in xmlC14NProcessAttrsAxis
 - python: Do not decref string after adding to the list (double-free /
 use-after-free)
 - c14n: Reuse tmp_str, xmlStrcat reallocates *cur (double-free)

 ### Improvements

 - schemas: Fix relative schemaLocation resolution in XSI assembly in
 streaming mode
 - xmlreader: propagate reader resource loaders to validator parsers
 - python: Make python bindings python2 compatible
 - xmlregexp: Fix escape-sequence character range matching
 - xmlreader: Free input in xmlReaderForFd (memory-leak)
 - xmlstring: Free cur on every error for xmlStrncat (memory-leak)
 - catalog: Free xmlCatalogResolveCache on cleanup (memory leak)
 - Fix nanohttp.c build when --without-output
 - test: fix mismatched signed/unsigned comparison
 }}}
 Fixed at 80f414c7f1. Leaving open for SA.
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23157#comment:3>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.