Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package libxml2 for openSUSE:Factory checked in at 2026-09-08 16:53:12 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/libxml2 (Old) and /work/SRC/openSUSE:Factory/.libxml2.new.1265 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "libxml2" Tue Sep 8 16:53:12 2026 rev:144 rq:1376040 version:2.15.4 Changes: -------- --- /work/SRC/openSUSE:Factory/libxml2/libxml2.changes 2026-07-12 16:19:45.161125658 +0200 +++ /work/SRC/openSUSE:Factory/.libxml2.new.1265/libxml2.changes 2026-09-08 16:53:42.371930507 +0200 @@ -1,0 +2,30 @@ +Fri Sep 4 18:58:36 UTC 2026 - Bjørn Lie <[email protected]> + +- Update to version 2.15.4: + + Security: + - xmlregexp: Prevent out-of-bounds read in NXT macro + - fix: add missing overflow checks in dict.c, uri.c, and + valid.c + - xmlregexp: Calc string length after null checking + - xpointer: Check overflow in xmlXPtrEvalXPtrPart + - xmlIO: Check for int overflow before calling writecallback + - fix(xinclude): propagate parseFlags in xmlXIncludeProcess and + xmlXIncludeProcessTree + + Improvements: + - Improve bound checks for xmlcatalog and xmllint arguments + (out-of-bound) + - Fix memory leak in static Windows library (memory-leak) + - xmlreader: Copy DTD in xmlTextReaderDumpCopy + - parser: Fix double free in xmlIOParseDTD (double-free) + - parser: fix division-by-zero when maxAmpl is set to 0 + - parser: Fix memory leak in xmlCtxtSetSaxHandler (memory-leak) + - catalog: Make sure to reset catalog resolve cache + - xmlAddChild: unlink node before free for text nodes + (memory-leak) + - Normalize entity values in attr in xmlNodeGetContent + - Handle whitespace for date/time/duration types + - catalog: Fix NULL deref for nextCatalog without 'catalog' + attribute (null-deref) +- Drop libxml2-CVE-2026-11979.patch: Fixed upstream. + +------------------------------------------------------------------- Old: ---- libxml2-2.15.3.tar.xz libxml2-CVE-2026-11979.patch New: ---- libxml2-2.15.4.tar.xz ----------(Old B)---------- Old: attribute (null-deref) - Drop libxml2-CVE-2026-11979.patch: Fixed upstream. ----------(Old E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ libxml2.spec ++++++ --- /var/tmp/diff_new_pack.vvru8O/_old 2026-09-08 16:53:43.105961302 +0200 +++ /var/tmp/diff_new_pack.vvru8O/_new 2026-09-08 16:53:43.107961386 +0200 @@ -19,7 +19,7 @@ %define libname libxml2-16 Name: libxml2 -Version: 2.15.3 +Version: 2.15.4 Release: 0 Summary: A Library to Manipulate XML Files License: MIT @@ -28,9 +28,7 @@ Source1: baselibs.conf # W3C Conformance tests Source2: https://www.w3.org/XML/Test/xmlts20080827.tar.gz -# CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790) -# - https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503 -Patch0: libxml2-CVE-2026-11979.patch + BuildRequires: fdupes BuildRequires: pkgconfig %if 0%{?suse_version} >= 1600 ++++++ libxml2-2.15.3.tar.xz -> libxml2-2.15.4.tar.xz ++++++ ++++ 147030 lines of diff (skipped)
