Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package libxml2 for openSUSE:Factory checked 
in at 2026-09-08 16:53:12
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/libxml2 (Old)
 and      /work/SRC/openSUSE:Factory/.libxml2.new.1265 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "libxml2"

Tue Sep  8 16:53:12 2026 rev:144 rq:1376040 version:2.15.4

Changes:
--------
--- /work/SRC/openSUSE:Factory/libxml2/libxml2.changes  2026-07-12 
16:19:45.161125658 +0200
+++ /work/SRC/openSUSE:Factory/.libxml2.new.1265/libxml2.changes        
2026-09-08 16:53:42.371930507 +0200
@@ -1,0 +2,30 @@
+Fri Sep  4 18:58:36 UTC 2026 - Bjørn Lie <[email protected]>
+
+- Update to version 2.15.4:
+  + Security:
+    - xmlregexp: Prevent out-of-bounds read in NXT macro
+    - fix: add missing overflow checks in dict.c, uri.c, and
+      valid.c
+    - xmlregexp: Calc string length after null checking
+    - xpointer: Check overflow in xmlXPtrEvalXPtrPart
+    - xmlIO: Check for int overflow before calling writecallback
+    - fix(xinclude): propagate parseFlags in xmlXIncludeProcess and
+      xmlXIncludeProcessTree
+  + Improvements:
+    - Improve bound checks for xmlcatalog and xmllint arguments
+      (out-of-bound)
+    - Fix memory leak in static Windows library (memory-leak)
+    - xmlreader: Copy DTD in xmlTextReaderDumpCopy
+    - parser: Fix double free in xmlIOParseDTD (double-free)
+    - parser: fix division-by-zero when maxAmpl is set to 0
+    - parser: Fix memory leak in xmlCtxtSetSaxHandler (memory-leak)
+    - catalog: Make sure to reset catalog resolve cache
+    - xmlAddChild: unlink node before free for text nodes
+      (memory-leak)
+    - Normalize entity values in attr in xmlNodeGetContent
+    - Handle whitespace for date/time/duration types
+    - catalog: Fix NULL deref for nextCatalog without 'catalog'
+      attribute (null-deref)
+- Drop libxml2-CVE-2026-11979.patch: Fixed upstream.
+
+-------------------------------------------------------------------

Old:
----
  libxml2-2.15.3.tar.xz
  libxml2-CVE-2026-11979.patch

New:
----
  libxml2-2.15.4.tar.xz

----------(Old B)----------
  Old:      attribute (null-deref)
- Drop libxml2-CVE-2026-11979.patch: Fixed upstream.
----------(Old E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ libxml2.spec ++++++
--- /var/tmp/diff_new_pack.vvru8O/_old  2026-09-08 16:53:43.105961302 +0200
+++ /var/tmp/diff_new_pack.vvru8O/_new  2026-09-08 16:53:43.107961386 +0200
@@ -19,7 +19,7 @@
 
 %define libname    libxml2-16
 Name:           libxml2
-Version:        2.15.3
+Version:        2.15.4
 Release:        0
 Summary:        A Library to Manipulate XML Files
 License:        MIT
@@ -28,9 +28,7 @@
 Source1:        baselibs.conf
 # W3C Conformance tests
 Source2:        https://www.w3.org/XML/Test/xmlts20080827.tar.gz
-# CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility 
when running in `--shell` mode (bsc#1269790)
-# - 
https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503
-Patch0:         libxml2-CVE-2026-11979.patch
+
 BuildRequires:  fdupes
 BuildRequires:  pkgconfig
 %if 0%{?suse_version} >= 1600

++++++ libxml2-2.15.3.tar.xz -> libxml2-2.15.4.tar.xz ++++++
++++ 147030 lines of diff (skipped)

Reply via email to