• Bug#1110152: unblock: libxml2/2.12.7+dfsg+really2.9.14-2.1

    From Adrian Bunk@21:1/5 to All on Wed Jul 30 23:00:01 2025
    XPost: linux.debian.bugs.dist

    This is a multi-part MIME message sent by reportbug.


    Package: release.debian.org
    Severity: normal
    X-Debbugs-Cc: [email protected], Guilhem Moulin <[email protected]> Control: affects -1 + src:libxml2
    User: [email protected]
    Usertags: unblock

    Please unblock package libxml2

    CVE-2025-6170 fix, already accepted into bookworm-pu in #1109947.

    unblock libxml2/2.12.7+dfsg+really2.9.14-2.1

    diffstat for libxml2-2.12.7+dfsg+really2.9.14 libxml2-2.12.7+dfsg+really2.9.14

    changelog | 8 +++
    patches/CVE-2025-6170.patch | 100 ++++++++++++++++++++++++++++++++++++++++++++
    patches/series | 1
    3 files changed, 109 insertions(+)

    diff -Nru libxml2-2.12.7+dfsg+really2.9.14/debian/changelog libxml2-2.12.7+dfsg+really2.9.14/debian/changelog
    --- libxml2-2.12.7+dfsg+really2.9.14/debian/changelog 2025-07-17 18:09:57.000000000 +0300
    +++ libxml2-2.12.7+dfsg+really2.9.14/debian/changelog 2025-07-27 01:59:51.000000000 +0300
    @@ -1,3 +1,11 @@
    +libxml2 (2.12.7+dfsg+really2.9.14-2.1) unstable; urgency=medium
    +
    + * Non-maintainer upload.
    + * Fix CVE-2025-6170: Potential buffer overflows in the interactive shell
    + (Closes: #1107938).
    +
    + -- Guilhem Moulin <[email protected]> Sun, 27 Jul 2025 00:59:51 +0200
    +
    libxml2 (2.12.7+dfsg+really2.9.14-2) unstable; urgency=medium

    * Security fixes:
    diff -Nru libxml2-2.12.7+dfsg+really2.9.14/debian/patches/CVE-2025-6170.patch libxml2-2.12.7+dfsg+really2.9.14/debian/patches/CVE-2025-6170.patch
    --- libxml2-2.12.7+dfsg+really2.9.14/debian/patches/CVE-2025-6170.patch 1970-01-01 02:00:00.000000000 +0200
    +++ libxml2-2.12.7+dfsg+really2.9.14/debian/patches/CVE-2025-6170.patch 2025-07-27 01:59:51.000000000 +0300
    @@ -0,0 +1,100 @@
    +From: Michael Mann <[email protected]>
    +Date: Fri, 20 Jun 2025 23
  • From Debian Bug Tracking System@21:1/5 to All on Wed Jul 30 23:00:02 2025
    Processing control commands:

    affects -1 + src:libxml2
    Bug #1110152 [release.debian.org] unblock: libxml2/2.12.7+dfsg+really2.9.14-2.1 Added indication that 1110152 affects src:libxml2

    --
    1110152: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1110152
    Debian Bug Tracking System
    Contact [email protected] with problems

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Debian Bug Tracking System@21:1/5 to All on Wed Jul 30 23:10:01 2025
    This is a multi-part message in MIME format...

    Your message dated Wed, 30 Jul 2025 21:02:56 +0000
    with message-id <[email protected]>
    and subject line unblock libxml2
    has caused the Debian Bug report #1110152,
    regarding unblock: libxml2/2.12.7+dfsg+really2.9.14-2.1
    to be marked as done.

    This means that you claim that the problem has been dealt with.
    If this is not the case it is now your responsibility to reopen the
    Bug report if necessary, and/or fix the problem forthwith.

    (NB: If you are a system administrator and have no idea what this
    message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact [email protected]
    immediately.)


    --
    1110152: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1110152
    Debian Bug Tracking System
    Contact [email protected] with problems

    Received: (at submit) by bugs.debian.org; 30 Jul 2025 20:53:20 +0000 X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
    (2024-03-25) on buxtehude.debian.org
    X-Spam-Level:
    X-Spam-Status: No, score=-131.1 required=4.0 tests=BAYES_00,
    BODY_INCLUDES_CONTROL_AFFECTS,BODY_INCLUDES_PACKAGE,DKIMWL_WL_HIGH,
    DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FOURLA,
    FROMDEVELOPER,HAS_PACKAGE,MD5_SHA1_SUM,SPF_HELO_NONE,SPF_NONE,
    UNPARSEABLE_RELAY,USER_IN_DKIM_WELCOMELIST,XMAILER_REPORTBUG
    autolearn=ham autolearn_force=no
    version=4.0.1-bugs.debian.org_2005_01_02
    X-Spam-Bayes: score:0.0000 Tokens: new, 11; hammy, 150; neutral, 256; spammy,
    0. spammytokens:
    hammytokens:0.000-+--Hx-spam-relays-external:sk:stravin,
    0.000-+--H*RT:sk:stravin, 0.000-+--Hx-spam-relays-external:311,
    0.000-+--H*RT:311, 0.000-+--H*RT:108
    Return-path: <bunk@d