-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 25 Aug 2025 19:30:10 +0800 Source: libxml2 Binary: libxml2 libxml2-dbgsym libxml2-dev libxml2-utils libxml2-utils-dbgsym python3-libxml2 python3-libxml2-dbgsym Architecture: amd64 Version: 2.9.14+dfsg-1.3~deb12u4 Distribution: bookworm-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-02) Changed-By: Aron Xu Description: libxml2 - GNOME XML library libxml2-dev - GNOME XML library - development files libxml2-utils - GNOME XML library - utilities python3-libxml2 - GNOME XML library - Python3 bindings Closes: 1109122 Changes: libxml2 (2.9.14+dfsg-1.3~deb12u4) bookworm-security; urgency=high . * CVE-2025-7425: heap-use-after-free in xmlFreeID caused by `atype` corruption (Closes: #1109122) Checksums-Sha1: ac6ecfa8b810399acd26090e86b88227cedabf65 1865732 libxml2-dbgsym_2.9.14+dfsg-1.3~deb12u4_amd64.deb 327231f0e8fb6c4911a8860d3d09d8762ac70e28 782332 libxml2-dev_2.9.14+dfsg-1.3~deb12u4_amd64.deb 2feeffa8ec36f36c1fcaabfdc9c8f70ca3a028e4 77236 libxml2-utils-dbgsym_2.9.14+dfsg-1.3~deb12u4_amd64.deb 9bfdd926da1a84be04beb1c5894332ce6133a66d 99488 libxml2-utils_2.9.14+dfsg-1.3~deb12u4_amd64.deb 795289bcc0d14e52f403d2b9eb23fbd1887eed53 9187 libxml2_2.9.14+dfsg-1.3~deb12u4_amd64-buildd.buildinfo 73d9b287566e6cde666e7edbea1771e0d01246ac 687316 libxml2_2.9.14+dfsg-1.3~deb12u4_amd64.deb f01f55c3ba1816ccf38d03fe2da5656675ea6359 220640 python3-libxml2-dbgsym_2.9.14+dfsg-1.3~deb12u4_amd64.deb 909ba61efface07a228a3d4692ef28fd83016759 188104 python3-libxml2_2.9.14+dfsg-1.3~deb12u4_amd64.deb Checksums-Sha256: 3063a7821509cd9e791a537589b39eef911b9ce737d26c3342bc1ce4181c84cc 1865732 libxml2-dbgsym_2.9.14+dfsg-1.3~deb12u4_amd64.deb 16e787b3611409a7f48da1e4f152842e9bf5c168b311d882cf3719cc6572e11d 782332 libxml2-dev_2.9.14+dfsg-1.3~deb12u4_amd64.deb f50b1468b73946bcd72bc30209b7eef8d094c5960b641b6f11e8977180a2b937 77236 libxml2-utils-dbgsym_2.9.14+dfsg-1.3~deb12u4_amd64.deb 4a176c9f16934a3549b60afa958f6a7c17fc8e2f86889968c4a6f2c3eee0fed0 99488 libxml2-utils_2.9.14+dfsg-1.3~deb12u4_amd64.deb ee822ae82f6058b6291160f92485f819ba0e3e2d2f981c9ff7c9138cc2f03a0a 9187 libxml2_2.9.14+dfsg-1.3~deb12u4_amd64-buildd.buildinfo f3bac32a5f7d32990af06713eef57664a66e98c13750fa8e007c9cbaf49b98c7 687316 libxml2_2.9.14+dfsg-1.3~deb12u4_amd64.deb 74c18690773866c9468a416f979be6bddbf4f02088c6f1dbd5d7bc782a2edfe8 220640 python3-libxml2-dbgsym_2.9.14+dfsg-1.3~deb12u4_amd64.deb 4f65e135c059c0399d1ac9108ef668ff2af8b3bc2c30605f42e54038d2faa0b4 188104 python3-libxml2_2.9.14+dfsg-1.3~deb12u4_amd64.deb Files: 44e9256d7e0b12fbd4c1a13597662c50 1865732 debug optional libxml2-dbgsym_2.9.14+dfsg-1.3~deb12u4_amd64.deb aaac7845ec7a8c6c73bb8c6b9cbfde2d 782332 libdevel optional libxml2-dev_2.9.14+dfsg-1.3~deb12u4_amd64.deb 62b60f72f563a6691dc25048f980a587 77236 debug optional libxml2-utils-dbgsym_2.9.14+dfsg-1.3~deb12u4_amd64.deb a3791f62f4848e19eb84c8d831353944 99488 text optional libxml2-utils_2.9.14+dfsg-1.3~deb12u4_amd64.deb 7a748bd3d80e2f5bf0e75b9e5a6b1af9 9187 libs optional libxml2_2.9.14+dfsg-1.3~deb12u4_amd64-buildd.buildinfo 0023e42644b222313de2250cfd291871 687316 libs optional libxml2_2.9.14+dfsg-1.3~deb12u4_amd64.deb 8114fa269eecede24e3c52c27ead0b84 220640 debug optional python3-libxml2-dbgsym_2.9.14+dfsg-1.3~deb12u4_amd64.deb 7bd6d95bcce45ef5de462d572c7d43a6 188104 python optional python3-libxml2_2.9.14+dfsg-1.3~deb12u4_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEc5vuvf2HND40bnI+8IREj/cRiTMFAmisT8wACgkQ8IREj/cR iTP6PQ//TCNwVRR9eu4ASUZuk4EHiQ6TFMYws6WO/J1dZPBUle4Fv2gW3xVaQQr6 NQXVyRg8dtL+h/JyS9RUDyVkKsAD98esHtpEkOWkbqtL/wZT+8VJLrxCUjSvaAxF Gdd5SoNEpWVXXHXSZgglAqulfJN/3P4pbnX4APMElYkxV7wjNmemsYIL/oj+X4DI vGdMRZZc6tvH16/NzQXmyElG8Acxz59Uzh4JY4MS+puNCqWAjbqZ4pFEJmgptfwU icgvZHVSP7tlCQYgqA74h3tEMQG8xVIFNM3W9Cl6KGIYZzuj4PI14OPnonR1sVnc IVBovzTeDhAtczb8PiAJF0X1a4AgfMV/6aLe1A7Uw+/4YOFhVVVRioANes5sk5cE 2nb1SU30Hq5alEtqBnCFaqcs4u8BCa4A2ejU9Dmx634tZXp8TAf5/dYlTlwRCxBd 9zelnGOvDiYBjLsSm55DkEZYJ+DrgorMKiWw5qra9Bfr5ORpDzXLYCHGx0BCU+nX 8bOmAWZmmNxmgCuUd/1h00IuZzGjaa1LSJMqs8OIbvDKP0uZUTiIGxEstxL+OEGk S2gEFxnztDRPbi95RTBLcBBmKybLaihsfiVgayvQ85ye39x+VeURCtBenSiAL7Sb 9yi6HFO8ObPuYECK2WSepunb399ngzm7EON5RjLCbVJYhu3Qmt8= =Pd2k -----END PGP SIGNATURE-----