-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 25 Aug 2025 19:38:04 +0800 Source: libxml2 Binary: libxml2 libxml2-dbgsym libxml2-dev libxml2-utils libxml2-utils-dbgsym python3-libxml2 python3-libxml2-dbgsym Architecture: armhf Version: 2.12.7+dfsg+really2.9.14-2.1+deb13u1 Distribution: trixie-security Urgency: high Maintainer: arm Build Daemon (arm-conova-01) Changed-By: Aron Xu Description: libxml2 - GNOME XML library libxml2-dev - GNOME XML library - development files libxml2-utils - GNOME XML library - utilities python3-libxml2 - GNOME XML library - Python3 bindings Closes: 1109122 Changes: libxml2 (2.12.7+dfsg+really2.9.14-2.1+deb13u1) trixie-security; urgency=high . * CVE-2025-7425: heap-use-after-free in xmlFreeID caused by `atype` corruption (Closes: #1109122) Checksums-Sha1: e73db9155fca55e86ae8d2685e2e18d18c708a16 1911316 libxml2-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf.deb a6e402656b1046fa2dc5e10b3ddfd05dc703116e 723048 libxml2-dev_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf.deb 336675dfe7704f57c6028c8752c2d09442d5da43 77400 libxml2-utils-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf.deb 9da3c64417cb940aa5652e1a8e74e1f2167e7726 99488 libxml2-utils_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf.deb 6e64e640b90d000aeef9932fdf0afc2609c298d8 9021 libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf-buildd.buildinfo bfd30248d702e8204430da601a782a11d44cc01c 604408 libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf.deb db97e8f97cb39e4ce89a36ec937f4fa04fba689e 254532 python3-libxml2-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf.deb dd97e1e7be67a9d195ad3f2a92a05d084b1ccba5 180304 python3-libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf.deb Checksums-Sha256: 86970158de5934ad74a74d3a7891c66a446edb3138fc855f8d426f869b951e75 1911316 libxml2-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf.deb a722eb09a631ad3574b01213693b76504017fbf6742fc0131e0557169855cf5a 723048 libxml2-dev_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf.deb 83fc5ec2f94f56c526d905bb17819106fbc083041ff6868e8fc7f9a9ef732c4f 77400 libxml2-utils-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf.deb b3bec2093c5a0e10ab7d02fdf71434a8b87fb969fcb92f0e5c19aea0b260670a 99488 libxml2-utils_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf.deb ce64a6da9861fdce5edc27f8aeed143c5dbe0e9c605af1a372851149f0bdf206 9021 libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf-buildd.buildinfo 9fc0686f5f30792badaf7a0c0cadad9dc43a1fc9a0015625befb70f86b33fa88 604408 libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf.deb 27bd9b66a399954cc8c543a1ad8366940166dcbdd0c2ad60fda2e4abc293f414 254532 python3-libxml2-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf.deb 2049b23bf1f98798c217f039d84aa10f6948a5954bddcab91ba84912267251cf 180304 python3-libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf.deb Files: d8ea8a0296890f2702841962bfcb0179 1911316 debug optional libxml2-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf.deb 0c3a3357197190e35d2f3db2958216a0 723048 libdevel optional libxml2-dev_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf.deb 774992960e6121f52a738e4ac58336ce 77400 debug optional libxml2-utils-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf.deb 626cae97de09a4779fce8e224f178804 99488 text optional libxml2-utils_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf.deb 774ef66d099b148500bd678038bd3675 9021 libs optional libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf-buildd.buildinfo 31203ac00ad9a522a245af40223664ad 604408 libs optional libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf.deb d26e062d81982996e5937979fde42249 254532 debug optional python3-libxml2-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf.deb a649cf210df8e56fc97287c8b030ae1e 180304 python optional python3-libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEegRwmIwj8f99iF4m4CwlMGxHD8UFAmisVJoACgkQ4CwlMGxH D8WrEw//RnwvYHiUPgKzPG5amU3EFMhQ2cGW5i8+iQ5rEncVmpsMacFrUCKHybdL BepfWPFVfIH14mu9OtuQLeDAJpMWj77NVV6gwTgN33Onm/2xVIyFebuNrIYDnYtj 5NZeacdplVuCYscL0dFSuwaAcsMTqIFNQcg+n8JvnqSm5LFh+86HMYJCvTQnGhmk 1pFerVhNnaqoi0h1lHdMNnjJIMN7sNpRHT25LimrV/jHCObrGM1HK+QKKy73xU8a i9aTQCFeScGg25mPicniitmEud5ZMLaugEkZU0UHLqeAtBJpKURZUdWuzK+hyv+6 pD1pem5tT8Krm6EOsYKI/F/IGaAjsNIoXh8MJq81eb0q+XiNRv3yiXS4jkIBTW0i n5yHev3a0CROvi/J3uoNh+8AuNfqx2tiz1ktQZNEFWkxYndAg9ooJ7TiC8NoipxW Nb75A9buuw0f4C0BytAAfMlQJ/8G1PtEBzmg1MwsgHE36eWRpDB7HWNYDyR4GkoR S1cCABm9hDh27ELmBQuQ2R+R++zOB+sIV1jlUz2Xhh9+VLhHFVJoNCGxR5HYk2HM Jjv5Tt8HZ792SNvoY2jf0/AkxytWbNfzxRIG07PXihNjdVrvN6OadoOgmBxzxztD x3Ry8F+Hlm63gUfy3ApGhkfCWqRxyL5Z5bpR6tLc8OWp93uYbZc= =f5dB -----END PGP SIGNATURE-----