-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 25 Aug 2025 19:38:04 +0800 Source: libxml2 Binary: libxml2 libxml2-dbgsym libxml2-dev libxml2-utils libxml2-utils-dbgsym python3-libxml2 python3-libxml2-dbgsym Architecture: i386 Version: 2.12.7+dfsg+really2.9.14-2.1+deb13u1 Distribution: trixie-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Aron Xu Description: libxml2 - GNOME XML library libxml2-dev - GNOME XML library - development files libxml2-utils - GNOME XML library - utilities python3-libxml2 - GNOME XML library - Python3 bindings Closes: 1109122 Changes: libxml2 (2.12.7+dfsg+really2.9.14-2.1+deb13u1) trixie-security; urgency=high . * CVE-2025-7425: heap-use-after-free in xmlFreeID caused by `atype` corruption (Closes: #1109122) Checksums-Sha1: 9fcc4a09cbf366aa568bf1518dd3f424c983e97f 1743272 libxml2-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386.deb dffef70a4706709cdf699f04c08a899d1823f327 856212 libxml2-dev_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386.deb 7d63458a1b504d3bb3c3b008d83b85b058b6e87c 71424 libxml2-utils-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386.deb f72e8e20385e6d583c60f515351d66582ab84eb0 100472 libxml2-utils_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386.deb 9a48830995266b70e5f2c49a1b9ecc3fde50577a 9044 libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386-buildd.buildinfo f9df6247253958b2f80999bfacef638417c8dbd3 733128 libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386.deb d291b25f3757f37f85e5881e02b356a462d0405c 187684 python3-libxml2-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386.deb 0b4592d07e546a8d8cd437cae423be651bd95b60 190204 python3-libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386.deb Checksums-Sha256: 13f1dc4cb7add16b58114cf6336253b050a52ae3da74f7a8e9d0e41c29efd880 1743272 libxml2-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386.deb c33680db0dad6c21099680c604ba42e7e57695ce6d0e55090c75335bfa87a2da 856212 libxml2-dev_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386.deb cc6545a9a0db866a058ab112c32c09393b0a12745d3f30f3b14eda4d59e54989 71424 libxml2-utils-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386.deb e8a4eff618faf1a8051c827ce23a5bcf092a38559a2ae126295d8820418949ed 100472 libxml2-utils_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386.deb 6cab6873515af1a390c9e4d19363264ca1a32c20a8f57f30ed636bbd71ae36da 9044 libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386-buildd.buildinfo 1e5865a5d72fb7855cf5582f1ebb141390f4e078d972ffacb7b0f3302e465d1d 733128 libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386.deb 7b1a2b694949ae11c0ad0fcfec70b1711103c5b89a6a0d1971848fb371a31ca9 187684 python3-libxml2-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386.deb 0e7d59561e61319021936821aed45f3f9f2fe428cb59eef4c100968a25a00a32 190204 python3-libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386.deb Files: 3181163f7e53b66c2ed4718dec8d3032 1743272 debug optional libxml2-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386.deb f3ac239f0bdfee25ed69ce06634a4a9c 856212 libdevel optional libxml2-dev_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386.deb 1d67aa446a8c755f196dd2d786147cfb 71424 debug optional libxml2-utils-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386.deb 22ee93475232440d2af5f6eedd5e51d8 100472 text optional libxml2-utils_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386.deb efa3897c377dec204615593b9f7fc460 9044 libs optional libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386-buildd.buildinfo 4aa3e7b630a9bcc76ecddab62dbbb7b1 733128 libs optional libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386.deb b2837d89f3359847f09bfd148dbd39e4 187684 debug optional python3-libxml2-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386.deb eca0573391ebda16392f1d818bd4b295 190204 python optional python3-libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEnw0rdzqckKx6dwRTEbCLukZn24oFAmisUr4ACgkQEbCLukZn 24pttQ//UBax16B16X4cgKogLA3FQtouSOZP/u3AVT10kB0vk/YYe5VVAc/OnCDs 2+ESgN8pBKj/3ICO8AZGUqK5FrOUS0ZqX0ehsm3bstY5MXvwWT++51pQs2bjk969 8J4qvuD4qKiqD+r24dgXr2z59XQIknni1DIkPzkuqKjMvnaW1hh/6I8NbFgh5PfU PWZKzPC5EkqvmHy7Hd62c8tKvMRIltFDzb1kSaTVhqPoY6G+ovMtd4OEZ8ir50xq zeVkll7lbmJsKMd8nWUmn8wVTdHMdys9p5Q1xFGd/OObfDQDRJJFiEKvrGP++jyM 6lonaZ9ROcCdkxWFf79sEeATWzfmNXyaMmaCbgYpabHvnWn9haCyGI9Z2Ji+cDro fkj+SOyIoyB2jbd9fOFWchk8xYo40B/FFuUuAlbL6J07hlqx/JFGzCOilgUp+TmU dM618U0vgPaeanFKk1LeyJYpa9CeuRrwDlkOmloD038FVfp4fPny5rQlqzQDTHM8 zY3bYCV0cZRpxI1VPIaK7vWUXOeQuKp/mpdE4Cs/MlpGxVUwdfiS/nSSmokTosiG O9zk39o2gY/pwGk2GIU8xLsPfhIsSM5KMTmmMu/YtJRrKLuPbMGft61U+sgVfnxU WklGZzoWdU1KZG/rn4xVBWtSyrupfy3DnahLiPVKeNbmycXy3y4= =cOVy -----END PGP SIGNATURE-----