-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 25 Aug 2025 19:38:04 +0800 Source: libxml2 Binary: libxml2 libxml2-dbgsym libxml2-dev libxml2-utils libxml2-utils-dbgsym python3-libxml2 python3-libxml2-dbgsym Architecture: arm64 Version: 2.12.7+dfsg+really2.9.14-2.1+deb13u1 Distribution: trixie-security Urgency: high Maintainer: arm Build Daemon (arm-conova-01) Changed-By: Aron Xu Description: libxml2 - GNOME XML library libxml2-dev - GNOME XML library - development files libxml2-utils - GNOME XML library - utilities python3-libxml2 - GNOME XML library - Python3 bindings Closes: 1109122 Changes: libxml2 (2.12.7+dfsg+really2.9.14-2.1+deb13u1) trixie-security; urgency=high . * CVE-2025-7425: heap-use-after-free in xmlFreeID caused by `atype` corruption (Closes: #1109122) Checksums-Sha1: 3246d07dfb0c3c7ca5a2c1907a6c3427ae9213ac 1895348 libxml2-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64.deb 88d3cbb2d67b6c6fd1011da3ae1a6deeeb6576c5 751272 libxml2-dev_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64.deb 41bdc608adedf5b38304af2cc955d56e9bbeee13 80632 libxml2-utils-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64.deb 5d7024286f97baf62983d71a32121aae92989293 98768 libxml2-utils_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64.deb 432a8eb28cf1ae97155c8c4d677b46c94652ffc6 9142 libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64-buildd.buildinfo 0e19b12ad8685aabdd6c26baff8bed0cc5b5580a 631164 libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64.deb 4a5eea96a1bd0ca0fab5c27cd0bbb5dfca5c2a70 247428 python3-libxml2-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64.deb 9c9a3a11a06afe4885ec6379d06e08c766a9329c 185768 python3-libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64.deb Checksums-Sha256: e93297c320975d25516f674b59551b9971dc7f0a4234d073ea6366ed752254fb 1895348 libxml2-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64.deb 7c76f0859f71cad883b44975dc1c0b80424cfec0ea14c4052d4832b453b9788a 751272 libxml2-dev_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64.deb bc4d641276fb7aadbb090c1bbedf7c2200db9a725f8e0527e331017688b7cb06 80632 libxml2-utils-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64.deb 685440250e8ef04dd150286a07dff7a987055932b6d0c0329f768c1c4d432bac 98768 libxml2-utils_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64.deb e851386abf061bebec90117edb6cc0878bdc9332def6075eb8985d3288c37c0d 9142 libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64-buildd.buildinfo 32baac0386190ff9d0a3994dcb6c18048dff90b69fb0c10861add5efc6c7c8f5 631164 libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64.deb 7f5c57d1b3ddf86a1f5789a764e5b05facf3980068113c52fbf5d4cd9f70c3ab 247428 python3-libxml2-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64.deb 7e0a51f722197d8b9bd42fb5c8ad560ec2a6882274208726f605b54f8b821854 185768 python3-libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64.deb Files: c9d922c6e6189510d70cd6515bd3d38a 1895348 debug optional libxml2-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64.deb a9e7ae39cc911b5198437511777eed83 751272 libdevel optional libxml2-dev_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64.deb fe5f760df753e76834c7c303ddde19b8 80632 debug optional libxml2-utils-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64.deb 97cbb0bdd0c694acc05e4d48677d8f22 98768 text optional libxml2-utils_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64.deb ad71ba7ff3fe681c0901839c72256a80 9142 libs optional libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64-buildd.buildinfo 74613a97eb9dcca1a0ee89aa35169208 631164 libs optional libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64.deb a260fe589ecfc3a259b71031a9cef6bd 247428 debug optional python3-libxml2-dbgsym_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64.deb a5524cdccfbe4a59bda68949d253c993 185768 python optional python3-libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEegRwmIwj8f99iF4m4CwlMGxHD8UFAmisVaAACgkQ4CwlMGxH D8UTnBAAvtZkywx3RRsjICVhP12Qcgh0YyrpanYannKktUYZCQ5+T+ZWozG1azGp pu2vd5d15GsdB7PgAeJRqSbyV8Rj4CnoOFVTRLvIXB5/BJcqAeAaW+iM9MLCSpsH e1oRhLbHVWHyLvkNtH8upWicrOWcmYnP3Rca9W5xSTtwLO5Bgjlrf8PDxP7C3fiW e9NI10tAJz3MsSwtjiAa0MoI11syVT8PuMae4ierXCX93OKObsDwT1UIYk4gOqka en5vYw+LbWOX3ER9ni3xlJWpivokN+w/sb3izGBCAnjbdB/j4p0X6YuKlm9U4YCg DPTCojn/p0E2kKwcKtYuW75+X0/y9uWEDxy69FwNALPsE9FUfPc/QixWJL1NnEMF ffuBStQBZ6R9zyxeqapUOKoKX5cTMfPm8SI6+ZUsVQ2zpQtgFhDWhRy8CjAaxI+r 8JRPPUtvgVXY3dlOSNj882U6DCYb+J22zY+jz3K8AwFlpbY4TdPbxyIrci1lo49v IlB+1DdvqbRaJyJTp+nSMKc9NnFYaBCoCXxVnsTUCgY/ytkNdWpKIjTYbK2U67G/ z9MNfxldXaLP80r8yEzSuTYlivoyBClZwddMFMzQAQcn9g+ivNNXqPe9CFI8rPz+ gNEF22IirNY1ISum1H0++P3ippakA/P56Fe8HNnSrv62T6x0E8I= =AQh6 -----END PGP SIGNATURE-----