Release date:
2026-09-29 19:15:57 UTC
Description:
* SECURITY UPDATE: double free in the Python SAX attributeDecl callback
- debian/patches/CVE-2026-74860.patch: drop the extra Py_DECREF() on
each enumeration value string in pythonAttributeDecl(), since
PyList_SetItem() already steals that reference, so a DTD with an
enumerated attribute no longer frees the strings twice
- CVE-2026-74860
* debian/rules: run the C regression programs (runtest, testapi,
testrecurse, testcatalog, testchar, testdict) and the Python binding
tests in the arch build; skip only the cases whose data the +dfsg
tarball does not ship (runxmlconf, runtest's threads group, reader5.py)
Updated packages:
-
libxml2_2.9.10+dfsg-6.7+deb11u10+tuxcare.els3_amd64.deb
sha:f96574f8cea893a0f04a133502de759e54486b7c
-
libxml2-dev_2.9.10+dfsg-6.7+deb11u10+tuxcare.els3_amd64.deb
sha:870fd81a05c37c1f242491469ecfca156954dfad
-
libxml2-doc_2.9.10+dfsg-6.7+deb11u10+tuxcare.els3_all.deb
sha:f65938358ed9afcb5276fe8eb865c4380b54c98e
-
libxml2-utils_2.9.10+dfsg-6.7+deb11u10+tuxcare.els3_amd64.deb
sha:5efc71621f46c71cf3f402896068ef6c2a0ae292
-
python3-libxml2_2.9.10+dfsg-6.7+deb11u10+tuxcare.els3_amd64.deb
sha:e7af9b57ebf85b260b0073829e5ec6b09c71b03e
-
libxml2_2.9.10+dfsg-6.7+deb11u10+tuxcare.els3_arm64.deb
sha:5dc143e1ea5021c0213843e4f252853e31dd777e
-
libxml2-dev_2.9.10+dfsg-6.7+deb11u10+tuxcare.els3_arm64.deb
sha:041e25d4d938579346844882977a7c855b31f38c
-
libxml2-utils_2.9.10+dfsg-6.7+deb11u10+tuxcare.els3_arm64.deb
sha:d14cdc660b4196120ff53406c8c9ba2f7efcade2
-
python3-libxml2_2.9.10+dfsg-6.7+deb11u10+tuxcare.els3_arm64.deb
sha:0327d24f3ba6c697ed869fc58ec3a0cbf2ae80d4
-
libxml2_2.9.10+dfsg-6.7+deb11u10+tuxcare.els3_armel.deb
sha:f35723e633199cab1eee4b5f322831b21073e9c2
-
libxml2-dev_2.9.10+dfsg-6.7+deb11u10+tuxcare.els3_armel.deb
sha:15d079178198188522f78e49cbbecd134f1c03d7
-
libxml2-utils_2.9.10+dfsg-6.7+deb11u10+tuxcare.els3_armel.deb
sha:0db919996790f0d5a91e841d5b5c8fdc2833eba1
-
python3-libxml2_2.9.10+dfsg-6.7+deb11u10+tuxcare.els3_armel.deb
sha:47fa6488c43020bb70cb8c765e5faaffdd9232f6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.