-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 23 Sep 2025 12:48:41 +0200 Source: libxml2 Architecture: source Version: 2.9.10+dfsg-6.7+deb11u9 Distribution: bullseye-security Urgency: high Maintainer: Debian XML/SGML Group <debian-xml-sgml-pkgs@lists.alioth.debian.org> Changed-By: Guilhem Moulin <guilhem@debian.org> Closes: 1109122 Changes: libxml2 (2.9.10+dfsg-6.7+deb11u9) bullseye-security; urgency=high . * Non-maintainer upload by the LTS Team. * Mitigate CVE-2025-7425/libxslt: Heap-use-after-free in xmlFreeID() caused by `atype` corruption. (Closes: #1109122) * Fix CVE-2025-9714: Stack overflow via crafted expressions. Checksums-Sha1: 68bbdba88d5992b517008d688edec71c22142157 2704 libxml2_2.9.10+dfsg-6.7+deb11u9.dsc 256b9b8e9b82ee5a731bb345d5637ecc113d4b43 57008 libxml2_2.9.10+dfsg-6.7+deb11u9.debian.tar.xz 5c02f1a218c2dd9b6a85b3a5d68a91ed840ddfd6 9847 libxml2_2.9.10+dfsg-6.7+deb11u9_amd64.buildinfo Checksums-Sha256: 11dea507a5f3732b61d5e3be54619ca5de2833508125b5e2f51ccd705ef0f1e5 2704 libxml2_2.9.10+dfsg-6.7+deb11u9.dsc 627bb24321c2343ba2fc73f1e1cbde42b975d1c27b5fabb0282bf101274889e2 57008 libxml2_2.9.10+dfsg-6.7+deb11u9.debian.tar.xz 5c143cb7d781749960e4ed703020e6794aa112187935926678791dff753c0231 9847 libxml2_2.9.10+dfsg-6.7+deb11u9_amd64.buildinfo Files: 8cfa3605bff1700f0ea146f0470e4a04 2704 libs optional libxml2_2.9.10+dfsg-6.7+deb11u9.dsc c8ff651c89391d08c87a3b96af0049f7 57008 libs optional libxml2_2.9.10+dfsg-6.7+deb11u9.debian.tar.xz 38fae8b5b7d7318382cf70d297dbe720 9847 libs optional libxml2_2.9.10+dfsg-6.7+deb11u9_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmjbli0ACgkQ05pJnDwh pVLNgA/+P097uJh3tFakanxSyV9UHVFVRDKM0S4Bq755XDuu/OFvB2bJCd5f27bu NgM+5UnyZDToosk7cGflsasYwv5CVNcmv2XrXefGvY9I4OjKxpgqbppovvQJPcE6 p6JA1PA/JncrgktJZx1zSuMWKpi3QTg+TqxVP8F/BVfEAzE1e3DLzjf4UAkQaIyY M3vOsaH5htobdSd7vzwbyaZHwGDJzVDCCFGPid9CmZ6Gku6DBNdgoC/ODZHQzXru 3LQnsYv9ujw9UZCOrZafRABDLJ51snMiMXvdKqziwOIEwTPs9hOk/dMwmPxnomaY tE9Tc3eBLlyky0kc7K8GA3EcpRnrd+Rl9ybL+NvYG1T5HSydVMp0uzRQbqvDwqZB wA8qzrpvbdfZOX5S/Nzab7N/AC0a+MUwmKwFEngz7kbo1dIOcCYFEHYgU4XhwwUu jCpUM2s/CfbIoGLm9Ppn1O7ToG6ll1GgUBoLKFua3OnyaMHFdMV/irY0Gh3IQwKt 695PkvLs1Xt08r382WSGujoxNWeyJN5SNfIIrHdlnTlki81d7ZxpIHbzwfp+IkY9 uZrLDgP0zAvKiOtBQVp05sjl3gO8/qQqBiAYoTJr8T0SijZx/kYejgRw3iDHXI0D GIgqv4SUiERooUejf9mooiFQgTQftcMbo/xvvZ6wA/m+Dqszk+0= =3hNs -----END PGP SIGNATURE-----