Marked for autoremoval on 30 November due to rst2pdf: #1118331high
Version 4.6.3-1 of libxmp is marked for autoremoval from testing on Sun 30 Nov 2025. It depends (transitively) on rst2pdf, affected by #1118331. You should try to prevent the removal by fixing these RC bugs.
1 issue left for the package maintainer to handle:
CVE-2025-47256:
(needs triaging)
Libxmp through 4.6.2 has a stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha format tracker module in a .mod file.
Among the 2 debian patches
available in version 4.6.3-1 of the package,
we noticed the following issues:
1 patch
where the metadata indicates that the patch has not yet been forwarded
upstream. You should either forward the patch upstream or update the
metadata to document its real status.