]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
libxml2: Security fix for CVE-2025-7425
authorHitendra Prajapati <hprajapati@mvista.com>
Thu, 4 Dec 2025 12:53:54 +0000 (18:23 +0530)
committerSteve Sakoman <steve@sakoman.com>
Mon, 8 Dec 2025 14:43:27 +0000 (06:43 -0800)
commitcf260bef4495186662b74b8324d01efcfc2121fd
tree5df717913f5321342a15955d506034a78d1f171e
parent80c7fd87fd95a79c6eb5f41b95cf70ccc70d9615
libxml2: Security fix for CVE-2025-7425

CVE-2025-7425
libxslt: heap-use-after-free in xmlFreeID caused by `atype` corruption

Origin: https://launchpad.net/ubuntu/+source/libxml2/2.9.14+dfsg-1.3ubuntu3.6
Ref : https://security-tracker.debian.org/tracker/CVE-2025-7425

Upstream-Status: Backport from https://gitlab.gnome.org/GNOME/libxslt/-/issues/140
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-core/libxml/libxml2/CVE-2025-7425.patch [new file with mode: 0644]
meta/recipes-core/libxml/libxml2_2.9.14.bb