]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core-contrib.git/commitdiff
libxml2: mark patch as fixing CVE-2025-27113
authorPeter Marko <peter.marko@siemens.com>
Fri, 28 Feb 2025 17:16:58 +0000 (18:16 +0100)
committerSteve Sakoman <steve@sakoman.com>
Mon, 3 Mar 2025 15:11:35 +0000 (07:11 -0800)
This vulnerability has now a CVE assigned.

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-core/libxml/libxml2/CVE-2025-27113.patch [moved from meta/recipes-core/libxml/libxml2/0001-pattern-Fix-compilation-of-explicit-child-axis.patch with 98% similarity]
meta/recipes-core/libxml/libxml2_2.9.14.bb

similarity index 98%
rename from meta/recipes-core/libxml/libxml2/0001-pattern-Fix-compilation-of-explicit-child-axis.patch
rename to meta/recipes-core/libxml/libxml2/CVE-2025-27113.patch
index 932c0ec4225c82b493b5b593b444d4fcfa44bb3c..92713375ebc5cc97f004d33a5a81bae732bb475f 100644 (file)
@@ -6,6 +6,7 @@ Subject: [PATCH] pattern: Fix compilation of explicit child axis
 The child axis is the default axis and should generate XML_OP_ELEM like
 the case without an axis.
 
+CVE: CVE-2025-27113
 Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/libxml2/-/commit/503f788e84f1c1f1d769c2c7258d77faee94b5a3]
 Signed-off-by: Peter Marko <peter.marko@siemens.com>
 ---
index 8f1d882505e4e06e0d41375304e9ae4e4dc5dc0f..1cbd620b3498b1dd250d343cec6462b245c8b470 100644 (file)
@@ -34,7 +34,7 @@ SRC_URI += "http://www.w3.org/XML/Test/xmlts20080827.tar;subdir=${BP};name=testt
            file://CVE-2024-25062.patch \
            file://CVE-2024-34459.patch \
            file://CVE-2022-49043.patch \
-           file://0001-pattern-Fix-compilation-of-explicit-child-axis.patch \
+           file://CVE-2025-27113.patch \
            file://CVE-2024-56171.patch \
            file://CVE-2025-24928.patch \
            "