alt-libxml2 (2.10.2-5) stable; urgency=medium

  * SECURITY UPDATE: use-after-free after xmlSchemaItemListAdd
    - debian/patches/libxml2-2.10.2-CVE-2024-56171.patch: refresh the
      cached pointer to the duplicates array after xmlSchemaItemListAdd()
      may have reallocated it, in xmlSchemaIDCFillNodeTables and
      xmlSchemaBubbleIDCNodeTables in xmlschemas.c; backport of upstream
      libxml2 5880a9a6 (v2.12.10, v2.13.6, v2.14.0). Reachable from
      schema validation of an untrusted instance document that produces
      duplicate identity-constraint keys. The second site additionally
      checks xmlSchemaItemListAdd()'s return before refreshing the
      pointer: 2.10.2 assigns xmlRealloc()'s result straight to
      list->items, so unlike upstream it leaves it NULL on failure
    - CVE-2024-56171
  * SECURITY UPDATE: use-after-free in xmlParseInternalSubset
    - debian/patches/libxml2-2.10.2-CVE-2026-6653.patch: drop the
      post-push XML_PARSER_EOF check from xmlPushInput(), and give the
      xmlSkipBlankChars() loop an XML_PARSER_EOF guard, both in
      parser.c; backports of upstream libxml2 f19a9510 (its xmlPushInput
      hunk) and e129c1d1. xmlPushInput() tested for a halted parser only
      after inputPush() had already installed the input as ctxt->input,
      and then returned -1, so xmlParsePEReference() freed an input
      stream that ctxt->input still pointed at and a crafted DTD
      internal subset caused a heap use-after-free read in
      xmlParseInternalSubset(). With that input no longer freed the
      parser goes on to re-enter xmlSkipBlankChars(), whose loop was
      unconditional while NEXT is a no-op on a halted parser, so the
      same document would spin at 100% CPU instead of crashing; the
      guard ends the loop, matching the three other loops in the file.
      The halt comes from the entity amplification check added for
      CVE-2021-3541, which 2.10.2 carries; that check is left in place.
      The upstream fix for this CVE (463bbeec, v2.11.0) is not used: it
      appends members to the public xmlEntity and xmlParserInput
      structs, changing their size, and enforces the amplification cap
      even under XML_PARSE_HUGE
    - CVE-2026-6653

 -- Juan Carlos Garcia <jgarcia@cloudlinux.com>  Wed, 16 Sep 2026 00:00:00 +0000

alt-libxml2 (2.10.2-4) stable; urgency=medium

  * SECURITY UPDATE: out-of-bounds read in the libxml2 regexp parser
    - debian/patches/libxml2-2.10.2-CVE-2026-86137.patch: bounds-check
      the parser cursor in xmlFAParsePosCharGroup before the NXT macro
      reads past the end of the expression; backport of upstream libxml2
      76fe08d9 (v2.15.4)
    - CVE-2026-86137
  * SECURITY UPDATE: integer overflow and heap buffer overflow in xmlDictAddQString
    - debian/patches/libxml2-2.10.2-CVE-2026-86138.patch: add overflow
      checks to the pool size arithmetic in dict.c before allocating and
      copying the qualified name; backport of upstream libxml2 a4cba4b5
      (v2.15.4)
    - CVE-2026-86138
  * SECURITY UPDATE: stack buffer overflow in xmlSnprintfElements
    - debian/patches/libxml2-2.10.2-CVE-2025-24928.patch: compute the
      combined QName length once, before any append, so the bounds check
      in the xmlSnprintfElements loop is no longer made against a stale
      buffer length; backport of upstream libxml2 8c8753ad (v2.14.0).
      This is the overflow that is reachable on 2.10.2: a DTD content
      model whose element QNames exceed the 5000-byte dump buffer
      (xmllint --valid) overflows the stack
    - CVE-2025-24928
  * SECURITY UPDATE: unchecked strcat around the xmlSnprintfElements loop
    - debian/patches/libxml2-2.10.2-CVE-2026-86140.patch: replace the
      unchecked strcat calls at the entry and exit of the DTD content-model
      dump in valid.c with bounds-checked appends; backport of upstream
      libxml2 d1686f91 (v2.15.4). On 2.10.2 both sites are hardening only:
      the function is static and its callers pass a freshly emptied buffer,
      so the overflow that can be reached is the one fixed by the
      CVE-2025-24928 patch above
    - CVE-2026-86140
  * SECURITY UPDATE: NULL pointer dereference in xmlRegNewParserCtxt
    - debian/patches/libxml2-2.10.2-CVE-2026-86141.patch: compute the
      expression length only after the xmlStrdup result has been NULL-
      checked in xmlregexp.c; backport of upstream libxml2 e89a8aae
      (v2.15.4)
    - CVE-2026-86141
  * SECURITY UPDATE: heap buffer overflow in xmlXPtrEvalXPtrPart
    - debian/patches/libxml2-2.10.2-CVE-2026-86142.patch: check the
      xpointer part length for overflow before allocating the evaluation
      buffer in xpointer.c; backport of upstream libxml2 6b3a736c
      (v2.15.4)
    - CVE-2026-86142
  * SECURITY UPDATE: negative lengths reaching output write callbacks
    - debian/patches/libxml2-2.10.2-CVE-2026-86143.patch: check for int
      overflow between xmlBufUse and the write callback length in
      xmlIO.c so a negative length can no longer reach
      xmlOutputWriteCallback; backport of upstream libxml2 90f293ba
      (v2.15.4)
    - CVE-2026-86143
  * SECURITY UPDATE: XInclude ignores the document parse flags
    - debian/patches/libxml2-2.10.2-CVE-2026-86144.patch: make
      xmlXIncludeProcess and xmlXIncludeProcessTree propagate the
      document's parseFlags (e.g. XML_PARSE_NONET) to the include
      context in xinclude.c; backport of upstream libxml2 b63cd517
      (v2.15.4)
    - Behaviour change: the include context now inherits every parse
      flag of the document, XML_PARSE_NOENT, XML_PARSE_RECOVER and
      XML_PARSE_HUGE included, not only XML_PARSE_NONET. A document
      parsed with XML_PARSE_NOENT and then passed to xmlXIncludeProcess()
      now also substitutes external entities inside the included
      documents; callers that must not load them should not pass
      XML_PARSE_NOENT, or should call xmlXIncludeProcessFlags() with an
      explicit flag set. PHP's DOMDocument::xinclude() already uses
      xmlXIncludeProcessFlags() and is unaffected
    - CVE-2026-86144

  * Fix deb packaging defects surfaced by the first Debian/Ubuntu build: point the
    alt-libxml2-devel libxml2.so symlink at the 2.10.2 soname (was 2.9.7) and
    repair the malformed 2.9.7-2 changelog trailer (three spaces before the date).

 -- Juan Carlos Garcia <jgarcia@cloudlinux.com>  Thu, 10 Sep 2026 00:00:00 +0000

alt-libxml2 (2.10.2-3) stable; urgency=medium

  * ALTPHP-1941: remove python module from build

 -- Sergey Fokin <sfokin@cloudlinux.com>  Fri, 14 Mar 2025 10:28:00 +0100

alt-libxml2 (2.10.2-2) stable; urgency=medium

  * build with alt-python311

 -- Sergey Fokin <sfokin@cloudlinux.com>  Fri, 06 Dec 2024 16:17:00 +0100

libxml2 (2.10.2-1) stable; urgency=medium

  * ALTPHP-1311: Update to 2.10.2

 -- Ilya Voyskovsky <ivoyskovsky@cloudlinux.com>  Tue, 20 Sep 2022 11:10:00 +0200

libxml2 (2.9.7-2) stable; urgency=medium

  * ALTPHP-1154: Fix alt-libxml2 requires

 -- Eduard Abdullin <eabdullin@cloudlinux.com>  Wed, 21 Jul 2021 14:54:12 +0300

libxml2 (2.9.7-1) stable; urgency=medium

  * Update to 2.9.7

 -- Anatholy Scryabin <ascryabin@cloudlinux.com>  Mon, 15 Mar 2021 14:15:27 +0300

libxml2 (2.9.4-1cloudlinux1) unstable; urgency=medium

  * Initial release for alt-libxml2

 -- Anatholy Scryabin <ascryabin@cloudlinux.com>  Thu, 17 May 2018 08:13:52 +0300
