alt-libxml2 (2.10.2-7) stable; urgency=medium

  * SECURITY UPDATE: NULL pointer dereference in xmlPatMatch
    - debian/patches/libxml2-2.10.2-CVE-2025-27113.patch: compile an
      explicit child:: axis step to XML_OP_ELEM instead of XML_OP_CHILD
      in xmlCompileStepPattern() in pattern.c; backport of upstream
      libxml2 503f788e (v2.12.10, v2.13.6, v2.14.0). XML_OP_CHILD accepts
      a document node and does not advance the current node, so a pattern
      such as "/child::name" matched against a document node reached the
      unguarded node->parent load in the XML_OP_ROOT case of xmlPatMatch()
      and crashed. Reachable through the public xmlPatternMatch(), used
      in-tree by xmlTextReaderPreservePattern() and by Schematron rule
      contexts; the streaming matcher already compiled the child axis
      correctly, so XML Schema identity constraints and the XPath
      streaming optimisation are unaffected. Upstream fixed only the
      compiler side and leaves the XML_OP_ROOT load unguarded to this day;
      it is left unguarded here too, and no in-tree caller reaches it.
      Behaviour change: patterns using the explicit child:: axis now
      select the named element itself rather than its parent, which is
      correct XPath and what the streaming matcher already did
    - CVE-2025-27113
  * SECURITY UPDATE: heap out-of-bounds read in xmlSchemaIDCFillNodeTables
    - debian/patches/libxml2-2.10.2-CVE-2025-32415.patch: use the live
      bind->nbNodes instead of the stale local nbNodeTable for both the
      guard and the terminator of the IDC node-table loop in
      xmlSchemaIDCFillNodeTables in xmlschemas.c; backport of upstream
      libxml2 384cc7c1 (v2.13.8), whose master twin is 487ee1d8
      (v2.14.2). nbNodeTable is snapshotted before the target loop, but
      the loop shrinks the node table every time it moves a duplicate
      key-sequence to bind->dupls, so from the next target onwards the
      loop walks slots past the live end of the table; once the table is
      empty the guard is still true and a match evaluates
      bind->nodeTable[-1], reading one element before the start of the
      heap allocation and leaving bind->nbNodes negative for the targets
      that follow. Reachable from schema validation of an untrusted
      instance document against a schema carrying identity constraints,
      or from an untrusted schema. Applied on top of
      libxml2-2.10.2-CVE-2024-56171.patch, which edits the same function
      but a different defect (a stale pointer rather than a stale count)
      and does not overlap these hunks
    - CVE-2025-32415
  * SECURITY UPDATE: integer overflow in xmlBuildQName leading to a
    stack-based buffer overflow
    - debian/patches/libxml2-2.10.2-CVE-2025-6021.patch: hold the
      local-name and prefix lengths in size_t, reject a negative len, and
      bound lenn + lenp + 2 against SIZE_MAX before the buffer-size test
      and the allocation, in tree.c; backport of upstream libxml2
      17d950ae (v2.13.9). The lengths were held in int and summed in int
      arithmetic, so a long enough QName made lenn + lenp + 2 wrap
      negative, which both defeated the buffer-size test - handing back a
      caller's 50-byte stack buffer - and undersized the xmlMallocAtomic()
      allocation, letting the following memcpy()s and the NUL store write
      out of bounds
    - CVE-2025-6021
  * SECURITY UPDATE: stack-based buffer overflows in xmlcatalog --shell
    - debian/patches/libxml2-2.10.2-CVE-2026-11979.patch: bounds-check the
      three copy loops in usershell() in xmlcatalog.c, which wrote a line
      of user input into the fixed command[100], arg[400] and argv[20]
      stack buffers with no limit at all; backport of upstream libxml2
      cd48d441 (v2.15.4), whose xmlcatalog.c hunks are identical to
      master's c2e233fc. Over-long input is now rejected with a diagnostic
      instead of corrupting the stack frame. Upstream's
      test/catalogs/test.sh hunk is dropped because that file does not
      exist in 2.10.2; usershell() itself is byte-identical to upstream's
      pre-fix version, so the guards are carried verbatim. Affects only
      the xmlcatalog command-line utility shipped by this package -- no
      library entry point reaches usershell()
    - CVE-2026-11979
  * Harden the xmlcatalog command line parser
    - debian/patches/libxml2-2.10.2-xmlcatalog-argv-oob-read.patch: check
      that --add and --del were given enough arguments before indexing
      argv in main() in xmlcatalog.c; backport of upstream libxml2
      b1fea45b. This is not a CVE and is not part of CVE-2026-11979; it
      is carried alongside it because upstream shipped both in the same
      release and both touch the same file. "xmlcatalog --add a" read
      argv[4] past the end of the argument vector and passed whatever
      followed it, in practice a process environment string, to
      xmlCatalogAdd()

 -- Tamar Zerekidze <tzerekidze@cloudlinux.com>  Wed, 16 Sep 2026 00:00:00 +0000

alt-libxml2 (2.10.2-6) stable; urgency=medium

  * SECURITY UPDATE: integer overflows with XML_PARSE_HUGE
    - debian/patches/libxml2-2.10.2-CVE-2022-40303.patch: bound every
      length counter that can wrap while parsing a multi-gigabyte
      document, in parser.c and in xmlSAX2Text() in SAX2.c; backports of
      upstream libxml2 c846986 and d3b4850 (v2.10.3). Without them a
      caller that sets XML_PARSE_HUGE overflows the int counters and the
      parser indexes an array at a negative 2GB offset, typically a
      segfault. Note that upstream's fix also makes the length limits
      unconditional: names are now capped at 10,000,000 bytes and entity
      values, attribute values, comments, PIs and CDATA sections at
      1,000,000,000 bytes even when XML_PARSE_HUGE is set, and the
      XML_ERR_NAME_TOO_LONG message becomes "Name too long". No public
      struct, exported symbol or default option changes
    - CVE-2022-40303
  * SECURITY UPDATE: dict corruption / double free on entity reference
    cycles
    - debian/patches/libxml2-2.10.2-CVE-2022-40304.patch: stop storing
      an entity's content, orig, ExternalID and SystemID in the document
      dictionary in xmlCreateEntity(), and free them unconditionally in
      xmlFreeEntity(), in entities.c; backport of upstream libxml2
      1b41ec4e (v2.10.3). Content shorter than 5 bytes, ExternalID and
      SystemID were interned in the shared dictionary, while the parser
      clears a looping entity in place with ent->content[0] = 0, so a
      crafted cyclic entity declaration wrote a NUL into the dictionary
      string pool and corrupted an interned hash key, from which a
      double free can be provoked. entity->name stays interned and keeps
      its xmlDictOwns() guard. No public API, ABI or struct layout
      change
    - CVE-2022-40304
  * SECURITY UPDATE: use-after-free in xmlXIncludeAddNode
    - debian/patches/libxml2-2.10.2-CVE-2022-49043.patch: move the
      xmlFree() of the built-up include URI past its last use in
      xmlXIncludeAddNode in xinclude.c; backport of upstream libxml2
      5a19e216 (v2.11.0). The URI was freed unconditionally before the
      result of xmlSaveUri() was tested, and the NULL branch then
      formatted the freed string into the "invalid value URI %s"
      message, a use-after-free read reachable on allocation failure
      while processing an XInclude directive. The only deviation from
      upstream is one context line: upstream had already changed the
      function to return a pointer, so it reads return(NULL) where
      2.10.2 still returns -1
    - CVE-2022-49043
  * SECURITY UPDATE: use-after-free in xmlValidatePopElement with the
    XML Reader interface
    - debian/patches/libxml2-2.10.2-CVE-2024-25062.patch: add the missing
      (reader->state != XML_TEXTREADER_BACKTRACK) condition to the
      "Handle XInclude if asked for" block after the node_found: label in
      xmlTextReaderRead() in xmlreader.c, so an element of the XInclude
      namespace is expanded only on the descending pass and not a second
      time while the reader backtracks out of it; backport of upstream
      libxml2 2b0aac14 (v2.11.7, v2.12.5, v2.13.0). With DTD validation
      (XML_PARSE_DTDVALID) and XInclude expansion both enabled on the
      reader, the repeated xmlXIncludeProcessNode() call mutates and frees
      nodes the reader has already walked, after which
      xmlTextReaderValidatePop() hands the stale node to
      xmlValidatePopElement(). The two neighbouring blocks in the same
      function, xmlTextReaderValidatePush() and the pattern match, already
      carried exactly this guard
    - CVE-2024-25062

 -- Tamar Zerekidze <tzerekidze@cloudlinux.com>  Wed, 16 Sep 2026 00:00:00 +0000

alt-libxml2 (2.10.2-5) stable; urgency=medium

  * SECURITY UPDATE: use-after-free after xmlSchemaItemListAdd
    - debian/patches/libxml2-2.10.2-CVE-2024-56171.patch: refresh the
      cached pointer to the duplicates array after xmlSchemaItemListAdd()
      may have reallocated it, in xmlSchemaIDCFillNodeTables and
      xmlSchemaBubbleIDCNodeTables in xmlschemas.c; backport of upstream
      libxml2 5880a9a6 (v2.12.10, v2.13.6, v2.14.0). Reachable from
      schema validation of an untrusted instance document that produces
      duplicate identity-constraint keys. The second site additionally
      checks xmlSchemaItemListAdd()'s return before refreshing the
      pointer: 2.10.2 assigns xmlRealloc()'s result straight to
      list->items, so unlike upstream it leaves it NULL on failure
    - CVE-2024-56171
  * SECURITY UPDATE: use-after-free in xmlParseInternalSubset
    - debian/patches/libxml2-2.10.2-CVE-2026-6653.patch: drop the
      post-push XML_PARSER_EOF check from xmlPushInput(), and give the
      xmlSkipBlankChars() loop an XML_PARSER_EOF guard, both in
      parser.c; backports of upstream libxml2 f19a9510 (its xmlPushInput
      hunk) and e129c1d1. xmlPushInput() tested for a halted parser only
      after inputPush() had already installed the input as ctxt->input,
      and then returned -1, so xmlParsePEReference() freed an input
      stream that ctxt->input still pointed at and a crafted DTD
      internal subset caused a heap use-after-free read in
      xmlParseInternalSubset(). With that input no longer freed the
      parser goes on to re-enter xmlSkipBlankChars(), whose loop was
      unconditional while NEXT is a no-op on a halted parser, so the
      same document would spin at 100% CPU instead of crashing; the
      guard ends the loop, matching the three other loops in the file.
      The halt comes from the entity amplification check added for
      CVE-2021-3541, which 2.10.2 carries; that check is left in place.
      The upstream fix for this CVE (463bbeec, v2.11.0) is not used: it
      appends members to the public xmlEntity and xmlParserInput
      structs, changing their size, and enforces the amplification cap
      even under XML_PARSE_HUGE
    - CVE-2026-6653

 -- Juan Carlos Garcia <jgarcia@cloudlinux.com>  Wed, 16 Sep 2026 00:00:00 +0000

alt-libxml2 (2.10.2-4) stable; urgency=medium

  * SECURITY UPDATE: out-of-bounds read in the libxml2 regexp parser
    - debian/patches/libxml2-2.10.2-CVE-2026-86137.patch: bounds-check
      the parser cursor in xmlFAParsePosCharGroup before the NXT macro
      reads past the end of the expression; backport of upstream libxml2
      76fe08d9 (v2.15.4)
    - CVE-2026-86137
  * SECURITY UPDATE: integer overflow and heap buffer overflow in xmlDictAddQString
    - debian/patches/libxml2-2.10.2-CVE-2026-86138.patch: add overflow
      checks to the pool size arithmetic in dict.c before allocating and
      copying the qualified name; backport of upstream libxml2 a4cba4b5
      (v2.15.4)
    - CVE-2026-86138
  * SECURITY UPDATE: stack buffer overflow in xmlSnprintfElements
    - debian/patches/libxml2-2.10.2-CVE-2025-24928.patch: compute the
      combined QName length once, before any append, so the bounds check
      in the xmlSnprintfElements loop is no longer made against a stale
      buffer length; backport of upstream libxml2 8c8753ad (v2.14.0).
      This is the overflow that is reachable on 2.10.2: a DTD content
      model whose element QNames exceed the 5000-byte dump buffer
      (xmllint --valid) overflows the stack
    - CVE-2025-24928
  * SECURITY UPDATE: unchecked strcat around the xmlSnprintfElements loop
    - debian/patches/libxml2-2.10.2-CVE-2026-86140.patch: replace the
      unchecked strcat calls at the entry and exit of the DTD content-model
      dump in valid.c with bounds-checked appends; backport of upstream
      libxml2 d1686f91 (v2.15.4). On 2.10.2 both sites are hardening only:
      the function is static and its callers pass a freshly emptied buffer,
      so the overflow that can be reached is the one fixed by the
      CVE-2025-24928 patch above
    - CVE-2026-86140
  * SECURITY UPDATE: NULL pointer dereference in xmlRegNewParserCtxt
    - debian/patches/libxml2-2.10.2-CVE-2026-86141.patch: compute the
      expression length only after the xmlStrdup result has been NULL-
      checked in xmlregexp.c; backport of upstream libxml2 e89a8aae
      (v2.15.4)
    - CVE-2026-86141
  * SECURITY UPDATE: heap buffer overflow in xmlXPtrEvalXPtrPart
    - debian/patches/libxml2-2.10.2-CVE-2026-86142.patch: check the
      xpointer part length for overflow before allocating the evaluation
      buffer in xpointer.c; backport of upstream libxml2 6b3a736c
      (v2.15.4)
    - CVE-2026-86142
  * SECURITY UPDATE: negative lengths reaching output write callbacks
    - debian/patches/libxml2-2.10.2-CVE-2026-86143.patch: check for int
      overflow between xmlBufUse and the write callback length in
      xmlIO.c so a negative length can no longer reach
      xmlOutputWriteCallback; backport of upstream libxml2 90f293ba
      (v2.15.4)
    - CVE-2026-86143
  * SECURITY UPDATE: XInclude ignores the document parse flags
    - debian/patches/libxml2-2.10.2-CVE-2026-86144.patch: make
      xmlXIncludeProcess and xmlXIncludeProcessTree propagate the
      document's parseFlags (e.g. XML_PARSE_NONET) to the include
      context in xinclude.c; backport of upstream libxml2 b63cd517
      (v2.15.4)
    - Behaviour change: the include context now inherits every parse
      flag of the document, XML_PARSE_NOENT, XML_PARSE_RECOVER and
      XML_PARSE_HUGE included, not only XML_PARSE_NONET. A document
      parsed with XML_PARSE_NOENT and then passed to xmlXIncludeProcess()
      now also substitutes external entities inside the included
      documents; callers that must not load them should not pass
      XML_PARSE_NOENT, or should call xmlXIncludeProcessFlags() with an
      explicit flag set. PHP's DOMDocument::xinclude() already uses
      xmlXIncludeProcessFlags() and is unaffected
    - CVE-2026-86144

  * Fix deb packaging defects surfaced by the first Debian/Ubuntu build: point the
    alt-libxml2-devel libxml2.so symlink at the 2.10.2 soname (was 2.9.7) and
    repair the malformed 2.9.7-2 changelog trailer (three spaces before the date).

 -- Juan Carlos Garcia <jgarcia@cloudlinux.com>  Thu, 10 Sep 2026 00:00:00 +0000

alt-libxml2 (2.10.2-3) stable; urgency=medium

  * ALTPHP-1941: remove python module from build

 -- Sergey Fokin <sfokin@cloudlinux.com>  Fri, 14 Mar 2025 10:28:00 +0100

alt-libxml2 (2.10.2-2) stable; urgency=medium

  * build with alt-python311

 -- Sergey Fokin <sfokin@cloudlinux.com>  Fri, 06 Dec 2024 16:17:00 +0100

libxml2 (2.10.2-1) stable; urgency=medium

  * ALTPHP-1311: Update to 2.10.2

 -- Ilya Voyskovsky <ivoyskovsky@cloudlinux.com>  Tue, 20 Sep 2022 11:10:00 +0200

libxml2 (2.9.7-2) stable; urgency=medium

  * ALTPHP-1154: Fix alt-libxml2 requires

 -- Eduard Abdullin <eabdullin@cloudlinux.com>  Wed, 21 Jul 2021 14:54:12 +0300

libxml2 (2.9.7-1) stable; urgency=medium

  * Update to 2.9.7

 -- Anatholy Scryabin <ascryabin@cloudlinux.com>  Mon, 15 Mar 2021 14:15:27 +0300

libxml2 (2.9.4-1cloudlinux1) unstable; urgency=medium

  * Initial release for alt-libxml2

 -- Anatholy Scryabin <ascryabin@cloudlinux.com>  Thu, 17 May 2018 08:13:52 +0300
