[Buildroot] [PATCH 1/1] package/libxml2: bump to version 2.9.14

Peter Korsgaard peter at korsgaard.com
Sat May 28 08:30:24 UTC 2022


>>>>> "James" == James Hilliard <james.hilliard1 at gmail.com> writes:

 > Signed-off-by: James Hilliard <james.hilliard1 at gmail.com>

As the release notes clearly state, this fixes security issues:

https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.9.14

Security

    [CVE-2022-29824] Integer overflow in xmlBuf and xmlBuffer
    Fix potential double-free in xmlXPtrStringRangeFunction
    Fix memory leak in xmlFindCharEncodingHandler
    Normalize XPath strings in-place
    Prevent integer-overflow in htmlSkipBlankChars() and xmlSkipBlankChars() (David Kilzer)
    Fix leak of xmlElementContent (David Kilzer)

So adjusted the commit message to make this clear and committed to
2022.02.x, thanks.

-- 
Bye, Peter Korsgaard



More information about the buildroot mailing list