[CLSA-2025:1753374216] Fix CVE(s): CVE-2025-49794, CVE-2025-49796
Type:
security
Severity:
Critical
Release date:
2025-07-24 16:23:41 UTC
Description:
* SECURITY UPDATE: memory vulnerabilities in schematron - debian/patches/CVE-2025-49794_CVE-2025-49796.patch: fix memory safety issues in xmlSchematronReportOutput when parsing XPath elements and memory corruption issue triggered by processing sch:name elements in input XML file - CVE-2025-49794 - CVE-2025-49796
Updated packages:
  • libxml2_2.9.4+dfsg1-6.1ubuntu1.9+tuxcare.els4_amd64.deb
    sha:360b793c9defb98a6bd833b2b43d76bc9606eecb
  • libxml2-dev_2.9.4+dfsg1-6.1ubuntu1.9+tuxcare.els4_amd64.deb
    sha:310a7ca2f79236891394abfc9028463f4b2f3868
  • libxml2-doc_2.9.4+dfsg1-6.1ubuntu1.9+tuxcare.els4_all.deb
    sha:115a9f04d955ff4d926db88e79154d474812dd03
  • libxml2-utils_2.9.4+dfsg1-6.1ubuntu1.9+tuxcare.els4_amd64.deb
    sha:afcf903dd632c87e88f8974c5e718db54671f7f2
  • python-libxml2_2.9.4+dfsg1-6.1ubuntu1.9+tuxcare.els4_amd64.deb
    sha:cd5e98c43c61bb6b8153082390549b6fd38b7069
  • python3-libxml2_2.9.4+dfsg1-6.1ubuntu1.9+tuxcare.els4_amd64.deb
    sha:a7c3216a052684d1eeba8c9ba9ec1596d74a7818
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.