[CLSA-2025:1753298604] Fix CVE(s): CVE-2025-49794, CVE-2025-49796
Type:
security
Severity:
Critical
Release date:
2025-07-23 19:23:29 UTC
Description:
* SECURITY UPDATE: memory vulnerabilities in schematron - debian/patches/CVE-2025-49794_CVE-2025-49796.patch: fix memory safety issues in xmlSchematronReportOutput when parsing XPath elements and memory corruption issue triggered by processing sch:name elements in input XML file - CVE-2025-49794 - CVE-2025-49796
Updated packages:
  • libxml2_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els2_amd64.deb
    sha:5709629e8a3a03e6d558167ec5d27b383ddf6472
  • libxml2-dev_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els2_amd64.deb
    sha:6b141ad0d8e68f39206c66883a6e3d57568ec35f
  • libxml2-doc_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els2_all.deb
    sha:53f6b94d59d9e68e2f11c2925339c44f94c238a6
  • libxml2-utils_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els2_amd64.deb
    sha:e99987c1c31782af2d68ca3cfae8ec82e4a15ad3
  • python-libxml2_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els2_amd64.deb
    sha:7aaaf1bdb521db9f675bb44a071e22c6480c120f
  • python3-libxml2_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els2_amd64.deb
    sha:a1975cd981f9d5260536ca2f93a9de26fd1e5afa
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.