From: Peter Marko <peter.marko@siemens.com>
To: openembedded-core@lists.openembedded.org
Cc: peter.marko@siemens.com
Subject: [wrynose][PATCH 5/6] libxml2: set status for CVE-2026-6732
Date: Tue, 4 Aug 2026 22:03:55 +0200 [thread overview]
Message-ID: <20260804200356.2093270-5-peter.marko@siemens.com> (raw)
In-Reply-To: <20260804200356.2093270-1-peter.marko@siemens.com>
From: Peter Marko <peter.marko@siemens.com>
This is a version-less RedHat CVE.
[1] points to [2] and [3].
These were backported as [4] and [5] in v2.15.3.
[1] https://security-tracker.debian.org/tracker/CVE-2026-6732
[2] https://gitlab.gnome.org/GNOME/libxml2/-/commit/226b560837b90dea9b14431eca6e6fda8fb01ab4
[3] https://gitlab.gnome.org/GNOME/libxml2/-/commit/7cea3fd1557437b88f2c7b5e1b71a2d5fb152b55
[4] https://gitlab.gnome.org/GNOME/libxml2/-/commit/ad0f009a8366860272acb8e05c41a401798f2855
[5] https://gitlab.gnome.org/GNOME/libxml2/-/commit/65d0fe61c6f36ee40431aeb041ea703e839ff60d
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(From OE-Core rev: 7a75c7c8485cb9225f1714c4c08e1fd05a95f145)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
---
meta/recipes-core/libxml/libxml2_2.15.3.bb | 1 +
1 file changed, 1 insertion(+)
diff --git a/meta/recipes-core/libxml/libxml2_2.15.3.bb b/meta/recipes-core/libxml/libxml2_2.15.3.bb
index 02507d8042..abf9889b3f 100644
--- a/meta/recipes-core/libxml/libxml2_2.15.3.bb
+++ b/meta/recipes-core/libxml/libxml2_2.15.3.bb
@@ -25,6 +25,7 @@ SRC_URI[archive.sha256sum] = "78262a6e7ac170d6528ebfe2efccdf220191a5af6a6cd61ea4
SRC_URI[testtar.sha256sum] = "c6b2d42ee50b8b236e711a97d68e6c4b5c8d83e69a2be4722379f08702ea7273"
CVE_STATUS[CVE-2025-6170] = "fixed-version: fixed in version 2.14.5"
+CVE_STATUS[CVE-2026-6732] = "fixed-version: fixed in version 2.15.3"
BINCONFIG = "${bindir}/xml2-config"
next prev parent reply other threads:[~2026-08-04 20:04 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-04 20:03 [wrynose][PATCH 1/6] connman: remove connection_manager from CVE_PRODUCTS Peter Marko
2026-08-04 20:03 ` [wrynose][PATCH 2/6] p11-kit: upgrade 0.26.2 -> 0.26.4 Peter Marko
2026-08-04 20:03 ` [wrynose][PATCH 3/6] p11-kit: set status for CVE-2026-13757 Peter Marko
2026-08-04 20:03 ` [wrynose][PATCH 4/6] libxml2: upgrade 2.15.2 -> 2.15.3 Peter Marko
2026-08-04 20:03 ` Peter Marko [this message]
2026-08-04 20:03 ` [wrynose][PATCH 6/6] python3-cryptography(-vectors): upgrade 46.0.5 -> 46.0.7 Peter Marko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260804200356.2093270-5-peter.marko@siemens.com \
--to=peter.marko@siemens.com \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox