{"id":"CLSA-2025-1741286239","summary":"Fix of 5 CVEs","details":"   * SECURITY UPDATE: buffer over-read in xmlHTMLPrintFileContext\n     - debian/patches/CVE-2024-34459.patch: Fix buffer overread with `xmllint\n       --htmlout` by adding a missing bounds check\n     - CVE-2024-34459\n   * SECURITY UPDATE: use-after-free vulnerability in xinclude.c\n     - debian/patches/CVE-2022-49043.patch: Fix use-after-free in\n       xmlXIncludeAddNode, free URI after reporting the error to avoid use-after-free\n     - CVE-2022-49043\n   * SECURITY UPDATE: stack-based buffer overflow in xmlSnprintfElements in\n     valid.c\n     - debian/patches/CVE-2025-24928.patch: Fix stack-buffer-overflow in\n       xmlSnprintfElements caused by improperly calculating qname length\n     - CVE-2025-24928\n   * SECURITY UPDATE: NULL pointer dereference in xmlPatMatch in pattern.c\n     - debian/patches/CVE-2025-27113.patch: Fix compilation of explicit child\n       axis to generate XML_OP_ELEM like the case without an axis\n     - CVE-2025-27113\n   * SECURITY UPDATE: use-after-free vulnerability in XML schema processing\n     - debian/patches/CVE-2024-56171.patch: Fix use-after-free after\n       xmlSchemaItemListAdd in xmlSchemaIDCFillNodeTables and\n       xmlSchemaBubbleIDCNodeTables\n     - CVE-2024-56171","modified":"2026-06-04T10:03:13.313824144Z","published":"2025-03-06T18:37:24Z","upstream":["CVE-2022-49043","CVE-2024-34459","CVE-2024-56171","CVE-2025-24928","CVE-2025-27113"],"references":[{"type":"ADVISORY","url":"https://errata.cloudlinux.com/ubuntu16-els/CLSA-2025-1741286239.html"}],"affected":[{"package":{"name":"libxml2","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libxml2?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.9.3+dfsg1-1ubuntu0.7+tuxcare.els8"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2025-1741286239.json"}},{"package":{"name":"libxml2-dev","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libxml2-dev?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.9.3+dfsg1-1ubuntu0.7+tuxcare.els8"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2025-1741286239.json"}},{"package":{"name":"libxml2-doc","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libxml2-doc?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.9.3+dfsg1-1ubuntu0.7+tuxcare.els8"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2025-1741286239.json"}},{"package":{"name":"libxml2-utils","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libxml2-utils?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.9.3+dfsg1-1ubuntu0.7+tuxcare.els8"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2025-1741286239.json"}},{"package":{"name":"python-libxml2","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/python-libxml2?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.9.3+dfsg1-1ubuntu0.7+tuxcare.els8"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2025-1741286239.json"}}],"schema_version":"1.7.5"}