ChangeLog for: 2026-02-01 00:57:36
d/python-pip-26.0-x86_64-1.txz: Upgraded.
kde/marble-23.08.5-x86_64-11.txz: Rebuilt.
Recompiled against protobuf-33.5.
l/expat-2.7.4-x86_64-1.txz: Upgraded.
This update fixes security issues:
Function XML_ExternalEntityParserCreate failed to copy the encoding handler
data passed to XML_SetUnknownEncodingHandler from the parent to the new
subparser. This can cause a NULL dereference and denial of service.
Integer overflow related to buffer size determination in function doContent.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2026-24515
https://www.cve.org/CVERecord?id=CVE-2026-25210
(* Security fix *)
l/gvfs-1.58.1-x86_64-1.txz: Upgraded.
l/protobuf-33.5-x86_64-1.txz: Upgraded.
Shared library .so-version bump.
(Or, at least, we've been told to always expect ABI breakage)
l/python-psutil-7.2.2-x86_64-1.txz: Upgraded.
l/qt6-6.10.2_20260125_abfb3788-x86_64-1.txz: Upgraded.
Compiled against protobuf-33.5.
n/mosh-1.4.0-x86_64-17.txz: Rebuilt.
Recompiled against protobuf-33.5.