ChangeLog for: 2026-03-05 06:21:21
a/hwdata-0.405-noarch-1.txz: Upgraded.
a/kernel-firmware-20260303_f69a5e7-noarch-1.txz: Upgraded.
a/kernel-generic-6.12.75-x86_64-1.txz: Upgraded.
a/nvi-1.81.6-x86_64-4.txz: Rebuilt.
Merge patchset from Debian.
This makes a number of fixes and improvements, especially concerning
wide-character support. It also fixes a possible heap-based buffer
overflow in the regex handling affecting 32-bit platforms.
Thanks to r1w1s1.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2015-2305
(* Security fix *)
ap/lsof-4.99.6-x86_64-1.txz: Upgraded.
d/kernel-headers-6.12.75-x86-1.txz: Upgraded.
k/kernel-source-6.12.75-noarch-1.txz: Upgraded.
l/libxml2-2.15.2-x86_64-1.txz: Upgraded.
This update fixes security issues:
CVE-2026-1757 fix: Memory leak in xmllint Shell - shell.c
CVE-2026-0990 fix: Prevent infinite recursion in
xmlCatalogListXMLResolve
CVE-2026-0992 fix: Exponential behavior when handling
parser: Fix infinite loop in xmlCtxtParseContent
CVE-2025-10911 libxslt related: Ignore next/prev of documents when
traversing XPath
CVE-2026-0989 fix: Add RelaxNG include limit
xmlIO: use size_t for buffer size reallocation
uri: fix signed integer overflow in xmlBuildRelativeURISafe
schematron: fix memory leaks on error paths in xmlSchematronParseRule
catalog: fix stack overflow from self-referencing SGML CATALOG entries
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2026-1757
https://www.cve.org/CVERecord?id=CVE-2026-0990
https://www.cve.org/CVERecord?id=CVE-2026-0992
https://www.cve.org/CVERecord?id=CVE-2025-10911
https://www.cve.org/CVERecord?id=CVE-2026-0989
(* Security fix *)
n/alpine-2.29.9-x86_64-1.txz: Upgraded.
n/iptables-1.8.13-x86_64-1.txz: Upgraded.
n/libksba-1.6.8-x86_64-1.txz: Upgraded.
n/nfs-utils-2.8.5-x86_64-3.txz: Rebuilt.
Added sample /etc/idmapd.conf and missing documentation for nfsidmap.
isolinux/initrd.img: Rebuilt.
kernels/*: Upgraded.
testing/packages/linux-6.18.x/kernel-generic-6.18.16-x86_64-1.txz: Upgraded.
testing/packages/linux-6.18.x/kernel-headers-6.18.16-x86-1.txz: Upgraded.
testing/packages/linux-6.18.x/kernel-source-6.18.16-noarch-1.txz: Upgraded.
usb-and-pxe-installers/usbboot.img: Rebuilt.