[MEDIUM] Patch libxslt for CVE-2025-7424#15254
Conversation
ca5ae18 to
108efe6
Compare
|
libxslt is version upgraded to 1.1.43 which already has fix
|
|
Buddy build is successful. |
libxslt to 1.1.43 and patch CVE-2025-7424
Kanishk-Bansal
left a comment
There was a problem hiding this comment.
Minor version up to 1.1.43, after this upgrade the patch of CVE-2025-7424 applies cleanly. Some patches were remove as a part of minor upgrade as those were already covered in this release. Changes LGTM.
We have similar changes in 3.0 as well which is already merged without any regression
|
Full Build as this a toolchain package. |
Could see failure in building libvirt package. Analysing in progress |
108efe6 to
b43c749
Compare
libxslt to 1.1.43 and patch CVE-2025-7424
kgodara912
left a comment
There was a problem hiding this comment.
Please update the toolchain entries with updated version of this package.
Updated |
|
Full Build results are having failure in building SPECS_EXTENDED package - pngcrush Otherwise the full build seems successful |
There was a problem hiding this comment.
Both the patches match with respective upstream references and not modification except context different. Buddy build is successful. Full build was failed in first attempt but after re-running it was successful, and logs weren't showing libxslt as an issue. Further there is one extended repo package failure, pngcrush which was failing previously as well and is not related to this package. LGTM.






Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
What does the PR accomplish, why was it needed?
Upgrade: libxslt version to 1.1.43 and fix CVE-2025-7424
Change Log
Does this affect the toolchain?
NO
Links to CVEs
Test Methodology