[Low] Patch libxml2 for CVE-2025-8732#15690
Conversation
|
Buddy Build has passed. |
|
Patch looks fine. Buddy build passes. |
|
https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1046961&view=results
rabbitmq-server seems to be failing but it is a known issue in elixir elixir-lang/elixir#12506 for v1.14.3, rebuilding solves this mostly. |
Reran the build - https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1047454&view=results |
kgodara912
left a comment
There was a problem hiding this comment.
Please resolve the merge conflicts.
Resolved the merge conflicts. |
|
Buddy build after rebase. |
Buddy build has passed. |
kgodara912
left a comment
There was a problem hiding this comment.
Patch functionally matches with upstream reference. Buddy build and full build are successful except few known fluctuating failures. LGTM.


Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
depthargument to thexmlExpandCatalog()function definition.Change Log
Does this affect the toolchain?
YES
Associated issues
Links to CVEs
Test Methodology
Log:
libxml2-2.10.4-11.cm2.src.rpm.log
Patch applies cleanly.