Slackware 1237 Published by

New packages are available for libxml2 and libarchive to fix security issues on Slackware 15.0 and -current. The updates for libxml2 address several vulnerabilities, including memory leaks and infinite recursion, while the update for libarchive fixes bugs and security issues such as NULL pointer dereferences and potential memory leaks.

libxml2 (SSA:2026-070-02)
libarchive (SSA:2026-070-01)




libxml2 (SSA:2026-070-02)


libxml2 (SSA:2026-070-02)

New libxml2 packages are available for Slackware 15.0 and -current to
fix security issues.

Here are the details from the Slackware 15.0 ChangeLog:
+--------------------------+
patches/packages/libxml2-2.11.9-i586-8_slack15.0.txz: Rebuilt.
This update fixes security issues:
CVE-2026-1757 fix: Memory leak in xmllint Shell - shell.c
CVE-2026-0990 fix: Prevent infinite recursion in
xmlCatalogListXMLResolve
CVE-2026-0992 fix: Exponential behavior when handling
parser: Fix infinite loop in xmlCtxtParseContent
CVE-2025-10911 libxslt related: Ignore next/prev of documents when
traversing XPath
CVE-2026-0989 fix: Add RelaxNG include limit
Thanks to r1w1s1 for locating the backported patches.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2026-1757
https://www.cve.org/CVERecord?id=CVE-2026-0990
https://www.cve.org/CVERecord?id=CVE-2026-0992
https://www.cve.org/CVERecord?id=CVE-2025-10911
https://www.cve.org/CVERecord?id=CVE-2026-0989
(* Security fix *)
+--------------------------+

Where to find the new packages:
+-----------------------------+

Thanks to the friendly folks at the OSU Open Source Lab
( http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 15.0:
ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libxml2-2.11.9-i586-8_slack15.0.txz

Updated package for Slackware x86_64 15.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/libxml2-2.11.9-x86_64-8_slack15.0.txz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/libxml2-2.15.2-i686-1.txz

Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/l/libxml2-2.15.2-x86_64-1.txz

MD5 signatures:
+-------------+

Slackware 15.0 package:
5868328f253dc7040729ef0b057a429c libxml2-2.11.9-i586-8_slack15.0.txz

Slackware x86_64 15.0 package:
7969553fbdf9ffdce4bfec2619ff38a6 libxml2-2.11.9-x86_64-8_slack15.0.txz

Slackware -current package:
a474110a92bac5d51ac8fb62c270b10d l/libxml2-2.15.2-i686-1.txz

Slackware x86_64 -current package:
484f22dfed7a7391119bd53bebf8480f l/libxml2-2.15.2-x86_64-1.txz

Installation instructions:
+------------------------+

Upgrade the package as root:
# upgradepkg libxml2-2.11.9-i586-8_slack15.0.txz

+-----+

Slackware Linux Security Team
http://slackware.com/gpg-key



libarchive (SSA:2026-070-01)


libarchive (SSA:2026-070-01)

New libarchive packages are available for Slackware 15.0 and -current to
fix security issues.

Here are the details from the Slackware 15.0 ChangeLog:
+--------------------------+
patches/packages/libarchive-3.8.6-i586-1_slack15.0.txz: Upgraded.
This update fixes bugs and security issues:
libarchive: fix incompatibility with Nettle 4.x (#2858)
libarchive: fix NULL pointer dereference in
archive_acl_from_text_w() (#2859)
bsdunzip: fix ISO week year and Gregorian year confusion (#2860)
7zip: ix SEGV in check_7zip_header_in_sfx via ELF offset validation (#2864)
7zip: fix out-of-bounds access on ELF 64-bit header (#2875)
RAR5 reader: fix infinite loop in rar5 decompression (#2877)
RAR5 reader: fix potential memory leak (#2892)
RAR5: fix SIGSEGV when archive_read_support_format_rar5 is called
twice (#2893)
CAB reader: fix memory leak on repeated calls to
archive_read_support_format_cab (#2895)
mtree reader: Fix file descriptor leak in mtree parser
cleanup (CWE-775, #2878)
various small bugfixes in code and documentation
(* Security fix *)
+--------------------------+

Where to find the new packages:
+-----------------------------+

Thanks to the friendly folks at the OSU Open Source Lab
( http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 15.0:
ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libarchive-3.8.6-i586-1_slack15.0.txz

Updated package for Slackware x86_64 15.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/libarchive-3.8.6-x86_64-1_slack15.0.txz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/libarchive-3.8.6-i686-1.txz

Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/l/libarchive-3.8.6-x86_64-1.txz

MD5 signatures:
+-------------+

Slackware 15.0 package:
1469605a8cec4e66d7a16926ca13aec6 libarchive-3.8.6-i586-1_slack15.0.txz

Slackware x86_64 15.0 package:
3d55f09d648863928671f010a3fe4628 libarchive-3.8.6-x86_64-1_slack15.0.txz

Slackware -current package:
3ef64b383d3f537142d73d2bce6d784b l/libarchive-3.8.6-i686-1.txz

Slackware x86_64 -current package:
fafea232f0960e2aa345e5e3cf3ae152 l/libarchive-3.8.6-x86_64-1.txz

Installation instructions:
+------------------------+

Upgrade the package as root:
# upgradepkg libarchive-3.8.6-i586-1_slack15.0.txz

+-----+

Slackware Linux Security Team
http://slackware.com/gpg-key