Skip to content

build/deps: upgrade libxml2 to v2.15.3 (CVE-2026-6732)#30393

Merged
tyson-redpanda merged 1 commit intov26.1.xfrom
snyk/cve-2026-6732-libxml2-2.15.3-v26.1.x
May 8, 2026
Merged

build/deps: upgrade libxml2 to v2.15.3 (CVE-2026-6732)#30393
tyson-redpanda merged 1 commit intov26.1.xfrom
snyk/cve-2026-6732-libxml2-2.15.3-v26.1.x

Conversation

@tyson-redpanda
Copy link
Copy Markdown
Contributor

Upgrades libxml2 from 2.15.2 to 2.15.3 to fix CVE-2026-6732 (type confusion vulnerability in XSD validation with internal entity references, CVSS 7.1 High). Also affects v25.3.x (separate PR) and dev (#30392).

This PR depends on redpanda-data/vtools#4233 being merged first so the artifact is available in S3.

Backports Required

  • none - not a bug fix
  • none - this is a backport

Release Notes

Bug Fixes

  • Upgraded libxml2 to v2.15.3 to fix CVE-2026-6732 type confusion vulnerability in XSD validation.

FIXES=CORE-16201

@tyson-redpanda tyson-redpanda marked this pull request as ready for review May 7, 2026 12:44
@vbotbuildovich
Copy link
Copy Markdown
Collaborator

CI test results

test results on build#84161
test_status test_class test_method test_arguments test_kind job_url passed reason test_history
FLAKY(PASS) ShadowLinkingReplicationTests test_auto_prefix_trimming {"source_cluster_spec": {"cluster_type": "redpanda"}, "with_failures": true} integration https://buildkite.com/redpanda/redpanda/builds/84161#019e0291-3cf8-4c27-bdc2-72befbb81a41 10/11 Test PASSES after retries.No significant increase in flaky rate(baseline=0.0005, p0=1.0000, reject_threshold=0.0100. adj_baseline=0.1000, p1=0.3487, trust_threshold=0.5000) https://redpanda.metabaseapp.com/dashboard/87-tests?tab=142-dt-individual-test-history&test_class=ShadowLinkingReplicationTests&test_method=test_auto_prefix_trimming
FLAKY(PASS) WriteCachingFailureInjectionE2ETest test_crash_all {"use_transactions": false} integration https://buildkite.com/redpanda/redpanda/builds/84161#019e0291-3cfd-40fd-9143-20112797b29e 10/11 Test PASSES after retries.No significant increase in flaky rate(baseline=0.1031, p0=1.0000, reject_threshold=0.0100. adj_baseline=0.2785, p1=0.0382, trust_threshold=0.5000) https://redpanda.metabaseapp.com/dashboard/87-tests?tab=142-dt-individual-test-history&test_class=WriteCachingFailureInjectionE2ETest&test_method=test_crash_all

@tyson-redpanda tyson-redpanda merged commit 7be54c4 into v26.1.x May 8, 2026
18 checks passed
@tyson-redpanda tyson-redpanda deleted the snyk/cve-2026-6732-libxml2-2.15.3-v26.1.x branch May 8, 2026 14:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants