Mark the upgrade to 3.12.12 as fixing CVE-2025-8291, bsc#1251305.

This commit is contained in:
2025-11-11 21:26:09 +01:00
parent 9c55c6b365
commit a6fa7f608e

View File

@@ -10,7 +10,8 @@ Wed Oct 15 09:10:21 UTC 2025 - Daniel Garcia <daniel.garcia@suse.com>
- Security - Security
- gh-139700: Check consistency of the zip64 end of central - gh-139700: Check consistency of the zip64 end of central
directory record. Support records with “zip64 extensible data” directory record. Support records with “zip64 extensible data”
if there are no bytes prepended to the ZIP file. if there are no bytes prepended to the ZIP file
(CVE-2025-8291, bsc#1251305).
- gh-139400: xml.parsers.expat: Make sure that parent Expat - gh-139400: xml.parsers.expat: Make sure that parent Expat
parsers are only garbage-collected once they are no longer parsers are only garbage-collected once they are no longer
referenced by subparsers created by referenced by subparsers created by