Conversation
|
@larryluogit The build is broken and you have blocked changes from maintainers. Could you please have a look? |
@Algunenano The build failure has been resolved. The CVEs that this PR address exist in both 24.8lts and 25.3lts as well. Could you please set backport flag when you merge the PR? Thank you for your help! |
|
The CI is detecting issues with the library (https://s3.amazonaws.com/clickhouse-test-reports/PRs/81187/e3fb1a64431b6d199517249985c9e183a26126fa//integration_tests_tsan_2_6/integration_run_parallel5_0.log): |
The code in question (i.e. xmlIsMainThreadInternal) has been removed since libxml2 2.14.0. I will try bumping libxml2 to 2.14.3 |
|
Please don't merge master multiple times. I'll review the CI errors to confirm they are not related, but with each merge you add more failures to review 😉 |
0710f64
|
@Algunenano The CVEs mentioned in the description exist in 24.8lts and 25.3lts as well. Can this pr be backported? |
|
It's tagged to be backported to all releases |
Cherry pick #81187 to 24.8: Bump `libxml2` to 2.14.3
Cherry pick #81187 to 25.3: Bump `libxml2` to 2.14.3
Cherry pick #81187 to 25.4: Bump `libxml2` to 2.14.3
Cherry pick #81187 to 25.5: Bump `libxml2` to 2.14.3
Backport #81187 to 25.5: Bump `libxml2` to 2.14.3
Backport #81187 to 25.3: Bump `libxml2` to 2.14.3
Backport #81187 to 25.4: Bump `libxml2` to 2.14.3
Backport #81187 to 24.8: Bump `libxml2` to 2.14.3
Changelog category (leave one):
Changelog entry (a user-readable short description of the changes that goes to CHANGELOG.md):
Upgrade libxml2 to 2.14.3.
Addresses
CVE-2024-56171
CVE-2025-27113
CVE-2025-32414
CVE-2024-25062
CVE-2025-24928
CVE-2025-32415
CVE-2022-49043
CVE-2024-34459