[ Reason ]
Fix <no-dsa> issues CVE-2026-41066 and CVE-2026-49825.
[ Impact ]
Users will remain vulnerable to these issues, and will regress when
upgrading (a fix will be uploaded to Bookworm LTS shortly).
[ Tests ]
POC at https://bugs.launchpad.net/lxml/+bug/2146291 and
https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f
and manual test suite run (the test suite is not run at build time, see
#976148).
[ Risks ]
Trivial fixes.
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in stable
[x] the issue is verified as fixed in unstable
[ Changes ]
* Fix CVE-2026-41066: Default configuration of iterparse() and
ETCompatXMLParser() allows XXE to local files.
This update changes the default to resolve_entities='internal' (hence
disallowing local file access by default).
* Fix CVE-2026-49825: URL bypass in Cleaner via xlink:href.
* Add d/salsa-ci.yml for Salsa CI.
* Re-generate .c files.
[ Other info ]
The attached debdiff excludes the d/p/Update-.c-files.patch patch which
updates the generated .c files (the package is built without cython, so
.c files need to be regenerated and the result saved in d/patches). I
attach that file gzipped separately anyway.
Debusine workflow output:
https://debusine.debian.net/debian/developers/work-request/1367042/
Individual commits and tag can be found on the LTS team fork at
https://salsa.debian.org/lts-team/packages/lxml/-/tree/debian/trixie?ref_type=heads