#1149237 trixie-pu: package lxml/5.4.0-1+deb13u1

#1149237#5
Date:
2026-09-28 17:03:46 UTC
From:
To:
[ Reason ]

Fix <no-dsa> issues CVE-2026-41066 and CVE-2026-49825.

[ Impact ]

Users will remain vulnerable to these issues, and will regress when
upgrading (a fix will be uploaded to Bookworm LTS shortly).

[ Tests ]

POC at https://bugs.launchpad.net/lxml/+bug/2146291 and
https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f
and manual test suite run (the test suite is not run at build time, see
#976148).

[ Risks ]

Trivial fixes.

[ Checklist ]

  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in stable
  [x] the issue is verified as fixed in unstable

[ Changes ]

  * Fix CVE-2026-41066: Default configuration of iterparse() and
    ETCompatXMLParser() allows XXE to local files.
    This update changes the default to resolve_entities='internal' (hence
    disallowing local file access by default).
  * Fix CVE-2026-49825: URL bypass in Cleaner via xlink:href.
  * Add d/salsa-ci.yml for Salsa CI.
  * Re-generate .c files.

[ Other info ]

The attached debdiff excludes the d/p/Update-.c-files.patch patch which
updates the generated .c files (the package is built without cython, so
.c files need to be regenerated and the result saved in d/patches).  I
attach that file gzipped separately anyway.

Debusine workflow output:
https://debusine.debian.net/debian/developers/work-request/1367042/

Individual commits and tag can be found on the LTS team fork at
https://salsa.debian.org/lts-team/packages/lxml/-/tree/debian/trixie?ref_type=heads