SECURITY UPDATE: XML_ExternalEntityParserCreate does not copy unknown
encoding handler user data
debian/patches/CVE-2026-24515.patch: Fix a null pointer dereference
in the XML parser caused by the failure to copy user data for
unknown encoding handlers