SECURITY UPDATE: XMLExternalEntityParserCreate failure to copy the
encoding handler data can cause a NULL dereference (CWE-476) from external
entities that declare use of an unknown encoding. The expected impact is
denial of service.
debian/patches/CVE-2026-24515.patch: Make XML
ExternalEntityParserCreate
copy unknown encoding handler user data