<?xml version='1.0' encoding='UTF-8'?>
<oval_definitions xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:ind-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:linux="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>Tuxcare Errata System</oval:product_name>
    <oval:product_version>0.0.1</oval:product_version>
    <oval:schema_version>5.10</oval:schema_version>
    <oval:timestamp>2026-09-18T13:22:50</oval:timestamp>
  </generator>
  <definitions>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1774528491" version="1">
      <metadata>
        <title>Update of alt-php</title>
        <affected family="unix">
          <platform>Ubuntu 22.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1774528491" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1774528491" source="CLSA"/>
        <reference ref_id="CVE-2026-22796" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-22796" source="CVE"/>
        <reference ref_id="CVE-2025-69421" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-69421" source="CVE"/>
        <description>* fix changelog</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-03-26"/>
          <updated date="2026-03-26"/>
          <cve cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-1287" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-22796" impact="moderate" public="20260127">CVE-2026-22796</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-476" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-69421" impact="important" public="20260127">CVE-2025-69421</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-openssl is earlier than 0:1.1.1w-3.1" test_ref="oval:com.tuxcare.clsa:tst:1774528491001"/>
        <criterion comment="alt-openssl-dev is earlier than 0:1.1.1w-3.1" test_ref="oval:com.tuxcare.clsa:tst:1774528491002"/>
        <criterion comment="alt-openssl-doc is earlier than 0:1.1.1w-3.1" test_ref="oval:com.tuxcare.clsa:tst:1774528491003"/>
        <criterion comment="alt-openssl-libs is earlier than 0:1.1.1w-3.1" test_ref="oval:com.tuxcare.clsa:tst:1774528491004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1775149050" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2023-5678, CVE-2024-0727</title>
        <affected family="unix">
          <platform>Ubuntu 22.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1775149050" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1775149050" source="CLSA"/>
        <reference ref_id="CVE-2024-0727" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2024-0727" source="CVE"/>
        <reference ref_id="CVE-2023-5678" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2023-5678" source="CVE"/>
        <description>* SECURITY UPDATE: excessive time spent in DH check/generation with large Q
     - debian/patches/openssl-1.1.1-cve-2023-5678.patch: add bounds checks for
       excessively large Q parameter in DH_check_pub_key() and DH_generate_key()
     - CVE-2023-5678
   * SECURITY UPDATE: PKCS12 decoding crashes due to NULL pointer dereference
     - debian/patches/openssl-1.1.1-cve-2024-0727.patch: add NULL checks where
       ContentInfo data can be NULL in PKCS12/PKCS7 parsing functions
     - CVE-2024-0727</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-04-02"/>
          <updated date="2026-04-02"/>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" cwe="CWE-476" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2024-0727" impact="moderate" public="20240126">CVE-2024-0727</cve>
          <cve cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" cwe="CWE-606" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2023-5678" impact="moderate" public="20231106">CVE-2023-5678</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-openssl is earlier than 0:1.1.1w-3.2" test_ref="oval:com.tuxcare.clsa:tst:1775149050001"/>
        <criterion comment="alt-openssl-dev is earlier than 0:1.1.1w-3.2" test_ref="oval:com.tuxcare.clsa:tst:1775149050002"/>
        <criterion comment="alt-openssl-doc is earlier than 0:1.1.1w-3.2" test_ref="oval:com.tuxcare.clsa:tst:1775149050003"/>
        <criterion comment="alt-openssl-libs is earlier than 0:1.1.1w-3.2" test_ref="oval:com.tuxcare.clsa:tst:1775149050004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1776684331" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390</title>
        <affected family="unix">
          <platform>Ubuntu 22.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1776684331" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1776684331" source="CLSA"/>
        <reference ref_id="CVE-2026-28389" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-28389" source="CVE"/>
        <reference ref_id="CVE-2026-28390" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-28390" source="CVE"/>
        <reference ref_id="CVE-2026-28388" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-28388" source="CVE"/>
        <reference ref_id="CVE-2026-28387" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-28387" source="CVE"/>
        <description>* SECURITY UPDATE: use-after-free in DANE client code
     - debian/patches/openssl-1.1.1-cve-2026-28387.patch: use X509_free()
       instead of OPENSSL_free() to properly release reference-counted X509
       objects in dane_match()
     - CVE-2026-28387
   * SECURITY UPDATE: NULL pointer dereference in delta CRL processing
     - debian/patches/openssl-1.1.1-cve-2026-28388.patch: add NULL check for
       delta-&gt;crl_number before dereferencing in check_delta_base()
     - CVE-2026-28388
   * SECURITY UPDATE: NULL pointer dereference in CMS KeyAgreeRecipientInfo
     - debian/patches/openssl-1.1.1-cve-2026-28389.patch: use safe
       X509_ALGOR_get0() extraction in dh_cms_set_shared_info() and
       ecdh_cms_set_shared_info()
     - CVE-2026-28389
   * SECURITY UPDATE: NULL pointer dereference in CMS KeyTransportRecipientInfo
     - debian/patches/openssl-1.1.1-cve-2026-28390.patch: use safe
       X509_ALGOR_get0() extraction and OPENSSL_memdup() for label data in
       rsa_cms_decrypt()
     - CVE-2026-28390</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-04-20"/>
          <updated date="2026-04-20"/>
          <cve cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-166" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-28389" impact="moderate" public="20260407">CVE-2026-28389</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-476" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-28390" impact="important" public="20260407">CVE-2026-28390</cve>
          <cve cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-476" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-28388" impact="moderate" public="20260407">CVE-2026-28388</cve>
          <cve cvss3="3.7/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" cwe="CWE-1341" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-28387" impact="low" public="20260407">CVE-2026-28387</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-openssl is earlier than 0:1.1.1w-3.4" test_ref="oval:com.tuxcare.clsa:tst:1776684331001"/>
        <criterion comment="alt-openssl-dev is earlier than 0:1.1.1w-3.4" test_ref="oval:com.tuxcare.clsa:tst:1776684331002"/>
        <criterion comment="alt-openssl-doc is earlier than 0:1.1.1w-3.4" test_ref="oval:com.tuxcare.clsa:tst:1776684331003"/>
        <criterion comment="alt-openssl-libs is earlier than 0:1.1.1w-3.4" test_ref="oval:com.tuxcare.clsa:tst:1776684331004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1781799388" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-45447</title>
        <affected family="unix">
          <platform>Ubuntu 22.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1781799388" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1781799388" source="CLSA"/>
        <reference ref_id="CVE-2026-45447" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-45447" source="CVE"/>
        <description>* SECURITY UPDATE: use-after-free in PKCS7_verify
     - debian/patches/openssl-1.1.1-cve-2026-45447.patch: free the BIO chain
       explicitly and stop at the caller-supplied indata BIO so a crafted
       PKCS#7 / S-MIME message with an empty digestAlgorithms ASN.1 SET can no
       longer make OpenSSL free a caller-owned BIO in PKCS7_verify()
     - CVE-2026-45447</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-06-18"/>
          <updated date="2026-06-18"/>
          <cve cvss3="9.4/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-825" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-45447" impact="critical" public="20260609">CVE-2026-45447</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-openssl is earlier than 0:1.1.1w-3.5" test_ref="oval:com.tuxcare.clsa:tst:1781799388001"/>
        <criterion comment="alt-openssl-dev is earlier than 0:1.1.1w-3.5" test_ref="oval:com.tuxcare.clsa:tst:1781799388002"/>
        <criterion comment="alt-openssl-doc is earlier than 0:1.1.1w-3.5" test_ref="oval:com.tuxcare.clsa:tst:1781799388003"/>
        <criterion comment="alt-openssl-libs is earlier than 0:1.1.1w-3.5" test_ref="oval:com.tuxcare.clsa:tst:1781799388004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1785894684" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-69419</title>
        <affected family="unix">
          <platform>Ubuntu 22.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1785894684" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1785894684" source="CLSA"/>
        <reference ref_id="CVE-2025-69419" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-69419" source="CVE"/>
        <description>* SECURITY UPDATE: HollowByte handshake-buffer pre-allocation DoS
     - debian/patches/openssl-1.1.1-hollowbyte.patch: grow the handshake
       init_buf incrementally as data is received instead of pre-allocating
       the full peer-declared message size, so a peer that claims a large
       message but never sends it can no longer strand memory. Backport of
       OpenSSL 3.0 commit c5785a5e35 (PR #30794). OpenSSL handled this as a
       "bug or hardening" fix, so no CVE was assigned.
     - ELS-2635</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-08-05"/>
          <updated date="2026-08-05"/>
          <cve cvss3="7.4/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" cwe="CWE-787" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-69419" impact="important" public="20260127">CVE-2025-69419</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-openssl11 is earlier than 0:1.1.1w-3.7" test_ref="oval:com.tuxcare.clsa:tst:1785894684001"/>
        <criterion comment="alt-openssl11-dev is earlier than 0:1.1.1w-3.7" test_ref="oval:com.tuxcare.clsa:tst:1785894684002"/>
        <criterion comment="alt-openssl11-doc is earlier than 0:1.1.1w-3.7" test_ref="oval:com.tuxcare.clsa:tst:1785894684003"/>
        <criterion comment="alt-openssl11-libs is earlier than 0:1.1.1w-3.7" test_ref="oval:com.tuxcare.clsa:tst:1785894684004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1786472087" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-34180, CVE-2026-42766</title>
        <affected family="unix">
          <platform>Ubuntu 22.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1786472087" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1786472087" source="CLSA"/>
        <reference ref_id="CVE-2026-34180" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-34180" source="CVE"/>
        <reference ref_id="CVE-2026-42766" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-42766" source="CVE"/>
        <description>* SECURITY UPDATE: heap buffer over-read parsing large DER ASN.1 elements
     - debian/patches/openssl-1.1.1-cve-2026-34180.patch: keep the ASN.1
       content length as a long in asn1_ex_c2i() and reject elements whose
       length does not fit in an int, so a primitive element longer than
       2GB can no longer be truncated into a negative length and make
       ASN1_STRING_set() read past the end of the input buffer.
     - CVE-2026-34180
   * SECURITY UPDATE: NULL pointer dereference in password-based CMS decryption
     - debian/patches/openssl-1.1.1-cve-2026-42766.patch: check that the
       OPTIONAL PasswordRecipientInfo.keyDerivationAlgorithm field is present
       before dereferencing it in cms_RecipientInfo_pwri_crypt(), so a crafted
       password-encrypted CMS message can no longer crash the application.
     - CVE-2026-42766</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-08-11"/>
          <updated date="2026-08-11"/>
          <cve cvss3="8.2/CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H" cwe="CWE-125" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-34180" impact="important" public="20260609">CVE-2026-34180</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-476" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-42766" impact="important" public="20260609">CVE-2026-42766</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-openssl11 is earlier than 0:1.1.1w-3.8" test_ref="oval:com.tuxcare.clsa:tst:1786472087001"/>
        <criterion comment="alt-openssl11-dev is earlier than 0:1.1.1w-3.8" test_ref="oval:com.tuxcare.clsa:tst:1786472087002"/>
        <criterion comment="alt-openssl11-doc is earlier than 0:1.1.1w-3.8" test_ref="oval:com.tuxcare.clsa:tst:1786472087003"/>
        <criterion comment="alt-openssl11-libs is earlier than 0:1.1.1w-3.8" test_ref="oval:com.tuxcare.clsa:tst:1786472087004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789481975" version="1">
      <metadata>
        <title>Fix of 8 CVEs</title>
        <affected family="unix">
          <platform>Ubuntu 22.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789481975" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1789481975" source="CLSA"/>
        <reference ref_id="CVE-2026-86140" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86140" source="CVE"/>
        <reference ref_id="CVE-2026-86138" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86138" source="CVE"/>
        <reference ref_id="CVE-2026-86137" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86137" source="CVE"/>
        <reference ref_id="CVE-2025-24928" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-24928" source="CVE"/>
        <reference ref_id="CVE-2026-86144" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86144" source="CVE"/>
        <reference ref_id="CVE-2026-86142" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86142" source="CVE"/>
        <reference ref_id="CVE-2026-86141" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86141" source="CVE"/>
        <reference ref_id="CVE-2026-86143" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86143" source="CVE"/>
        <description>* SECURITY UPDATE: out-of-bounds read in the libxml2 regexp parser
     - debian/patches/libxml2-2.10.2-CVE-2026-86137.patch: bounds-check
       the parser cursor in xmlFAParsePosCharGroup before the NXT macro
       reads past the end of the expression; backport of upstream libxml2
       76fe08d9 (v2.15.4)
     - CVE-2026-86137
   * SECURITY UPDATE: integer overflow and heap buffer overflow in xmlDictAddQString
     - debian/patches/libxml2-2.10.2-CVE-2026-86138.patch: add overflow
       checks to the pool size arithmetic in dict.c before allocating and
       copying the qualified name; backport of upstream libxml2 a4cba4b5
       (v2.15.4)
     - CVE-2026-86138
   * SECURITY UPDATE: stack buffer overflow in xmlSnprintfElements
     - debian/patches/libxml2-2.10.2-CVE-2025-24928.patch: compute the
       combined QName length once, before any append, so the bounds check
       in the xmlSnprintfElements loop is no longer made against a stale
       buffer length; backport of upstream libxml2 8c8753ad (v2.14.0).
       This is the overflow that is reachable on 2.10.2: a DTD content
       model whose element QNames exceed the 5000-byte dump buffer
       (xmllint --valid) overflows the stack
     - CVE-2025-24928
   * SECURITY UPDATE: unchecked strcat around the xmlSnprintfElements loop
     - debian/patches/libxml2-2.10.2-CVE-2026-86140.patch: replace the
       unchecked strcat calls at the entry and exit of the DTD content-model
       dump in valid.c with bounds-checked appends; backport of upstream
       libxml2 d1686f91 (v2.15.4). On 2.10.2 both sites are hardening only:
       the function is static and its callers pass a freshly emptied buffer,
       so the overflow that can be reached is the one fixed by the
       CVE-2025-24928 patch above
     - CVE-2026-86140
   * SECURITY UPDATE: NULL pointer dereference in xmlRegNewParserCtxt
     - debian/patches/libxml2-2.10.2-CVE-2026-86141.patch: compute the
       expression length only after the xmlStrdup result has been NULL-
       checked in xmlregexp.c; backport of upstream libxml2 e89a8aae
       (v2.15.4)
     - CVE-2026-86141
   * SECURITY UPDATE: heap buffer overflow in xmlXPtrEvalXPtrPart
     - debian/patches/libxml2-2.10.2-CVE-2026-86142.patch: check the
       xpointer part length for overflow before allocating the evaluation
       buffer in xpointer.c; backport of upstream libxml2 6b3a736c
       (v2.15.4)
     - CVE-2026-86142
   * SECURITY UPDATE: negative lengths reaching output write callbacks
     - debian/patches/libxml2-2.10.2-CVE-2026-86143.patch: check for int
       overflow between xmlBufUse and the write callback length in
       xmlIO.c so a negative length can no longer reach
       xmlOutputWriteCallback; backport of upstream libxml2 90f293ba
       (v2.15.4)
     - CVE-2026-86143
   * SECURITY UPDATE: XInclude ignores the document parse flags
     - debian/patches/libxml2-2.10.2-CVE-2026-86144.patch: make
       xmlXIncludeProcess and xmlXIncludeProcessTree propagate the
       document's parseFlags (e.g. XML_PARSE_NONET) to the include
       context in xinclude.c; backport of upstream libxml2 b63cd517
       (v2.15.4)
     - Behaviour change: the include context now inherits every parse
       flag of the document, XML_PARSE_NOENT, XML_PARSE_RECOVER and
       XML_PARSE_HUGE included, not only XML_PARSE_NONET. A document
       parsed with XML_PARSE_NOENT and then passed to xmlXIncludeProcess()
       now also substitutes external entities inside the included
       documents; callers that must not load them should not pass
       XML_PARSE_NOENT, or should call xmlXIncludeProcessFlags() with an
       explicit flag set. PHP's DOMDocument::xinclude() already uses
       xmlXIncludeProcessFlags() and is unaffected
     - CVE-2026-86144
   * Fix deb packaging defects surfaced by the first Debian/Ubuntu build: point the
     alt-libxml2-devel libxml2.so symlink at the 2.10.2 soname (was 2.9.7) and
     repair the malformed 2.9.7-2 changelog trailer (three spaces before the date).</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-15"/>
          <updated date="2026-09-15"/>
          <cve cwe="CWE-121" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86140" impact="unknown" public="20260905">CVE-2026-86140</cve>
          <cve cwe="CWE-190" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86138" impact="unknown" public="20260905">CVE-2026-86138</cve>
          <cve cwe="CWE-125" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86137" impact="unknown" public="20260905">CVE-2026-86137</cve>
          <cve cvss3="7.7/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" cwe="CWE-121" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-24928" impact="important" public="20250218">CVE-2025-24928</cve>
          <cve cwe="CWE-669" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86144" impact="unknown" public="20260905">CVE-2026-86144</cve>
          <cve cwe="CWE-122" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86142" impact="unknown" public="20260905">CVE-2026-86142</cve>
          <cve cwe="CWE-252" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86141" impact="unknown" public="20260905">CVE-2026-86141</cve>
          <cve cwe="CWE-192" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-86143" impact="unknown" public="20260905">CVE-2026-86143</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-libxml2 is earlier than 0:2.10.2-4" test_ref="oval:com.tuxcare.clsa:tst:1789481975001"/>
        <criterion comment="alt-libxml2-devel is earlier than 0:2.10.2-4" test_ref="oval:com.tuxcare.clsa:tst:1789481975002"/>
        <criterion comment="alt-libxml2-doc is earlier than 0:2.10.2-4" test_ref="oval:com.tuxcare.clsa:tst:1789481975003"/>
        <criterion comment="alt-libxml2-static is earlier than 0:2.10.2-4" test_ref="oval:com.tuxcare.clsa:tst:1789481975004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789644637" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2024-56171, CVE-2026-6653</title>
        <affected family="unix">
          <platform>Ubuntu 22.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789644637" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1789644637" source="CLSA"/>
        <reference ref_id="CVE-2024-56171" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2024-56171" source="CVE"/>
        <reference ref_id="CVE-2026-6653" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-6653" source="CVE"/>
        <description>* SECURITY UPDATE: use-after-free after xmlSchemaItemListAdd
     - debian/patches/libxml2-2.10.2-CVE-2024-56171.patch: refresh the
       cached pointer to the duplicates array after xmlSchemaItemListAdd()
       may have reallocated it, in xmlSchemaIDCFillNodeTables and
       xmlSchemaBubbleIDCNodeTables in xmlschemas.c; backport of upstream
       libxml2 5880a9a6 (v2.12.10, v2.13.6, v2.14.0). Reachable from
       schema validation of an untrusted instance document that produces
       duplicate identity-constraint keys. The second site additionally
       checks xmlSchemaItemListAdd()'s return before refreshing the
       pointer: 2.10.2 assigns xmlRealloc()'s result straight to
       list-&gt;items, so unlike upstream it leaves it NULL on failure
     - CVE-2024-56171
   * SECURITY UPDATE: use-after-free in xmlParseInternalSubset
     - debian/patches/libxml2-2.10.2-CVE-2026-6653.patch: drop the
       post-push XML_PARSER_EOF check from xmlPushInput(), and give the
       xmlSkipBlankChars() loop an XML_PARSER_EOF guard, both in
       parser.c; backports of upstream libxml2 f19a9510 (its xmlPushInput
       hunk) and e129c1d1. xmlPushInput() tested for a halted parser only
       after inputPush() had already installed the input as ctxt-&gt;input,
       and then returned -1, so xmlParsePEReference() freed an input
       stream that ctxt-&gt;input still pointed at and a crafted DTD
       internal subset caused a heap use-after-free read in
       xmlParseInternalSubset(). With that input no longer freed the
       parser goes on to re-enter xmlSkipBlankChars(), whose loop was
       unconditional while NEXT is a no-op on a halted parser, so the
       same document would spin at 100% CPU instead of crashing; the
       guard ends the loop, matching the three other loops in the file.
       The halt comes from the entity amplification check added for
       CVE-2021-3541, which 2.10.2 carries; that check is left in place.
       The upstream fix for this CVE (463bbeec, v2.11.0) is not used: it
       appends members to the public xmlEntity and xmlParserInput
       structs, changing their size, and enforces the amplification cap
       even under XML_PARSE_HUGE
     - CVE-2026-6653</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-17"/>
          <updated date="2026-09-17"/>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2024-56171" impact="critical" public="20250218">CVE-2024-56171</cve>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-6653" impact="critical" public="20260622">CVE-2026-6653</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-libxml2 is earlier than 0:2.10.2-5" test_ref="oval:com.tuxcare.clsa:tst:1789644637001"/>
        <criterion comment="alt-libxml2-devel is earlier than 0:2.10.2-5" test_ref="oval:com.tuxcare.clsa:tst:1789644637002"/>
        <criterion comment="alt-libxml2-doc is earlier than 0:2.10.2-5" test_ref="oval:com.tuxcare.clsa:tst:1789644637003"/>
        <criterion comment="alt-libxml2-static is earlier than 0:2.10.2-5" test_ref="oval:com.tuxcare.clsa:tst:1789644637004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789646673" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-54874</title>
        <affected family="unix">
          <platform>Ubuntu 22.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789646673" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1789646673" source="CLSA"/>
        <reference ref_id="CVE-2026-54874" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-54874" source="CVE"/>
        <description>* SECURITY UPDATE: excessive memory use buffering DTLS records
     - debian/patches/openssl-1.1.1-cve-2026-54874.patch: copy only the record's
       own on-wire bytes into the queue entry in dtls1_buffer_record(), and copy
       them back into the live read buffer in dtls1_copy_record(), instead of
       handing the whole ~16.7KB read buffer to the queue and allocating a fresh
       one, so a peer sending a stream of tiny next-epoch records can no longer
       pin ~1.7MB of heap per connection; also lower the cap on the next-epoch
       (unprocessed_rcds) queue from 100 records to 16, which the same patch
       passes to dtls1_buffer_record() as an argument so that the other two
       queues keep the 100-record limit.
     - CVE-2026-54874</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-17"/>
          <updated date="2026-09-17"/>
          <cve cwe="CWE-405" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-54874" impact="unknown" public="20260825">CVE-2026-54874</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-openssl11 is earlier than 0:1.1.1w-3.10" test_ref="oval:com.tuxcare.clsa:tst:1789646673001"/>
        <criterion comment="alt-openssl11-dev is earlier than 0:1.1.1w-3.10" test_ref="oval:com.tuxcare.clsa:tst:1789646673002"/>
        <criterion comment="alt-openssl11-doc is earlier than 0:1.1.1w-3.10" test_ref="oval:com.tuxcare.clsa:tst:1789646673003"/>
        <criterion comment="alt-openssl11-libs is earlier than 0:1.1.1w-3.10" test_ref="oval:com.tuxcare.clsa:tst:1789646673004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789670491" version="1">
      <metadata>
        <title>Fix of 8 CVEs</title>
        <affected family="unix">
          <platform>Ubuntu 22.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789670491" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1789670491" source="CLSA"/>
        <reference ref_id="CVE-2026-11979" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-11979" source="CVE"/>
        <reference ref_id="CVE-2025-32415" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-32415" source="CVE"/>
        <reference ref_id="CVE-2022-49043" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2022-49043" source="CVE"/>
        <reference ref_id="CVE-2025-6021" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-6021" source="CVE"/>
        <reference ref_id="CVE-2022-40303" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2022-40303" source="CVE"/>
        <reference ref_id="CVE-2022-40304" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2022-40304" source="CVE"/>
        <reference ref_id="CVE-2024-25062" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2024-25062" source="CVE"/>
        <reference ref_id="CVE-2025-27113" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-27113" source="CVE"/>
        <description>* SECURITY UPDATE: NULL pointer dereference in xmlPatMatch
     - debian/patches/libxml2-2.10.2-CVE-2025-27113.patch: compile an
       explicit child:: axis step to XML_OP_ELEM instead of XML_OP_CHILD
       in xmlCompileStepPattern() in pattern.c; backport of upstream
       libxml2 503f788e (v2.12.10, v2.13.6, v2.14.0). XML_OP_CHILD accepts
       a document node and does not advance the current node, so a pattern
       such as "/child::name" matched against a document node reached the
       unguarded node-&gt;parent load in the XML_OP_ROOT case of xmlPatMatch()
       and crashed. Reachable through the public xmlPatternMatch(), used
       in-tree by xmlTextReaderPreservePattern() and by Schematron rule
       contexts; the streaming matcher already compiled the child axis
       correctly, so XML Schema identity constraints and the XPath
       streaming optimisation are unaffected. Upstream fixed only the
       compiler side and leaves the XML_OP_ROOT load unguarded to this day;
       it is left unguarded here too, and no in-tree caller reaches it.
       Behaviour change: patterns using the explicit child:: axis now
       select the named element itself rather than its parent, which is
       correct XPath and what the streaming matcher already did
     - CVE-2025-27113
   * SECURITY UPDATE: heap out-of-bounds read in xmlSchemaIDCFillNodeTables
     - debian/patches/libxml2-2.10.2-CVE-2025-32415.patch: use the live
       bind-&gt;nbNodes instead of the stale local nbNodeTable for both the
       guard and the terminator of the IDC node-table loop in
       xmlSchemaIDCFillNodeTables in xmlschemas.c; backport of upstream
       libxml2 384cc7c1 (v2.13.8), whose master twin is 487ee1d8
       (v2.14.2). nbNodeTable is snapshotted before the target loop, but
       the loop shrinks the node table every time it moves a duplicate
       key-sequence to bind-&gt;dupls, so from the next target onwards the
       loop walks slots past the live end of the table; once the table is
       empty the guard is still true and a match evaluates
       bind-&gt;nodeTable[-1], reading one element before the start of the
       heap allocation and leaving bind-&gt;nbNodes negative for the targets
       that follow. Reachable from schema validation of an untrusted
       instance document against a schema carrying identity constraints,
       or from an untrusted schema. Applied on top of
       libxml2-2.10.2-CVE-2024-56171.patch, which edits the same function
       but a different defect (a stale pointer rather than a stale count)
       and does not overlap these hunks
     - CVE-2025-32415
   * SECURITY UPDATE: integer overflow in xmlBuildQName leading to a
     stack-based buffer overflow
     - debian/patches/libxml2-2.10.2-CVE-2025-6021.patch: hold the
       local-name and prefix lengths in size_t, reject a negative len, and
       bound lenn + lenp + 2 against SIZE_MAX before the buffer-size test
       and the allocation, in tree.c; backport of upstream libxml2
       17d950ae (v2.13.9). The lengths were held in int and summed in int
       arithmetic, so a long enough QName made lenn + lenp + 2 wrap
       negative, which both defeated the buffer-size test - handing back a
       caller's 50-byte stack buffer - and undersized the xmlMallocAtomic()
       allocation, letting the following memcpy()s and the NUL store write
       out of bounds
     - CVE-2025-6021
   * SECURITY UPDATE: stack-based buffer overflows in xmlcatalog --shell
     - debian/patches/libxml2-2.10.2-CVE-2026-11979.patch: bounds-check the
       three copy loops in usershell() in xmlcatalog.c, which wrote a line
       of user input into the fixed command[100], arg[400] and argv[20]
       stack buffers with no limit at all; backport of upstream libxml2
       cd48d441 (v2.15.4), whose xmlcatalog.c hunks are identical to
       master's c2e233fc. Over-long input is now rejected with a diagnostic
       instead of corrupting the stack frame. Upstream's
       test/catalogs/test.sh hunk is dropped because that file does not
       exist in 2.10.2; usershell() itself is byte-identical to upstream's
       pre-fix version, so the guards are carried verbatim. Affects only
       the xmlcatalog command-line utility shipped by this package -- no
       library entry point reaches usershell()
     - CVE-2026-11979
   * Harden the xmlcatalog command line parser
     - debian/patches/libxml2-2.10.2-xmlcatalog-argv-oob-read.patch: check
       that --add and --del were given enough arguments before indexing
       argv in main() in xmlcatalog.c; backport of upstream libxml2
       b1fea45b. This is not a CVE and is not part of CVE-2026-11979; it
       is carried alongside it because upstream shipped both in the same
       release and both touch the same file. "xmlcatalog --add a" read
       argv[4] past the end of the argument vector and passed whatever
       followed it, in practice a process environment string, to
       xmlCatalogAdd()</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-17"/>
          <updated date="2026-09-17"/>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-121" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-11979" impact="important" public="20260629">CVE-2026-11979</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-1284" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-32415" impact="important" public="20250417">CVE-2025-32415</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2022-49043" impact="important" public="20250126">CVE-2022-49043</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-787" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-6021" impact="important" public="20250612">CVE-2025-6021</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-190" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2022-40303" impact="important" public="20221123">CVE-2022-40303</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-415" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2022-40304" impact="important" public="20221123">CVE-2022-40304</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2024-25062" impact="important" public="20240204">CVE-2024-25062</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-476" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2025-27113" impact="important" public="20250218">CVE-2025-27113</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-libxml2 is earlier than 0:2.10.2-7" test_ref="oval:com.tuxcare.clsa:tst:1789670491001"/>
        <criterion comment="alt-libxml2-devel is earlier than 0:2.10.2-7" test_ref="oval:com.tuxcare.clsa:tst:1789670491002"/>
        <criterion comment="alt-libxml2-doc is earlier than 0:2.10.2-7" test_ref="oval:com.tuxcare.clsa:tst:1789670491003"/>
        <criterion comment="alt-libxml2-static is earlier than 0:2.10.2-7" test_ref="oval:com.tuxcare.clsa:tst:1789670491004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789737730" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-89157, CVE-2026-89158</title>
        <affected family="unix">
          <platform>Ubuntu 22.04 LTS</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789737730" ref_url="https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1789737730" source="CLSA"/>
        <reference ref_id="CVE-2026-89158" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-89158" source="CVE"/>
        <reference ref_id="CVE-2026-89157" ref_url="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-89157" source="CVE"/>
        <description>* EA4D-994: Update to 10.48 version
   * Bundled Unicode data updated 16.0 -&gt; 17.0, changing what existing patterns
     match with no soname change: \d gains U+11DE0-U+11DE9, \w and \p{L} gain
     characters too, and U+0320 no longer matches \p{Latin}. Anything linked
     against libpcre2-8.so.0 sees this on upgrade without a rebuild; alt-php
     uses PHP's bundled PCRE2 and is not affected.</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-18"/>
          <updated date="2026-09-18"/>
          <cve cvss3="9.4/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L" cwe="CWE-190" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-89158" impact="critical" public="20260911">CVE-2026-89158</cve>
          <cve cvss3="9.4/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H" cwe="CWE-190" href="https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-89157" impact="critical" public="20260911">CVE-2026-89157</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-pcre2 is earlier than 0:10.48-1" test_ref="oval:com.tuxcare.clsa:tst:1789737730001"/>
        <criterion comment="alt-pcre2-dev is earlier than 0:10.48-1" test_ref="oval:com.tuxcare.clsa:tst:1789737730002"/>
        <criterion comment="alt-pcre2-static is earlier than 0:10.48-1" test_ref="oval:com.tuxcare.clsa:tst:1789737730003"/>
        <criterion comment="alt-pcre2-tools is earlier than 0:10.48-1" test_ref="oval:com.tuxcare.clsa:tst:1789737730004"/>
        <criterion comment="alt-pcre2-utf16 is earlier than 0:10.48-1" test_ref="oval:com.tuxcare.clsa:tst:1789737730005"/>
        <criterion comment="alt-pcre2-utf32 is earlier than 0:10.48-1" test_ref="oval:com.tuxcare.clsa:tst:1789737730006"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl is earlier than 0:1.1.1w-3.1" id="oval:com.tuxcare.clsa:tst:1774528491001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1774528491001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1774528491001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl-dev is earlier than 0:1.1.1w-3.1" id="oval:com.tuxcare.clsa:tst:1774528491002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1774528491002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1774528491001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl-doc is earlier than 0:1.1.1w-3.1" id="oval:com.tuxcare.clsa:tst:1774528491003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1774528491003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1774528491003"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl-libs is earlier than 0:1.1.1w-3.1" id="oval:com.tuxcare.clsa:tst:1774528491004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1774528491004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1774528491001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl is earlier than 0:1.1.1w-3.2" id="oval:com.tuxcare.clsa:tst:1775149050001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1774528491001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1775149050001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl-dev is earlier than 0:1.1.1w-3.2" id="oval:com.tuxcare.clsa:tst:1775149050002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1774528491002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1775149050001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl-doc is earlier than 0:1.1.1w-3.2" id="oval:com.tuxcare.clsa:tst:1775149050003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1774528491003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1775149050003"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl-libs is earlier than 0:1.1.1w-3.2" id="oval:com.tuxcare.clsa:tst:1775149050004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1774528491004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1775149050001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl is earlier than 0:1.1.1w-3.4" id="oval:com.tuxcare.clsa:tst:1776684331001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1774528491001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776684331001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl-dev is earlier than 0:1.1.1w-3.4" id="oval:com.tuxcare.clsa:tst:1776684331002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1774528491002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776684331001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl-doc is earlier than 0:1.1.1w-3.4" id="oval:com.tuxcare.clsa:tst:1776684331003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1774528491003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776684331003"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl-libs is earlier than 0:1.1.1w-3.4" id="oval:com.tuxcare.clsa:tst:1776684331004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1774528491004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1776684331001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl is earlier than 0:1.1.1w-3.5" id="oval:com.tuxcare.clsa:tst:1781799388001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1774528491001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781799388001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl-dev is earlier than 0:1.1.1w-3.5" id="oval:com.tuxcare.clsa:tst:1781799388002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1774528491002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781799388001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl-doc is earlier than 0:1.1.1w-3.5" id="oval:com.tuxcare.clsa:tst:1781799388003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1774528491003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781799388003"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl-libs is earlier than 0:1.1.1w-3.5" id="oval:com.tuxcare.clsa:tst:1781799388004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1774528491004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1781799388001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl11 is earlier than 0:1.1.1w-3.7" id="oval:com.tuxcare.clsa:tst:1785894684001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1785894684001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1785894684001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl11-dev is earlier than 0:1.1.1w-3.7" id="oval:com.tuxcare.clsa:tst:1785894684002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1785894684002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1785894684001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl11-doc is earlier than 0:1.1.1w-3.7" id="oval:com.tuxcare.clsa:tst:1785894684003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1785894684003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1785894684003"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl11-libs is earlier than 0:1.1.1w-3.7" id="oval:com.tuxcare.clsa:tst:1785894684004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1785894684004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1785894684001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl11 is earlier than 0:1.1.1w-3.8" id="oval:com.tuxcare.clsa:tst:1786472087001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1785894684001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1786472087001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl11-dev is earlier than 0:1.1.1w-3.8" id="oval:com.tuxcare.clsa:tst:1786472087002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1785894684002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1786472087001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl11-doc is earlier than 0:1.1.1w-3.8" id="oval:com.tuxcare.clsa:tst:1786472087003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1785894684003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1786472087003"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl11-libs is earlier than 0:1.1.1w-3.8" id="oval:com.tuxcare.clsa:tst:1786472087004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1785894684004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1786472087001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-libxml2 is earlier than 0:2.10.2-4" id="oval:com.tuxcare.clsa:tst:1789481975001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1789481975001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1789481975001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-libxml2-devel is earlier than 0:2.10.2-4" id="oval:com.tuxcare.clsa:tst:1789481975002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1789481975002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1789481975001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-libxml2-doc is earlier than 0:2.10.2-4" id="oval:com.tuxcare.clsa:tst:1789481975003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1789481975003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1789481975003"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-libxml2-static is earlier than 0:2.10.2-4" id="oval:com.tuxcare.clsa:tst:1789481975004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1789481975004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1789481975001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-libxml2 is earlier than 0:2.10.2-5" id="oval:com.tuxcare.clsa:tst:1789644637001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1789481975001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1789644637001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-libxml2-devel is earlier than 0:2.10.2-5" id="oval:com.tuxcare.clsa:tst:1789644637002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1789481975002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1789644637001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-libxml2-doc is earlier than 0:2.10.2-5" id="oval:com.tuxcare.clsa:tst:1789644637003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1789481975003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1789644637003"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-libxml2-static is earlier than 0:2.10.2-5" id="oval:com.tuxcare.clsa:tst:1789644637004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1789481975004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1789644637001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl11 is earlier than 0:1.1.1w-3.10" id="oval:com.tuxcare.clsa:tst:1789646673001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1785894684001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1789646673001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl11-dev is earlier than 0:1.1.1w-3.10" id="oval:com.tuxcare.clsa:tst:1789646673002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1785894684002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1789646673001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl11-doc is earlier than 0:1.1.1w-3.10" id="oval:com.tuxcare.clsa:tst:1789646673003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1785894684003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1789646673003"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-openssl11-libs is earlier than 0:1.1.1w-3.10" id="oval:com.tuxcare.clsa:tst:1789646673004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1785894684004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1789646673001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-libxml2 is earlier than 0:2.10.2-7" id="oval:com.tuxcare.clsa:tst:1789670491001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1789481975001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1789670491001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-libxml2-devel is earlier than 0:2.10.2-7" id="oval:com.tuxcare.clsa:tst:1789670491002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1789481975002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1789670491001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-libxml2-doc is earlier than 0:2.10.2-7" id="oval:com.tuxcare.clsa:tst:1789670491003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1789481975003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1789670491003"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-libxml2-static is earlier than 0:2.10.2-7" id="oval:com.tuxcare.clsa:tst:1789670491004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1789481975004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1789670491001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-pcre2 is earlier than 0:10.48-1" id="oval:com.tuxcare.clsa:tst:1789737730001" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1789737730001"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1789737730001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-pcre2-dev is earlier than 0:10.48-1" id="oval:com.tuxcare.clsa:tst:1789737730002" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1789737730002"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1789737730001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-pcre2-static is earlier than 0:10.48-1" id="oval:com.tuxcare.clsa:tst:1789737730003" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1789737730003"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1789737730001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-pcre2-tools is earlier than 0:10.48-1" id="oval:com.tuxcare.clsa:tst:1789737730004" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1789737730004"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1789737730001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-pcre2-utf16 is earlier than 0:10.48-1" id="oval:com.tuxcare.clsa:tst:1789737730005" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1789737730005"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1789737730001"/>
    </linux:dpkginfo_test>
    <linux:dpkginfo_test check="at least one" comment="alt-pcre2-utf32 is earlier than 0:10.48-1" id="oval:com.tuxcare.clsa:tst:1789737730006" version="1">
      <linux:object object_ref="oval:com.tuxcare.clsa:obj:1789737730006"/>
      <linux:state state_ref="oval:com.tuxcare.clsa:ste:1789737730001"/>
    </linux:dpkginfo_test>
  </tests>
  <objects>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1774528491001" version="1">
      <linux:name>alt-openssl</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1774528491002" version="1">
      <linux:name>alt-openssl-dev</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1774528491003" version="1">
      <linux:name>alt-openssl-doc</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1774528491004" version="1">
      <linux:name>alt-openssl-libs</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1785894684001" version="1">
      <linux:name>alt-openssl11</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1785894684002" version="1">
      <linux:name>alt-openssl11-dev</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1785894684003" version="1">
      <linux:name>alt-openssl11-doc</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1785894684004" version="1">
      <linux:name>alt-openssl11-libs</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789481975001" version="1">
      <linux:name>alt-libxml2</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789481975002" version="1">
      <linux:name>alt-libxml2-devel</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789481975003" version="1">
      <linux:name>alt-libxml2-doc</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789481975004" version="1">
      <linux:name>alt-libxml2-static</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789737730001" version="1">
      <linux:name>alt-pcre2</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789737730002" version="1">
      <linux:name>alt-pcre2-dev</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789737730003" version="1">
      <linux:name>alt-pcre2-static</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789737730004" version="1">
      <linux:name>alt-pcre2-tools</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789737730005" version="1">
      <linux:name>alt-pcre2-utf16</linux:name>
    </linux:dpkginfo_object>
    <linux:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789737730006" version="1">
      <linux:name>alt-pcre2-utf32</linux:name>
    </linux:dpkginfo_object>
  </objects>
  <states>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1774528491001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:1.1.1w-3.1</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1774528491003" version="1">
      <linux:evr datatype="evr_string" operation="less than">0:1.1.1w-3.1</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1775149050001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:1.1.1w-3.2</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1775149050003" version="1">
      <linux:evr datatype="evr_string" operation="less than">0:1.1.1w-3.2</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1776684331001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:1.1.1w-3.4</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1776684331003" version="1">
      <linux:evr datatype="evr_string" operation="less than">0:1.1.1w-3.4</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1781799388001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:1.1.1w-3.5</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1781799388003" version="1">
      <linux:evr datatype="evr_string" operation="less than">0:1.1.1w-3.5</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1785894684001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:1.1.1w-3.7</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1785894684003" version="1">
      <linux:evr datatype="evr_string" operation="less than">0:1.1.1w-3.7</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1786472087001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:1.1.1w-3.8</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1786472087003" version="1">
      <linux:evr datatype="evr_string" operation="less than">0:1.1.1w-3.8</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789481975001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.10.2-4</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789481975003" version="1">
      <linux:evr datatype="evr_string" operation="less than">0:2.10.2-4</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789644637001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.10.2-5</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789644637003" version="1">
      <linux:evr datatype="evr_string" operation="less than">0:2.10.2-5</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789646673001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:1.1.1w-3.10</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789646673003" version="1">
      <linux:evr datatype="evr_string" operation="less than">0:1.1.1w-3.10</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789670491001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:2.10.2-7</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789670491003" version="1">
      <linux:evr datatype="evr_string" operation="less than">0:2.10.2-7</linux:evr>
    </linux:dpkginfo_state>
    <linux:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789737730001" version="1">
      <linux:arch datatype="string" operation="equals">amd64</linux:arch>
      <linux:evr datatype="evr_string" operation="less than">0:10.48-1</linux:evr>
    </linux:dpkginfo_state>
  </states>
</oval_definitions>
