Latest updates delete libxml2-2

Hey!

So the latest updates on slowroll delete libxml2-2. I know the system has been using libxml2-16 for a while, but Ineed libxml2-2 for Cisco Anyconnect, since my workspace only allows this VPN, not even OpenVPN sadly.

Eralier I’ve installed libxml2-2 from a differrent repo and Slowroll updated everything nicely, but now it deletes it and Anyconnect stops working.

Tha latest Cisco Secure Clients still depend on libxml2-2 as far as I know.

Any suggestions how to solve this?

@ChaserHUN

Yeah, the same thing happened to my system. I had installed libxml2-2 from this repo home:alvistack (openSUSE_Tumbleweed) and for some reason the repo removed it too and since the repo removed it, zypper uninstalled it from my system too. As a result viber doesn’t start anymore.

This page, says that community packages are still available in two repos. I don’t know whether those repos are safe though. If anyone here can verify that we can install libxml2-2 safely from either of those two repos, we can do that possibly.

You could download the libxml2-2.13.8-1.4.src.rpm from wolfii323 Repo and build it by your own:
rpmbuild --rebuild libxml2-2.13.8-1.4.src.rpm

Well I’ve locked libxml2-2, and when running sudo zypper dup it didn’t conflict with anything, so the updates ran and Cicso is still working.

BTW when I first updated and it deleted the alvistack version and I installed another one somehow Cisco didn’t work anymore. When I rolled back and did what I wrote earlier it worked.

Download the libxml2-2 and keep it for safety. You can create a directory repo so in case you will need it in the future you can always install it.

@conram

Is libxml2-2 still being developed?

I have installed it from the wolfie323 repo and every time i do a zypper dup, the system finds newer versions of two other packages in that repo, and it keeps asking me whether I’d like to install them from that repo or keep the existing ones.

Of course I’m keeping the existing ones so far but this continuous questioning is a bit annoying. So, if libxml2-2 has stopped being developed and no newer versions are to be expected, I’d rather lock the installed package and either disable or remove the wolfie323 repo, since I do not use it for anything else.

What would you suggest?
Thank you.

The libxml2-2 version you use from this home repository is deprecated and does not recieve any updates anymore. That is the reason it was removed from TW and SR. In Leap 16.0 the same version is used but at least it recieved a lot of patches to fix several CVEs. It is questionable if an up to date Anyconnect version still relies on this deprecated libxml2-2 version. From another thread of you, one could see that your company was using an Anyconnect version which is already EOL and no longer supported by the manufacturer.

If you need to use an insecure libxml2-2 version, you should at least disable this home repo. It contains a full set of KDE Frameworks5 packages which is useless on an actual Leap 16, Slowroll or Tumbleweed system with Plasma 6.

@hui

The only app that needs it on my system is viber. It doesn’t start if libxml2-2 is removed. I have installed the .rpm version of the app from viber.com.

An alternative would be to use the appimage they offer but since libxml2-2 is not maintained anymore, would switching to the appimage make any difference?

I’d say the problem does not exist. It is caused by outdated software versions and shows that Viber does not care about keeping the rpm they offer up to date and modern standards. Where FYI the flatpak works fine and does not require you to break your system with EOL packages.

1 Like

@alexsec What I mean is download the libxml rpm from the wolfi repo and save it on your directory repositoy. You can create the repository using myrlyn. you can lock the package and remove the wolfi repository but you still have the rpm package available.

Yeah but Ciscso still hasn’t made a version that uses libxml2-16. It was a bit stupid to just switch out libxml2-2 to 2-16 this way like lot of distros did.

libxml2-2 is from April 2025. It has 4 open CVEs and 8 other security issues. So why is it stupid to replace an insecure version for newer versions where the issues are fixed?

You or your employer should ask Cisco instead why you have to pay them money when they can’t even properly maintain their so called “security software”.

I saw this issue with lot of people with lot of distros. And on other distros they couldn’t even install libxml2-2 like you can on Opensuse.

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.