April (E)LTS Report


Here are my LTS and ELTS reports for April 2019.

Debian LTS report

I was allocated 17.25 hours. I have spent all of them in the following


  + Triage security backlog. Reproduce issues and coordinate with upstream
    to get rid of our huge undetermined backlog (35+ issues).


  + Continue to work on my patch for CVE-2018-20362, coordinate to get it
    reviewed and merged upstream.

    Involved a lot of (painful) research in ISO/IEC 13818-7:2006.

  + Provide in depth analysis for CVE-2018-19887 and prepare a patch.
    Coordinate to get it reviewed and merged upstream.

    Involved a lot of research in ISO/IEC 14496-3:2001.

    (See upstream bug reports for detailed information.)


  + Analyse CVE-2019-10906, develop a POC to assess vulnerability and
    reproduce on all suites. Find related patches and coordinate with
    security team and maintainer for update. Ongoing work.


  + Prepare a security update addressing CVE-2018-10243 and CVE-2018-10242,
    test and upload it (DLA-1751-1). Analyse CVE-2018-10244 and mark it
    not-affected in jessie.


  + CVE triage work for, among others, libvirt, systemd.
  + help Markus diagnose graphicsmagik problems with failing testsuite,
    resulting in jasper regression update later.

Debian ELTS report

I was allocated 9 hours. I have spent all of them in the following


  + Analyse CVE-2018-10244, CVE-2018-10243 and CVE-2018-10242, not-affected
    in wheezy.


  + Analyse CVE-2019-10902 and CVE-2019-10896, not-affected in wheezy.

    Reproduce CVE-2019-10903, CVE-2019-10901 and CVE-2019-10899. Prepare,
    test and upload a security update addressing these issues (ELA-106-1).


  + Analyse CVE-2019-3886 and mark it not-affected in wheezy.


  + CVE-2018-19217 analysis and triage. Discussion with Sylvain about
    not-affected status.


  + Triage CVE-2019-11068, prepare, test and upload a security update
    addressing this vulnerability (ELA-107-1).


  + Analyse CVE-2019-9619 and CVE-2019-3842 and get in coordinate with Mike
    Gabriel for update.


  + CVE triage

Early report this month. I was allocated less LTS hours than last month and
spent a lot of time on faad2 patches, hdf5 and jinja2 triage. The number of
released DLAs is low (only one in total), but I have four pending
(wireshark, hdf5, faad2 waiting for more patches, and jinja2 for answer
from secteam).

Concerning ELTS, the number of updates was limited to two. Testing the
wireshark update was longer than expected and releasing binaries for both
amd64 and i386 has its overhead.


