[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: bookwork-pu for glibc CVE-2025-4802



Hello,

On Tue 27 May 2025 at 06:29pm +02, Aurelien Jarno wrote:

> Hi Sean,
>
> On 2025-05-27 15:26, Sean Whitton wrote:
>> Hello Aurelien,
>>
>> May I use the bookworm branch of glibc.git on salsa to prepare a
>> bookworm-pu for CVE-2025-4802, please?
>>
>> I'm asking because in our notes it says that LTS contributors are
>> welcome to use the *-security branches of your repository, but
>> (implicitly) not others.
>
> Please do not use the bookworm branch for that, as we usually follow
> the upstream branch for pu uploads, which usually include the security
> fixes. And if it is not the case we work with upstream to include them.
>
> Also in that specific case, I have been coordinating the fixes with the
> security team, so the bookworm branch already contains the fix for
> CVE-2025-4802 since last Sunday.

Thank you very much for the info.

-- 
Sean Whitton

Attachment: signature.asc
Description: PGP signature


Reply to: