Debian (E)LTS report for August 2025
Hi everyone,
In August I worked on fixing git in bullseye, namely:
- CVE-2025-48384
And validated that git/bullseye is unaffected by CVE-2025-48385. I also did some
cleanup on the patches of the previous two CVEs I worked on from last month and
also attempted to reproduce the CVE-2025-27613 with the unpatched git version
since the patch is quite large, however I could not trigger the security hole.
I did some changes to the git LTS repo to conform to DEP-14. I also started
patching git/bookworm. Since the patching workflow for the Debian packaging repo
is unclear to me, I decided to add bookworm to the LTS repo and follow standard
DEP-14/gbp practice.
Thanks to our sponsors for financing this work, and to Freexian for coordinating!
Regards,
Lee Garrett,
Debian LTS Team
Reply to: