[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

E?LTS report



I've worked during September on the below listed packages, for Freexian
LTS/ELTS [1]

Many thanks to Freexian and our sponsors [2] for providing this opportunity!

ELTS
====

ca-certificates-java
---------------------------

release ELA-1514-1 fixing a bug blocking security update of ca-certificates

imagemagick
--------------------
backport to buster
release ELA-1515-1 fixing CVE-2025-53014 CVE-2025-53019 CVE-2025-53101 CVE-2025-55154 CVE-2025-55212 CVE-2025-55298 CVE-2025-57803 CVE-2025-57807
backport to stretch fixing same CVEs

pam
------

release ELA 1522-1 fixing CVE-2024-22365 and CVE-2025-6020

ceph
-------

stretch and buster fix fixing  CVE-2025-52555 ELA-1526-1

freeipa
----------

patch bookworm
 determine that CVE-2025-4404 should be ignored for bookworm, server is not packaged.
Retriagge other CVEs
Fix remaining CVE and evoluate new CVEs.
Test fixes

LTS
===

imagemagick
--------------------

fix imagemagick sid
fix bookworm
fix bullseye

shibboleth-sp

Release DLA-4300-1 fixing CVE-2025-9943

node-sha.js
----------------

release DLA-4302-1

pam
-------

Release DLA-4306-1 fixing CVE-2024-22365 and CVE-2025-6020 in pam namespace. Add extensive test

ceph
--------

Release fix for  CVE-2025-52555

squid
--------

Release DLA 4312-1 fixing CVE-2023-5824 CVE-2023-46728 CVE-2025-54574

Other
=====

I was FD.


Cheers

rouca

[1]  https://www.freexian.com/lts/
[2]  https://www.freexian.com/lts/debian/#sponsors

Attachment: signature.asc
Description: This is a digitally signed message part.


Reply to: