[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Debian 11 rear CVE-2024-23301



Hi,

On 09/12/2025 09:13, Schöke, Karsten wrote:
I've been maintainer for rear for quite some time.

After updating the source package upstream, I'm now working on patching CVE-2024-23301 [1].
I've set up a PU [2] for bookworm and already uploaded it to the archive.

Now I also wanted to perform an LTS upload for bullseye and planned to follow these instructions [3].

I'm allowed to do this as a regular DM?
Can I use the existing DLA [4] that's used in buster for bullseye as well?
Thanks for taking over the maintenance of rear since October.

As a DM you can prepare the upload, but you'll need a DD to perform the actual upload. I would recommend that you prepare the upload, make it available on Salsa and propose it to this list. An LTS team member should volunteer to review, upload, and take care of the announcement as well as other administrativia. The LTS Team member will also register a new DLA, don't reuse the buster one.

Cheers!
Sylvain Beucler
Debian LTS Team


Reply to: