Re: bouncycastle: proposed bullseye LTS fix for CVE-2026-5588
Hello James,
On 20/04/2026 04:12, James Montgomery wrote:
I am new to LTS contribution and not a DD, so I have not claimed
bouncycastle in dla-needed.txt or attempted any upload.
I prepared a candidate bullseye-security update for CVE-2026-5588:
bouncycastle 1.68-2+deb11u1.
I posted the debdiff and validation summary to the BTS here:
https://bugs.debian.org/1134196
Summary:
- backports upstream commit:
https://github.com/bcgit/bc-java/commit/656bae0dbd9b1521f840521ff786e78749fe3057
- adds a regression test for an empty composite signature sequence
- clean bullseye pbuilder build passed
- targeted runtime check against the built libbcprov/libbcpkix jars passed
- lintian reports only pre-existing doc-package embedded JavaScript warnings
- no autopkgtest exists for this source package
I would appreciate guidance on whether this is useful for LTS review or
sponsorship, and whether I should claim the package in dla-needed.txt or
adjust the workflow.
Thanks for your interest in Debian LTS.
These appear to be your first contributions to Debian. I would recommend
starting with less sensitive and more accessible areas, such as Bug of
the Day http://blends.debian.net/botd/botd.html and more generally the
Debian New Member process https://nm.debian.org/ to e.g. get DM status.
In particular, we try not to perform security uploads for single-CVE
updates, and the update focuses more on thorough regression testing
(including rdeps) than on backporting itself, making this kind of
contribution less useful to the team.
Cheers!
Sylvain Beucler
Debian LTS Team
Reply to: