[ANNOUNCE] Release of dpkg 1.20.14
Guillem Jover <[email protected]> Mon, 6 Jul 2026 04:17:18 +0200
| Newsgroups | gmane.linux.debian.devel.dpkg.general |
|---|---|
| Message-ID | <[email protected]> |
--0MhBBJKM++ql1wLt Content-Type: text/plain; protected-headers=v1; charset=us-ascii Content-Disposition: inline Date: Mon, 6 Jul 2026 04:17:18 +0200 From: Guillem Jover <[email protected]> To: [email protected] Cc: Arnaud Rebillout <[email protected]> Subject: [ANNOUNCE] Release of dpkg 1.20.14 Hi! I've just done an upstream-only source tarball release for the 1.20.x series (Debian bullseye), as I had it laying around pending release, and it was also requested by Arnaud (CCed) for the Debian LTS project. This includes a security fix for the .deb cleanup of control members with restricted directories during extraction (CVE-2025-6297), a read overrun when parsing long GNU tar name and link entries not NUL-terminated, a segfault fix when adding triggers in no-act mode, a couple of robustness fixes for Rules-Requires-Root field handling, and a localization fix. All these fixes were (when relevant) also part of previous 1.21.x and 1.22.x security/stable releases. The code is available as a signed tag on git.dpkg.org: <https://git.dpkg.org/cgit/dpkg/dpkg.git/tag/?h=1.20.14> And as a signed tarball on: <https://www.dpkg.org/releases/dpkg-1.20.14.tar.xz> <https://www.dpkg.org/releases/dpkg-1.20.14.tar.xz.asc> Thanks, Guillem --0MhBBJKM++ql1wLt Content-Type: application/pgp-signature; name=signature.asc -----BEGIN PGP SIGNATURE----- wsG7BAEBCgBvBYJqSxAuCRC5cr8+pK5Xo0cUAAAAAAAeACBzYWx0QG5vdGF0aW9u cy5zZXF1b2lhLXBncC5vcmda9zaOHpugq4WqRDgxI0Mn/LggeKWW7OfHCwAO4hAE xBYhBE8+dPQ2BQwQ9WlldLlyvz6krlejAAA+yBAAs8PpSJoHhgnStEO2zfvUMaFF iukZDg97JdNyxHzcRhIinpltboKPBntfbx58cNOu9kURx3PMBCR7aLb1fFSC1H/u adVkHD6aB/QpcaAPVEJfdngWwa00U/ECTV5M4du9kk4t6qjI4bZTN/d1iHD2UhuP o1tJrV6+ELD16N7dmCIWkU6AgyoLg1OT3nMVDgexlEYAhM0XiXwN3DfJ2A5TERkL f9osVskM421K0CH4v0KIQqJhY4ZkCEi7xHg06ih/1C9rtSinc0XsKeFujU+hK6PT xk4qYhKTiBlxPIh0hdzBvFuDZKEdFe+YKHo8wbTtP/kTzbBxlgvdjES5dxgQIe12 xXyqVIshS2oH/Ki0W+OzKgO+yYvdOsY9KbittxL1ZVfKdGGVXYUM/0Zo7T8Jn4lQ jmRb4gB5QThWEts+bIL8qw2PC1Rew1WbXRspPhVS1sl3wqmSxhCC8xQYyLPUDEoI 9t7AIbRAlRANyVcOktiYb3QVMLzY8PjWOu3RsfyJ5NryuqFUZxROdrNuyqfqy5lz 2MkavXo8Valm7qJ6U4rLKSh0+CFuNG/txcDUkBj8oddubw+L13xmc/fKerNDdtZl QW8M1tNia0UpVaVKLDZglGaC0WXIl9AvCweal6ARN4OBqDLec026E53/QTltaA5h V5AQ/92dZWqa+tbrDRg= =zKks -----END PGP SIGNATURE----- --0MhBBJKM++ql1wLt--