Procedure for dealing with package updates that fix CVEs?
Samuel Young <[email protected]> Thu, 9 Jul 2026 10:51:40 -0500
| Newsgroups | gmane.linux.debian.devel.perl |
|---|---|
| Message-ID | <CAJ95btrf=SgWEqmaCck5ZHVMpsevgnsT+_NGP3GNc+XGrpGoGw@mail.gmail.com> |
I've been working on updating the libhttp-date-perl package to 6.08, which includes a fix to CVE-2026-14741. In the package's changelog, I've mentioned the CVE the update fixed. Is there anything else I should do about the CVE? As of right now, there doesn't seem to be a bug report or security issue filed for the CVE.