Re: Procedure for dealing with package updates that fix CVEs?
Sebastiaan Couwenberg <[email protected]> Thu, 9 Jul 2026 18:12:49 +0200
| Newsgroups | gmane.linux.debian.devel.perl |
|---|---|
| Message-ID | <[email protected]> |
On 7/9/26 5:51 PM, Samuel Young wrote: > I've been working on updating the libhttp-date-perl package to 6.08, > which includes a fix to CVE-2026-14741. In the package's changelog, > I've mentioned the CVE the update fixed. Is there anything else I > should do about the CVE? As of right now, there doesn't seem to be a > bug report or security issue filed for the CVE. DevRef documents the security uploads workflow: https://www.debian.org/doc/manuals/developers-reference/pkgs.en.html#bug-security Kind Regards, Bas