Re: Procedure for dealing with package updates that fix CVEs?

Sebastiaan Couwenberg <[email protected]> Thu, 9 Jul 2026 18:12:49 +0200
Newsgroups gmane.linux.debian.devel.perl
Message-ID <[email protected]>
On 7/9/26 5:51 PM, Samuel Young wrote:
> I've been working on updating the libhttp-date-perl package to 6.08,
> which includes a fix to CVE-2026-14741. In the package's changelog,
> I've mentioned the CVE the update fixed. Is there anything else I
> should do about the CVE? As of right now, there doesn't seem to be a
> bug report or security issue filed for the CVE.

DevRef documents the security uploads workflow:

  https://www.debian.org/doc/manuals/developers-reference/pkgs.en.html#bug-security

Kind Regards,

Bas