Re: Procedure for dealing with package updates that fix CVEs?
gregor herrmann <[email protected]> Sat, 11 Jul 2026 00:31:31 +0200
| Newsgroups | gmane.linux.debian.devel.perl |
|---|---|
| Message-ID | <[email protected]> |
------------=_1783722699-5622-373 Content-Type: text/plain; charset=us-ascii; format=flowed Content-Disposition: inline On Thu, 09 Jul 2026 18:12:49 +0200, Sebastiaan Couwenberg wrote: >On 7/9/26 5:51 PM, Samuel Young wrote: >>I've been working on updating the libhttp-date-perl package to 6.08, >>which includes a fix to CVE-2026-14741. In the package's changelog, >>I've mentioned the CVE the update fixed. Is there anything else I >>should do about the CVE? As of right now, there doesn't seem to be a >>bug report or security issue filed for the CVE. >DevRef documents the security uploads workflow: > https://www.debian.org/doc/manuals/developers-reference/pkgs.en.html#bug-security I think this doesn't answer Samuel's question in this case, which is - There's a published CVE (public) - There's a new upstream release which fixes and mentions this CVE (also public) - It's one of those many-reports-per-day "security issues" which are in practice cases of "well, not best practice, might cause problems in corner cases, no big deal but let's fix them". The Debian Security Team is IMO currently overwhelmed with (more or less useful) CVEs but when they get to it, they will record them in the security tracker and will be happy about accurate annotations in debian/changelog, as Samuel did in this case. (Disclaimer: It was me who uploaded the package without any changes). They do file bug reports if the new upstream release is not yet uploaded but (in my experience) not afterwards. Typically, the Security Team doesn't pursue uploads to debian-security for all these minor issues. If they recommend an upload to stable-updates, they will say so, and there's a procedure for it. Concluding: Samuel, I think you did what's appropriate in this situation. Cheers, gregor -- .''`. https://info.comodo.priv.at -- Debian Developer https://www.debian.org : :' : OpenPGP fingerprint D1E1 316E 93A7 60A8 104D 85FA BB3A 6801 8649 AA06 `. `' Member VIBE!AT & SPI Inc. -- Supporter Free Software Foundation Europe ------------=_1783722699-5622-373 Content-Type: application/pgp-signature; name="signature.asc" Content-Disposition: inline; filename="signature.asc" Content-Transfer-Encoding: 7bit Content-Description: Digital Signature -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEE0eExbpOnYKgQTYX6uzpoAYZJqgYFAmpRcstfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEQx RTEzMTZFOTNBNzYwQTgxMDREODVGQUJCM0E2ODAxODY0OUFBMDYACgkQuzpoAYZJ qgYavQ/+PwrktPE5TT+nDgbv/94qDWhX9bZIY+eFvm5WANQedutYzaJWuikin8+v Iph+qFxZ1j5NWF8xJ9xZEdoImJR33hMuq2ryWamRamqwIdmpPN7eyDQEY110RTpL yLSolybV57v6EEfEqiA4mdNc5PJejhBpTnpT+oj+3mrMHPPOKQFLiKjnTgv2ftF0 LSd74PufJaFQGdRlqZ1ROWS0R87W6juJb7mcBANUGAb6t8w+75Rew3U4G5kd+RXW Yb4HVGYYp7LiQ4KW60l6xkJT+KliC8Ao+Po8JWgHKnuWn0obo+L5jK2CaqVnZWmk 1wnNaUv4xPdAgANizPqT6WiIiZRJ+AgngpkN7dr+uf+pnMbjNBEWKv5wcDULiw4L NUC9rPsAUvwNuq+ZtDqqQ+cyLmjgdKaqO/qSNxSSrE2MEww+jXT8x4mJV4cDmrYy RMGq0BKBTbF8LIeehHmCZyWTYzjDC1QXuluIKxTQWg25LYdNwo4uA0CzxkGrcQbt QdBAB5xZkzrVBXb38U6Hdh2oVV89Jwebmyj+Nrerke1ZbtJeZiNWTGoZMOYFZYS1 KjDMpNj8ot/+0PStjK21uSj/82V37GJrIfryBL1RUNf9neLRK54NNF6qQVCpyhLw VLTRwGUb2Jng6eSyvlVZMpvvXSS+q3Hcglm4Gi3pyzEY8+AmREg= =sFs5 -----END PGP SIGNATURE----- ------------=_1783722699-5622-373--