Re: Procedure for dealing with package updates that fix CVEs?

gregor herrmann <[email protected]> Sat, 11 Jul 2026 00:31:31 +0200
Newsgroups gmane.linux.debian.devel.perl
Message-ID <[email protected]>
------------=_1783722699-5622-373
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Disposition: inline

On Thu, 09 Jul 2026 18:12:49 +0200, Sebastiaan Couwenberg wrote:

>On 7/9/26 5:51 PM, Samuel Young wrote:
>>I've been working on updating the libhttp-date-perl package to 6.08,
>>which includes a fix to CVE-2026-14741. In the package's changelog,
>>I've mentioned the CVE the update fixed. Is there anything else I
>>should do about the CVE? As of right now, there doesn't seem to be a
>>bug report or security issue filed for the CVE.
>DevRef documents the security uploads workflow:
> https://www.debian.org/doc/manuals/developers-reference/pkgs.en.html#bug-security

I think this doesn't answer Samuel's question in this case, which is
- There's a published CVE (public)
- There's a new upstream release which fixes and mentions this CVE 
   (also public)
- It's one of those many-reports-per-day "security issues" which are 
   in practice cases of "well, not best practice, might cause problems 
   in corner cases, no big deal but let's fix them".

The Debian Security Team is IMO currently overwhelmed with (more or 
less useful) CVEs but when they get to it, they will record them in 
the security tracker and will be happy about accurate annotations in 
debian/changelog, as Samuel did in this case. (Disclaimer: It was me 
who uploaded the package without any changes).
They do file bug reports if the new upstream release is not yet 
uploaded but (in my experience) not afterwards.

Typically, the Security Team doesn't pursue uploads to 
debian-security for all these minor issues. If they recommend an 
upload to stable-updates, they will say so, and there's a procedure 
for it.

Concluding: Samuel, I think you did what's appropriate in this 
situation.


Cheers,
gregor

-- 
  .''`.  https://info.comodo.priv.at -- Debian Developer https://www.debian.org
  : :' : OpenPGP fingerprint D1E1 316E 93A7 60A8 104D  85FA BB3A 6801 8649 AA06
  `. `'  Member VIBE!AT & SPI Inc. -- Supporter Free Software Foundation Europe

------------=_1783722699-5622-373
Content-Type: application/pgp-signature; name="signature.asc"
Content-Disposition: inline; filename="signature.asc"
Content-Transfer-Encoding: 7bit
Content-Description: Digital Signature

-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEE0eExbpOnYKgQTYX6uzpoAYZJqgYFAmpRcstfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEQx
RTEzMTZFOTNBNzYwQTgxMDREODVGQUJCM0E2ODAxODY0OUFBMDYACgkQuzpoAYZJ
qgYavQ/+PwrktPE5TT+nDgbv/94qDWhX9bZIY+eFvm5WANQedutYzaJWuikin8+v
Iph+qFxZ1j5NWF8xJ9xZEdoImJR33hMuq2ryWamRamqwIdmpPN7eyDQEY110RTpL
yLSolybV57v6EEfEqiA4mdNc5PJejhBpTnpT+oj+3mrMHPPOKQFLiKjnTgv2ftF0
LSd74PufJaFQGdRlqZ1ROWS0R87W6juJb7mcBANUGAb6t8w+75Rew3U4G5kd+RXW
Yb4HVGYYp7LiQ4KW60l6xkJT+KliC8Ao+Po8JWgHKnuWn0obo+L5jK2CaqVnZWmk
1wnNaUv4xPdAgANizPqT6WiIiZRJ+AgngpkN7dr+uf+pnMbjNBEWKv5wcDULiw4L
NUC9rPsAUvwNuq+ZtDqqQ+cyLmjgdKaqO/qSNxSSrE2MEww+jXT8x4mJV4cDmrYy
RMGq0BKBTbF8LIeehHmCZyWTYzjDC1QXuluIKxTQWg25LYdNwo4uA0CzxkGrcQbt
QdBAB5xZkzrVBXb38U6Hdh2oVV89Jwebmyj+Nrerke1ZbtJeZiNWTGoZMOYFZYS1
KjDMpNj8ot/+0PStjK21uSj/82V37GJrIfryBL1RUNf9neLRK54NNF6qQVCpyhLw
VLTRwGUb2Jng6eSyvlVZMpvvXSS+q3Hcglm4Gi3pyzEY8+AmREg=
=sFs5
-----END PGP SIGNATURE-----

------------=_1783722699-5622-373--