Bug#1142123: bookworm-pu: package modsecurity/3.0.9-1+deb12u3

Sylvain Beucler <[email protected]> Fri, 17 Jul 2026 08:40:16 +0200
Newsgroups gmane.linux.debian.devel.release
Message-ID <310c6160-21e4-4399-b398-fe97323e667c__31751.5182936162$1784270852$gmane$org@beuc.net>
Hello Alberto,

On 16/07/2026 21:26, Salvatore Bonaccorso wrote:
> On Wed, Jul 15, 2026 at 05:25:55PM +0200, Alberto Gonzalez Iniesta wrote:
>> Package: release.debian.org
>> Severity: normal
>> Tags: security
>> X-Debbugs-Cc: [email protected], [email protected], Debian Security Team <[email protected]>
>> Control: affects -1 + src:modsecurity
>> User: [email protected]
>> Usertags: pu
>>
>> [ Reason ]
>> Fixes for CVE-2026-52747 and CVE-2026-52761
>>
>> [ Impact ]
>> Security rules bypass.
>>
>> [ Tests ]
>> Fixed and tested by upstream.
>>
>> [ Risks ]
>> Low risk, simple patch.
>>
>> [ Checklist ]
>>    [x] *all* changes are documented in the d/changelog
>>    [x] I reviewed all changes and I approve them
>>    [x] attach debdiff against the package in (old)stable
>>    [x] the issue is verified as fixed in unstable
>>
>> [ Changes ]
>> Preserve line breaks from non-file form-field values.
>> Fix returned length of "unicode" variable.
> 
> As this proposed update targets 'bookworm'. Debian bookworm is now
> handed over to the LTS team, so no point releases are happening
> anymore, but updates are released via DLA's. I'm cc'ing the LTS list.

You can push an update to bookworm-lts following:
https://lts-team.pages.debian.net/wiki/Development.html

We can help with the administrative tasks.

According to:
https://security-tracker.debian.org/tracker/source-package/modsecurity
this is also an opportunity to fix CVE-2024-1019.

Cheers!
Sylvain Beucler
Debian LTS Team