Bug#1143148: trixie-pu: package python-aiohttp/3.11.16-1+deb13u2
Salvatore Bonaccorso <[email protected]> Sun, 2 Aug 2026 19:06:31 +0200
| Newsgroups | gmane.linux.debian.devel.release |
|---|---|
| Message-ID | <am95F0GetMOQ5X7H__18813.8573475712$1785690566$gmane$org@eldamar.lan> |
On Fri, Jul 31, 2026 at 04:16:48AM +0200, Daniel Leidert wrote: > Package: release.debian.org > Severity: normal > Tags: trixie > X-Debbugs-Cc: [email protected] > Control: affects -1 + src:python-aiohttp > User: [email protected] > Usertags: pu > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA512 > > [ Reason ] > > This update adresses a list of CVEs which should either be fixed via DSA or via > SPU. These are the CVEs fixed: > > * CVE-2025-53643 > * CVE-2026-22815 > * CVE-2026-34513 > * CVE-2026-34514 > * CVE-2026-34516 > * CVE-2026-34517 > * CVE-2026-34518 > * CVE-2026-34519 > * CVE-2026-34520 > * CVE-2026-34525 > * CVE-2026-34993 > * CVE-2026-47265 > * CVE-2026-50269 > * CVE-2026-54274 > * CVE-2026-54275 > * CVE-2026-54277 > * CVE-2026-54279 > * CVE-2026-54280 They are marked already no-dsa, thus the trixie-pu route is good. Can you please add as well the fix for CVE-2026-59881 in the same batch, this is as well no-dsa (should first be fixed as well in unstable). Regards, Salvatore