Re: Security update for Neutron (CVE-2026-55707 aka #1143170, OSSN-0102 aka #1142937)

Philipp Kern <[email protected]>
Newsgroups gmane.linux.debian.devel.wb-team,gmane.linux.debian.devel.release
Message-ID <[email protected]>
On 8/16/26 8:16 PM, Moritz Mühlenhoff wrote:
> On Sun, Aug 16, 2026 at 03:05:02PM +0300, Adrian Bunk wrote:
>>> thank you! One option would be to maybe disable it again after the
>>> round of neutron rebuilds. But I can understand we do not want to have
>>> a back and forth here. I remember we enabled temporarily as well the
>>> proposed-updates suites at least once (for firefox DSAs?) and the
>>> rolled back.
>>> ...
>>
>> What about declaring -security without -updates as unsupported in the
>> documentation?
> 
> That makes sense to me.
> 
>> It is not obvious to me why this should be a supported configuration,
>> and the only question would IMHO be whether to already consider that
>> unsupported for trixie or only starting from forky.
> 
> Let's do it for forky, then we can directly mentioned it in the release
> notes under the section of things to modify when migratin from an older
> released

I'll note that as part of the systemd kerfuffle many, many people did 
not know about -updates at all. Would be cool to have some way to flag 
to users that their configuration is weird. We chose to organize our 
repositories in this way and yet many DDs are not even after that this 
is how it works, after like what, over 10 years? ;-)

AIUI here it's only needed as a build dependency and not as an actual 
runtime dependency, right? So the workaround is fair and there are only 
very few things in -updates that all get looked at by SRM. For runtime 
dependencies I'd feel stronger about a judgement call of importing the 
package into -security instead.

Kind regards
Philipp Kern
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.