Re: Open security issues affecting trixie which are not RC (2025-04-29)
Jeffrey Walton <[email protected]> Tue, 29 Apr 2025 16:12:59 -0400
| Newsgroups | gmane.linux.debian.devel.security,gmane.linux.debian.devel.release |
|---|---|
| Message-ID | <CAH8yC8mrWaxtA0kYhc+_cd4C7fdAB4DAJ0F+pS7hTEF8Wd-FGg@mail.gmail.com> |
On Tue, Apr 29, 2025 at 2:21 PM Moritz Mühlenhoff <[email protected]> wrote: > > Hi, > giving this a try for the trixie release: > > If anyone wants to help getting trixie in good shape: Here's > a list of open security issues below the RC threshold which > would still be useful to fix before the release. Many of > these haven't seen recent updates, so if anyone has time, check > their status and apply/backport patches as needed and submit > them in the BTS or as MRs or NMU if appropriate: > > If anyone of these are bogus, don't apply to how we ship > them in Debian or cannot be addressed in some manner, > you can also leave a note in the bug or bounce a note to > [email protected] so that we update the Security > Tracker data accordingly. > [...] > > libcrypto++: > https://security-tracker.debian.org/tracker/CVE-2023-50980 For Crpyto++, Debian should grab <https://github.com/weidai11/cryptopp/commit/641ae35258de3977>. > [...] Jeff