[nghttp2] request for review of Debian CVE-2023-44487 backports
Lukas Märdian <[email protected]> Wed, 29 Apr 2026 16:12:50 +0200
| Newsgroups | gmane.linux.debian.devel.security |
|---|---|
| Message-ID | <CAA7PNc3QJ4wKt_TD6r-umSPgvunnoGuscHas=n_b0F1b=8qhrg@mail.gmail.com> |
--0000000000001012fd065099f2a5 Content-Type: text/plain; charset="UTF-8" Dear Security team, I've tried reaching out to the nghttp2 upstream maintainer, but have not received any feedback so far. Would you be willing to help with getting those changes reviewed? Trixie: https://salsa.debian.org/debian/nghttp2/-/merge_requests/12 Bookworm: https://salsa.debian.org/debian/nghttp2/-/merge_requests/11 The lack of review in trixie/bookworm is currently blocking the release of those fixes for Debian (E)LTS series (stretch/buster/bullseye). Cheers, Lukas ---------- Forwarded message --------- Von: Lukas Date: Fr., 17. Apr. 2026 um 08:54 Uhr Subject: [nghttp2] Debian CVE-2023-44487 backports To: Tatsuhiro Dear Tatsuhiro, This is Lukas from the Debian LTS team. I've been working on LTS backports for CVE-2023-44487. And while on it, I also backported your patches to Debian Stable (trixie) and Oldstable (bookworm). After coordinating with the Debian Security Team (jmm specifically), they mentioned that you'd already been involved with preparing such backports for Debian (old-)stable. Maybe you'd be interested in reviewing my work, so we can avoid duplication? Trixie: https://salsa.debian.org/debian/nghttp2/-/merge_requests/12 Bookworm: https://salsa.debian.org/debian/nghttp2/-/merge_requests/11 Please let me know what you think. Best regards, Lukas --0000000000001012fd065099f2a5 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>Dear Security team,</div><div><br></div><div>I've= tried reaching=C2=A0out to the nghttp2 upstream maintainer, but have not r= eceived any feedback so far.</div><div>Would you be willing to help with ge= tting those changes reviewed?</div><div><div><br></div>Trixie: <a href=3D"h= ttps://salsa.debian.org/debian/nghttp2/-/merge_requests/12" target=3D"_blan= k">https://salsa.debian.org/debian/nghttp2/-/merge_requests/12</a><div>Book= worm:=C2=A0<span><a href=3D"https://salsa.debian.org/debian/nghttp2/-/merge= _requests/11" target=3D"_blank">https://salsa.debian.org/debian/nghttp2/-/m= erge_requests/11</a></span></div></div><div><br></div><div>The lack of revi= ew in trixie/bookworm is currently blocking the release of those fixes</div= ><div>for Debian (E)LTS series (stretch/buster/bullseye).</div><div><br></d= iv><div>Cheers,</div><div>=C2=A0 Lukas</div><div><br><div class=3D"gmail_qu= ote gmail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">----------= Forwarded message ---------<br>Von: <b class=3D"gmail_sendername" dir=3D"a= uto">Lukas</b><br>Date: Fr., 17. Apr. 2026 um 08:54=C2=A0Uhr<br>Subject: [n= ghttp2] Debian CVE-2023-44487 backports<br>To: Tatsuhiro</div><br><br><div = dir=3D"ltr"><div>Dear Tatsuhiro,</div><div><br></div><div>This is Lukas fro= m the Debian LTS team. I've been working on LTS backports for=C2=A0CVE-= 2023-44487.</div><div>And while on it, I also backported your patches to De= bian Stable (trixie) and Oldstable (bookworm).</div><div><br></div><div>Aft= er coordinating with the Debian Security=C2=A0Team (jmm specifically), they= mentioned=C2=A0that you'd already been involved with preparing such ba= ckports for Debian (old-)stable.</div><div>Maybe you'd be interested in= reviewing my work, so we can avoid duplication?</div><div><br></div>Trixie= : <a href=3D"https://salsa.debian.org/debian/nghttp2/-/merge_requests/12" t= arget=3D"_blank">https://salsa.debian.org/debian/nghttp2/-/merge_requests/1= 2</a><div>Bookworm:=C2=A0<span><a href=3D"https://salsa.debian.org/debian/n= ghttp2/-/merge_requests/11" target=3D"_blank">https://salsa.debian.org/debi= an/nghttp2/-/merge_requests/11</a></span></div><div><span><br></span></div>= <div><span>Please let me know what you think.</span></div><div><span><br></= span></div><div><span>Best regards,</span></div><div><span>=C2=A0 Lukas</sp= an></div></div> </div></div></div> --0000000000001012fd065099f2a5--