Re: On bumping/fixing biber 2.22 in debian

Hilmar Preuße <[email protected]>
Newsgroups gmane.linux.debian.devel.tetex
Message-ID <[email protected]>
Hello,

as pointed out, there should be no strict version dependency between this biber release and biblatex. I just typed "dput", I assume, that the source package will be accepted.

Hilmar

18.08.2026 10:30:40 Pavel Sanda <[email protected]>:

> Hi Hilmar,
> 
> do you think it would be possible to bump biber to 2.22 before
> ubuntu imports freezes for the next release (2026-08-20)?
> 
> I would like to get the injection fix in before the window closes.
> The vulnerability is briefly documented at
> https://www.openwall.com/lists/oss-security/2026/08/17/1
> 
> I checked that bcf/bbl version remained same since 2.20
> so no problem should appear for the bump.
> 
> Apart from that I had lower priority question whether you think
> backporting fixes back to trixie or offering backport is viable
> option for trixie.
> 
> Even lower-prio issue is that from LyX POV current debian ships
> vulnerable xindy. It's caused by debian's own patchset and this won't
> be fixed by later TL updates. I can write details later in case
> you have time to deal with it. I think current security team
> is totally overwhelm by large scale issues, so it is leftover
> for normal maintainers...
> 
> Thanks,
> Pavel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.