Re: On bumping/fixing biber 2.22 in debian
Hilmar Preuße <[email protected]>
| Newsgroups | gmane.linux.debian.devel.tetex |
|---|---|
| Message-ID | <[email protected]> |
Hello, as pointed out, there should be no strict version dependency between this biber release and biblatex. I just typed "dput", I assume, that the source package will be accepted. Hilmar 18.08.2026 10:30:40 Pavel Sanda <[email protected]>: > Hi Hilmar, > > do you think it would be possible to bump biber to 2.22 before > ubuntu imports freezes for the next release (2026-08-20)? > > I would like to get the injection fix in before the window closes. > The vulnerability is briefly documented at > https://www.openwall.com/lists/oss-security/2026/08/17/1 > > I checked that bcf/bbl version remained same since 2.20 > so no problem should appear for the bump. > > Apart from that I had lower priority question whether you think > backporting fixes back to trixie or offering backport is viable > option for trixie. > > Even lower-prio issue is that from LyX POV current debian ships > vulnerable xindy. It's caused by debian's own patchset and this won't > be fixed by later TL updates. I can write details later in case > you have time to deal with it. I think current security team > is totally overwhelm by large scale issues, so it is leftover > for normal maintainers... > > Thanks, > Pavel