• Bug#1110095: unblock: cross-toolchain-base-ports/74

    From Jochen Sprickerhof@21:1/5 to All on Wed Jul 30 13:10:01 2025
    XPost: linux.debian.bugs.dist

    --NllAajm8opr1rDt0
    Content-Type: text/plain; charset=us-ascii; format=flowed
    Content-Disposition: inline

    Hi Aurelien,

    seems like you forgot the debdiff. I have attached it.

    Cheers Jochen

    * Aurelien Jarno <[email protected]> [2025-07-29 19:58]:
    Package: release.debian.org
    Severity: normal
    X-Debbugs-Cc: [email protected]
    Control: affects -1 + src:cross-toolchain-base-ports
    User: [email protected]
    Usertags: unblock

    Please unblock package cross-toolchain-base-ports

    [ Reason ]
    This is just a rebuild of cross-toolchain-base-ports against the latest
    linux and glibc version. This is needed because
    cross-toolchain-base-ports only builds arch:all packages and thus can't
    be binNMUed. This should reduce the number of Extra-Source-Only packages
    in Trixie.

    In addition, this fixes three security issues on the libc versions
    shipped by this package: CVE-2025-5702, CVE-2025-5745 and CVE-2025-8058.

    [ Impact ]
    Users using cross-toolchain-base-ports to build foreign static binaries
    will get binaries with security issue if this unblock is not granted.

    [ Tests ]
    None besides the autopkgtest one.

    [ Risks ]
    The risk is quite low, it's just a rebuild of source packages already in >Trixie, but for foreign architectures.

    [ Checklist ]
    [x] all changes are documented in the d/changelog
    [x] I reviewed all changes and I approve them
    [x] attach debdiff against the package in testing

    [ Other info ]
    I am not sure why the debian/no-packages file got added (it's not in the >git), but anyway it has no impact on the resulting packages.

    unblock cross-toolchain-base-ports/74

    --NllAajm8opr1rDt0
    Content-Type: text/x-diff; charset=us-ascii
    Content-Disposition: attachment; filename="cross-toolchain-base-ports.patch" Content-Transfer-Encoding: quoted-printable

    diff -Nru cross-toolchain-base-ports-73/debian/changelog cross-toolchain-base-ports-74/debian/changelog
    --- cross-toolchain-base-ports-73/debian/changelog 2025-05-19 20:02:18.000000000 +0200
    +++ cross-toolchain-base-ports-74/debian/changelog 2025-07-29 10:53:48.000000000 +0200
    @@ -1,3 +1,10 @@
    +cross-toolchain-base-ports (74) unstable; urgency=medium
    +
    + * Build using glibc 2.41-11.
    + * Build using linux 6.12.38.
    +
    + -- Matthias Klose <[email protected]> Tue, 29 Jul 2025 10:53:48 +0200
    +
    cross-toolchain-base-ports (73) unstable; urgency=medium

    * Fix typo for the dpkg-query fix in last upload.
    diff -Nru cross-toolchain-base-ports-73/debian/control cross-toolchain-base-ports-74/debian/control
    --- cross-toolchain-base-ports-73/debian/control 2025-05-18 12:48:58.000000000 +0200
    +++ cross-toolchain-base-ports-74/debian/control 2025-07-29 10:53:48.000000000 +0200
    @@ -9,9 +9,9 @@
    Build-Depends: binutils-multiarch,
    dpkg (>= 1.21.17), rdfind, symlinks, lsb-release,
    binutils-source (>= 2.44-3~),
    - glibc-source (>= 2.41-8~),
    + glibc-source (>= 2.41-11~),
    gcc-14-source (>= 14.2.0-19