• Bug#1105009: Info received (Bug#1105009: Acknowledgement (bookworm-pu:

    From Sergei Golovan@21:1/5 to [email protected] on Sun Jul 20 15:00:01 2025
    XPost: linux.debian.devel.release

    Hi Salvatore,

    On Fri, Jun 27, 2025 at 12:28 AM Salvatore Bonaccorso <[email protected]> wrote:

    Hi Sergei,

    On Thu, Jun 26, 2025 at 01:38:27PM +0300, Sergei Golovan wrote:
    Hi!

    Sorry, I forgot to include links to the relevant bugreports:

    [1] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1107939
    [2] https://security-tracker.debian.org/tracker/CVE-2025-4748

    Just as FYI, to get the fixes accepted for the bookworm-pu it is
    needed that they are as well fixed in unstable (and so now as well
    trixie).

    But I see you have already #1108338, and there is though a question
    with moreinfo tag from Paul Gevers.

    Now, as #1108338 is done, and Erlang 27.3.4.1+dfsg-1 is already in testing,
    I'd like to proceed with fixing CVE-2025-4748 and CVE-2025-46712 in bookworm
    as well.

    Cheers!
    --
    Sergei Golovan

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Salvatore Bonaccorso@21:1/5 to Sergei Golovan on Sun Jul 20 21:50:01 2025
    XPost: linux.debian.devel.release

    Hi Sergei,

    On Sun, Jul 20, 2025 at 03:49:45PM +0300, Sergei Golovan wrote:
    Hi Salvatore,

    On Fri, Jun 27, 2025 at 12:28 AM Salvatore Bonaccorso <[email protected]> wrote:

    Hi Sergei,

    On Thu, Jun 26, 2025 at 01:38:27PM +0300, Sergei Golovan wrote:
    Hi!

    Sorry, I forgot to include links to the relevant bugreports:

    [1] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1107939
    [2] https://security-tracker.debian.org/tracker/CVE-2025-4748

    Just as FYI, to get the fixes accepted for the bookworm-pu it is
    needed that they are as well fixed in unstable (and so now as well
    trixie).

    But I see you have already #1108338, and there is though a question
    with moreinfo tag from Paul Gevers.

    Now, as #1108338 is done, and Erlang 27.3.4.1+dfsg-1 is already in testing, I'd like to proceed with fixing CVE-2025-4748 and CVE-2025-46712 in bookworm as well.

    Thanks!

    For bookworm, as they are considered no-dsa already, can you queue the
    update for the next bookworm point release?

    Regards,
    Salvatore

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)