On Thu, May 28, 2026 at 01:19:11PM +0200, Guilhem Moulin wrote:
> Control: retitle -1 DSA 6301-1 breaks roundcube on PHP <8
> Control: severity -1 normal
> Control: tag -1 pending
>
> Hi,
>
> On Thu, 28 May 2026 at 11:32:06 +0200, Vladislav Kurz wrote:
> >> Hello, I noticed that the problem is in the PHP version.
> >> We were running PHP 7.4. Problem was gone after switching to PHP 8.2.
> >
> > According to
> > https://github.com/roundcube/roundcubemail/wiki/Version-History
> >
> > Version 1.6 has PHP support: >=7.3 <=8.3
>
> The upstream PHP compatibility is mostly irrelevant for Debian. Trixie
> has PHP 8.4 and Bookworm 8.2, so that's the PHP versions against which
> the packages are tested and AFAIK everything else is unsupported.
Indeed, running the Debian packaged versions with external PHP versions
is unsupported.
> I don't think it warrants a regression update given supported systems
> are not affected, but I'm CC'ing the Security Team in case they have a
> different assessment (I can prepare the debdiffs in that case).
We can include the patch in a future Roundcube security update.
Cheers,
Moritz