Hi, On Tue, Jul 14, 2026 at 08:41:51AM +0300, Martin-Éric Racine wrote: > Greetings, > > My dashboard shows CVE-2025-70102 as still being unfixed for > oldoldstable. Since Bullseye is LTS at this point, this goes via the > Security team. The enclosed patch includes the fix for the CVE and > some basic packaging touchups to silence Lintian and CI. You're > welcome to use it.
Thanks for preparing the update. As you say bullseye is a LTS maintained suite, so this actually has to go via the LTS team, not the security team. I'm CC'ing the correct list, but that said, I see it is marked postponed/no-dsa, so this can be usually included in a future update covering more CVEs or now, but please coordinate further with the LTS team. LTS team, how do you want Martin-Eric to proceed? Regards, Salvatore

