On Fri, Jul 31, 2026 at 10:35:00PM +0200, Salvatore Bonaccorso wrote: > On Fri, Jul 31, 2026 at 05:37:03PM +0000, Debian Bug Tracking System wrote: > > open-isns (0.103-1) unstable; urgency=medium > > . > > * Team upload. > > * New upstream version 0.103, fixes CVE-2026-55995 (Closes: #1143053) > > I think that is not correct? > https://github.com/open-iscsi/open-isns/commit/56718d4e9d1a4f51c30697b5c0534144bb41c9bb > is not included in v0.103 or do I miss something?
You are, of course, correct. Sorry. I'm uploading -2 with the fix cherry-picked. > p.s.: I tend to mark this no-dsa, do you agree? I think so - however it's a bit unclear to me how to reach the affected code. Best, Chris

