On 8/17/26 5:15 PM, Salvatore Bonaccorso wrote:
If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
It's already fixed in experimental. The issue doesn't seem severe enough that we need to cherry-pick the patch for 3.6 in unstable and can just wait for the final 3.7 release. I you do intend to issue a DSA, we'll need to prepare an update for 3.5 in trixie too. Kind Regards, Bas -- PGP Key ID: 4096R/6750F10AE88D4AF1 Fingerprint: 8182 DE41 7056 408D 6146 50D1 6750 F10A E88D 4AF1

