Hi Colin, hi Moritz, On Thu, Aug 27, 2026 at 03:32:17PM +0000, Moritz Mühlenhoff wrote: > On Thu, Aug 27, 2026 at 04:17:35PM +0100, Colin Watson wrote: > > On Thu, Aug 27, 2026 at 04:18:26PM +0200, Salvatore Bonaccorso wrote: > > > Now that there is openssh-gssapi, should we reassign this bug to > > > src:openssh-gssapi as the GSS_API authentication and key exchange > > > support was droppend in src:openssh/1:10.4p1-5 ? > > > > I was holding off on doing so since I assume that what the security team > > mainly needs to track is stable releases, and those are all still openssh. > > What do you think? > > Thanks for considering that! But we predominantly operate on the data stored > in the Securiy Tracker, which tracks this across the rename correctly, so > for the BTS you can safely reassign.
Thank you both. So I have reassigned the bug and moved the number in the security-tracker associating it with src:openssh-gssapi. https://security-tracker.debian.org/tracker/CVE-2026-55654 schould soon reflect the appropriate tracking. Regards, Salvatore

