On Sat, Sep 12, 2026 at 05:07:07PM +0200, Salvatore Bonaccorso wrote: > Source: golang-github-google-cel-go > Version: 0.27.0+ds-6 > Severity: grave > Tags: security upstream > Justification: user security hole > X-Debbugs-Cc: [email protected], Debian Security Team > <[email protected]> > > Hi, > > The following vulnerability was published for golang-github-google-cel-go. > > AFAIU, is this source package replaced by golang-cel-cel-go which > already contains the fix and should golang-github-google-cel-go be > removed? This is as well the reason to make a RC level issue here.
Yes, golang-github-google-cel-go will be removed in forky/sid, superseded by golang-cel-cel-go but I'm not sure what needs to happen for that (it's tracked in #1146564). I'm also unsure about what to do in trixie. Incidentally, I've just uploaded 0.18.2+ds-5+deb13u1 for trixie-p-u without realizing about this CVE, sorry. If the patch applied cleanly to the trixie version (which I have not checked yet), we could either ask the SRM to cancel 0.18.2+ds-5+deb13u1, or maybe just make another release on top of that versioned +deb13u2. Cc: Simon for advice. Thanks.

