On Sat, Sep 12, 2026 at 05:07:07PM +0200, Salvatore Bonaccorso wrote:
> Source: golang-github-google-cel-go
> Version: 0.27.0+ds-6
> Severity: grave
> Tags: security upstream
> Justification: user security hole
> X-Debbugs-Cc: [email protected], Debian Security Team 
> <[email protected]>
> 
> Hi,
> 
> The following vulnerability was published for golang-github-google-cel-go.
> 
> AFAIU, is this source package replaced by golang-cel-cel-go which
> already contains the fix and should golang-github-google-cel-go be
> removed? This is as well the reason to make a RC level issue here.

Yes, golang-github-google-cel-go will be removed in forky/sid,
superseded by golang-cel-cel-go but I'm not sure what needs to happen
for that (it's tracked in #1146564).

I'm also unsure about what to do in trixie. Incidentally, I've just
uploaded 0.18.2+ds-5+deb13u1 for trixie-p-u without realizing about
this CVE, sorry.

If the patch applied cleanly to the trixie version (which I have not checked 
yet),
we could either ask the SRM to cancel 0.18.2+ds-5+deb13u1, or maybe
just make another release on top of that versioned +deb13u2.

Cc: Simon for advice.

Thanks.

Reply via email to