On Sun, Sep 27, 2026 at 10:12:21PM +0200, Emmanuel Bourg wrote:
> Hi Moritz,
>
> Le 25/10/2025 à 20:17, Moritz Mühlenhoff a écrit :
> >
> > CVE-2025-12194[0]:
>
> >
> > https://github.com/bcgit/bc-lts-java/commit/f2776feac0c30230f7a5ac34eb24f5019caf0324
> > https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%9012194
>
>
> BC FIPS and BC LTS are not packaged in Debian, our package tracks the main
> variant of Bouncy Castle (https://github.com/bcgit/bc-java). So this CVE
> doesn't affect the package.
Ack, I have updated the Security Tracker.
Cheers,
Moritz