I've worked during january on the below listed packages, for Freexian
LTS/ELTS [1]

Many thanks to Freexian and our sponsors [2] for providing this opportunity!

LTS
===

zabbix
----------
* recommend triage of remaining CVE to no-dsa or postponed (need zabbix 
superuser)

netty
--------
* fix remaining CVE
* split package for packaging lastest version for sid, avoiding hard to 
backport.

gpsd
-------

* fix sid (new upstream version)
* was hit by #1125944, determine it was not a debusine bug but a binutils/glibc 
bug.
* Propose PU for trixie #1126121 and #1126168 for bookworm
* Release DLA-4441-1

imagemagick
--------------------

* Fix CVE-2026-22770/CVE-2026-23874/CVE-2026-23876/CVE-2026-23952
* Release DLA-4448-1 and prepare DSA 6111-1

apache2
------------

Release DLA 4452-1 fixing CVE-2025-55753 CVE-2025-58098 CVE-2025-59775 
CVE-2025-65082 CVE-2025-66200
Fix also a regression propose PU for trixie and bookworm
Investigate another regression due to incomplete regression fix

ELTS
====

imagemagick
-------------------

* Release ELA-1606-1 fixing CVE-2025-65955 CVE-2025-66628 CVE-2025-68618 
CVE-2025-68950 CVE-2025-69204
* Fix CVE-2026-22770/CVE-2026-23874/CVE-2026-23876/CVE-2026-23952
* This backport was difficult due to missing function and code reorganisation 
that create subtle build on C++ module and autopkgtest failure
*  Release ELA-1624-1

tomcat9
-------------

Release ELA-1615-1 fixing CVE-2024-34750 CVE-2024-54677 CVE-2025-31650 
CVE-2025-31651 CVE-2025-46701 CVE-2025-48976 CVE-2025-48988 CVE-2025-49125 
CVE-2025-52434 CVE-2025-52520 CVE-2025-53506 CVE-2025-55668
Investigate a major regression not detected by autopkgtest due to build chain 
subtle problem. Help to found a path to solve this regression.

gpsd
-------

Release ELA-1617-1  fixing CVE-2025-67268 CVE-2025-67269

bind9
---------
* debug test following santiago remark

apache2
-------------

Fix CVE-2025-55753 CVE-2025-58098 CVE-2025-59775 CVE-2025-65082 CVE-2025-66200
Release ELA-1625-1 for buster
Release ELA-1626-1 for stretch

other
====

debusine
--------------

Try to debug debusing upload problem related to imagemagick PU
Open bug report https://salsa.debian.org/freexian-team/debusine/-/issues/124

Cheers

rouca

[1]  https://www.freexian.com/lts/
[2]  https://www.freexian.com/lts/debian/#sponsors

Attachment: signature.asc
Description: This is a digitally signed message part.

Reply via email to