I've worked during march on the below listed packages, for Freexian
LTS/ELTS [1]

Many thanks to Freexian and our sponsors [2] for providing this opportunity!

LTS
===

imagemagick
--------------------

I uploaded a new upstream version fixing 34 CVEs
I backported to trixie and security team released DSA-6158-1
I backported to bookworm and bullseye releasing DSA-6159-1 and DLA-4497-1
I backported to buster releasing ELA-1657-1 and stretch releasing ELA-1659-1
I uploade a new upstream version to sid fixing 17 CVEs including RCE
I backport to trixie. Security team released DSA-6169-1

I am chasing a regression under bookworm backport on i386 likely due to FPU 80 
bits long double versus 128 bits IEEE long double. 

netty
-------

DSA 6160-1 was released based on my work
I released DLA-4519-1 fixing CVE-2024-29025, CVE-2025-55163, CVE-2025-58056, 
CVE-2025-58057, CVE-2025-59419, CVE-2025-67735

gpsd
-------

upload a trixie version PU fixing CVE fixed in LTS

apache2
-------------

PU fixing a regression in httpd for trixie

bind9
-------

I am continuing to backport to buster

zabbix
----------

PU for 7.0.22+dfsg-1~deb13u1

ca-certificates-(?:java)?
--------------------------------

With arnaudr we are fising regression in ca-certificates-(?:java)?.

We fixed sid and released a new release due to bashism preventing upgrade of 
certificates in some cases.

Other
=====

I attend monthly meeting


Cheers

rouca

[1]  https://www.freexian.com/lts/
[2]  https://www.freexian.com/lts/debian/#sponsors

Attachment: signature.asc
Description: This is a digitally signed message part.

Reply via email to