Hi Abhijith, On Sat, Jul 25, 2026 at 10:13:36AM +0530, Abhijith PA wrote: > Hi, > > On 06/05/26 10:10 AM, Salvatore Bonaccorso wrote: > > Hi Abhijith, > > > > On Wed, May 06, 2026 at 12:11:59PM +0530, Abhijith PA wrote: > > > Hello security-team, > > > > > > I am currently preparing an upload for ruby-rack in bullseye LTS. I've > > > also prepared an update for trixie for ruby-rack[1] except > > > CVE-2026-26962[2]. I will do the same for bookworm too. ruby-rack is > > > listed in data/dsa-needed.txt, but the planned point releases are on > > > 16th May. > > > > To me it is not clar at all why this should be only 3.2 onwards. > > Looking at the code in trixie, the same is there. What I have not > > tried explicitly is to run the test code. Can you please loop in the > > question to upstream and keep us on the loop for that? > > So after some attempt, I was able to contact the committer. According > to them, > > CVE-2026-26962 was introduced due to applying fix for > CVE-2025-49007[1] (Fix ReDoS and consistency in multipart > regexes). They mentioned that since it released for 3.2.x , fix was > required in that series only. > > But when I looked, fix was also backported to 3.1.x series as well. I > have asked again for clarity. > > So at least bookworm and below versions are not affected.
Thanks for this update. Then given CVE-2025-49007 was addressed in 3.1.16-0.1 and trixie has 3.1.20-0+deb13u1, the status should be correct and trixie will need a fix as well. Keep us posted please with any update. Regards, Salvatore
