On 8/20/26 3:36 AM, Carlos Henrique Lima Melara wrote:
Hi zigo,
On Wed, Aug 19, 2026 at 09:31:03AM +0200, Thomas Goirand wrote:
I have just uploaded Swift. It was fixed in Trixie with this announce:
https://lists.debian.org/debian-security-announce/2026/msg00360.html
but please note that Swift in Bookworm is not affected by CVE-2026-71191,
CVE-2026-71192.
Is this a Debian specific thing? Because I looked at the upstream
advisory [1] and bug [2] before marking not-affected in the
security-tracker and they say only versions older than 2.18.0 are not
affected by these two CVEs. Should we warn them it is a different
version?
I've just asked on IRC to the author of the patches what is his thoughts
about it. I'll let you know if we need another follow-up patched version.
Can someone issue the DLA for me please ?
Thanks for the upload fixing the vulnerabilities! DLA-4746-1 was
reserved and the advisory sent to the mailing list.
Cheers,
Charles
Thank you Charles !
Cheers,
Thomas Goirand (zigo)