On 8/20/26 3:36 AM, Carlos Henrique Lima Melara wrote:
Hi zigo,

On Wed, Aug 19, 2026 at 09:31:03AM +0200, Thomas Goirand wrote:

I have just uploaded Swift. It was fixed in Trixie with this announce:

https://lists.debian.org/debian-security-announce/2026/msg00360.html

but please note that Swift in Bookworm is not affected by CVE-2026-71191,
CVE-2026-71192.

Is this a Debian specific thing? Because I looked at the upstream
advisory [1] and bug [2] before marking not-affected in the
security-tracker and they say only versions older than 2.18.0 are not
affected by these two CVEs. Should we warn them it is a different
version?

I've just asked on IRC to the author of the patches what is his thoughts about it. I'll let you know if we need another follow-up patched version.

Can someone issue the DLA for me please ?

Thanks for the upload fixing the vulnerabilities! DLA-4746-1 was
reserved and the advisory sent to the mailing list.

Cheers,
Charles

Thank you Charles !

Cheers,

Thomas Goirand (zigo)

Reply via email to