Am Mon, Jun 16, 2025 at 02:02:57AM +0300 schrieb Adrian Bunk:
> Package: release.debian.org
> Severity: normal
> Tags: bookworm moreinfo
> User: [email protected]
> Usertags: pu
> X-Debbugs-Cc: [email protected], [email protected]
> Control: affects -1 + src:icu
>
> * CVE-2025-5222: Stack-based buffer overflow (Closes: #1106684)
>
> Tagged moreinfo, as question to the security team whether they want
> this in pu or as DSA.
We should fix this via bookworm-security. Thanks for preparing a debdiff!
The patch looks good, please build with -sa and upload to security-master
Cheers,
Moritz