[SECURITY] Debian 10 LTS will reach end-of-life on June 30th, 2024

2024-05-03 Thread Santiago Ruano Rincón
Dear Debian LTS users,

This is a gentle reminder that Debian 10 ("buster") will reach end of support
as the LTS release on June 30, 2024. Users are encouraged to upgrade to
Debian 11 ("bullseye").

Starting in July, Debian will not provide further security updates for
Debian 10. A subset of buster packages will be supported by external parties.
Detailed information can be found at [Extended LTS].

The Debian LTS Team will prepare afterwards the transition to Debian 11, the
current oldstable release, taking over support from the Security Team during
August. While the Debian LTS Team will shift its focus to bullseye, we will do
our best to also contribute with security fixes for stable and the development
releases, that remain under the responsibility of the Security Team.

Debian 11 will also receive Long Term Support for five years after its initial
release, until June 30th, 2026. We will announce the supported architectures at
a later date.

For further information about using bullseye and upgrading from buster LTS,
please refer to [LTS/Using].

Debian and its LTS Team would like to thank all contributing users, developers
and sponsors who are making it possible to extend the life of previous stable
releases, and who have made this LTS a success.

If you rely on Debian LTS, please consider [joining the team], providing
patches, testing or [funding the efforts].

More information about Debian Long Term Support can be found at
https://wiki.debian.org/LTS/.

[Extended LTS] https://wiki.debian.org/LTS/Extended
[LTS/Using] https://wiki.debian.org/LTS/Using
[joining the team] https://wiki.debian.org/LTS/Development
[funding the efforts] https://wiki.debian.org/LTS/Funding

For the Debian LTS Team,

Santiago


signature.asc
Description: PGP signature


[SECURITY] [DLA 3807-1] glibc security update

2024-05-03 Thread Adrian Bunk
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

- -
Debian LTS Advisory DLA-3807-1debian-...@lists.debian.org
https://www.debian.org/lts/security/  Adrian Bunk
May 04, 2024  https://wiki.debian.org/LTS
- -

Package: glibc
Version: 2.28-10+deb10u3
CVE ID : CVE-2024-2961
Debian Bug : 1069191

Out-of-bounds write in the iconv ISO-2022-CN-EXT module has been fixed 
in the GNU C library.

For Debian 10 buster, this problem has been fixed in version
2.28-10+deb10u3.

We recommend that you upgrade your glibc packages.

For the detailed security status of glibc please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/glibc

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-BEGIN PGP SIGNATURE-

iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmY1aigACgkQiNJCh6LY
mLGjcxAAxBL18otZwuVuVB34Erd8NEPjiBRL5fGubQ5y2T3Amo8g/SY32KUR6Ud/
r/HZh3JYcYtwKLwRcMPszVCAAxB0dhSg4hwXgvh0LYEWL+Qdwccv1EjEDxxgYVCH
ecDGYjl7dYoGrNlsf2R3IMhpX9W8fn08vdbvheSgIkFSIRwccvswftH/CFn06UBd
TQxtyX0pbWljvHYUB/BxcOViHkrF1p7MS6XDG078d54EBzB0g7wwUyUzXN41myKN
N1/2AWH7fVFbpp+zoiuw5cr1QspiOxWuqse3W0nzisGMMDIStjAFQol51eVrY2M0
DUmOYFETep/9Q9cwFTKz0czwChFgazCmKiVAnuV3pg3DAlSa8IBjKTy0VSLcBlcT
Qaoh8nI67/aFKvzNKY1InuwHeokSJyPl8raWFpX1z7gDgvbthWJ9cHghdAQdIh22
7W2AAHw1l5ZHpbPacy5x9hWjQSxBo08AlqWFGWSFf+UXqo2y66PLa4aqlham7/Yj
Umr2wyQGpmACV3RHVTEYhbjfZDAcYqdo/L0W6vrQU+AIl1kpIMZyHj23rSkmwdAC
V+A8gUa33su6AQ6axSTEq1/JembE8bv/pqaJtYyBgjMX8cJ04UdNV1Z7NsPwelaK
a2Qm312fOHDZ4AnfhYBZLC4QE01Z9J2fN4+kCUsJfPzqKA3qpiM=
=Sg1j
-END PGP SIGNATURE-