Bug#1082631: transition: iniparser

2024-09-23 Thread Salvatore Bonaccorso
Package: release.debian.org Severity: normal X-Debbugs-Cc: inipar...@packages.debian.org, cava-a...@packages.debian.org, libapache2-mod-t...@packages.debian.org, mtd-ut...@packages.debian.org, nd...@packages.debian.org, ukui-interf...@packages.debian.org, car...@debian.org Control: affects -1 + s

Uploading linux (6.10.11-1)

2024-09-22 Thread Salvatore Bonaccorso
Hi I would like to upload linux version 6.10.11-1 to unstable. It is importing subsequent 6.10.10 and 6.10.11 versions on top of the 6.10.9-1 in testing. There are no packaging changes on top. Regards, Salvatore signature.asc Description: PGP signature

Re: Handling next linux upload to unstable

2024-09-22 Thread Salvatore Bonaccorso
Hi, On Sun, Sep 22, 2024 at 10:16:11AM +0100, Steve McIntyre wrote: > Hey Salvatore! > > On Fri, Sep 20, 2024 at 03:46:29PM +0200, Salvatore Bonaccorso wrote: > > > >Hope you and family are doing better already now. > > Thanks! > > >Just double-checking as w

Re: Handling next linux upload to unstable

2024-09-20 Thread Salvatore Bonaccorso
Hi Steve, On Sun, Sep 15, 2024 at 09:26:07PM +0100, Steve McIntyre wrote: > On Sun, Sep 15, 2024 at 12:31:12AM +0200, Cyril Brulebois wrote: > >Steve McIntyre (2024-09-14): > >> > >> That looks great for me, thanks. > > > >Then I think my work here is done: > > > >kibi@respighi:~$ dak ls deb

Handling next linux upload to unstable (was: Re: Uploading linux (6.10.7-1))

2024-09-13 Thread Salvatore Bonaccorso
Hi Cyril, Steve, On Wed, Sep 04, 2024 at 08:27:44AM +0200, Salvatore Bonaccorso wrote: > Hi Cyril, Steve, > > On Wed, Sep 04, 2024 at 07:51:40AM +0200, Cyril Brulebois wrote: > > Salvatore Bonaccorso (2024-09-03): > > > Right, this is sensible. We have currently th

Bug#1081034: bookworm-pu: package ikiwiki-hosting/0.20220716-2+deb12u1

2024-09-09 Thread Salvatore Bonaccorso
Hi Simon, Thanks for your reply, much appreciated! On Sat, Sep 07, 2024 at 07:20:14PM +0100, Simon McVittie wrote: > On Sat, 07 Sep 2024 at 12:13:20 +0200, Salvatore Bonaccorso wrote: > > We discussed this, if we should release the update for ikiwiki-hosting > > (real impact) and

Bug#1081035: bookworm-pu: package fcgiwrap/1.1.0-14+deb12u1

2024-09-07 Thread Salvatore Bonaccorso
rship of the new git directory. +(LP: #2067942, Closes: #1072394) + + -- Salvatore Bonaccorso Sat, 07 Sep 2024 11:31:30 +0200 + fcgiwrap (1.1.0-14) unstable; urgency=medium * Brown paper bag release. diff -Nru fcgiwrap-1.1.0/debian/tests/git-http-backend fcgiwrap-1.1.0/debian/tests/git

Bug#1081034: bookworm-pu: package ikiwiki-hosting/0.20220716-2+deb12u1

2024-09-07 Thread Salvatore Bonaccorso
nd the +git-daemon running as ikiwiki-anon needs to be able to read them all. +(Closes: #1076751) + + -- Salvatore Bonaccorso Sat, 07 Sep 2024 11:38:42 +0200 + ikiwiki-hosting (0.20220716-2) unstable; urgency=medium * d/p/ikisite-backup-Create-the-bundle-as-the-site-s-user.patch: di

Uploading linux (6.10.8-1)

2024-09-05 Thread Salvatore Bonaccorso
Hi I would like to upload linux version 6.10.8-1 to unstable. This imports on top 6.10.8 only. It addresses additionally #1079167. There are changes to address the current FTBFS on arm64 and riscv64: [ Aurelien Jarno ] * [riscv64] udeb: Ship mtd in kernel-image, drop mtd-core-modules and

Re: Uploading linux (6.10.7-1)

2024-09-03 Thread Salvatore Bonaccorso
Hi Cyril, Steve, On Wed, Sep 04, 2024 at 07:51:40AM +0200, Cyril Brulebois wrote: > Salvatore Bonaccorso (2024-09-03): > > Right, this is sensible. We have currently the FTBFS for 6.10.7-1 for > > riscv64 and arm64 which needs to be sorted. We either can have this > > f

Re: Uploading linux (6.10.7-1)

2024-09-03 Thread Salvatore Bonaccorso
Hi Cyril, On Tue, Sep 03, 2024 at 05:28:38PM +0200, Cyril Brulebois wrote: > Ciao Salvatore, > > [ftpmaster@ dropped.] > > Salvatore Bonaccorso (2024-08-31): > > I would like to upload linux version 6.10.7-1 to unstable. This is the > > import of the stable series up

Uploading linux (6.10.7-1)

2024-08-31 Thread Salvatore Bonaccorso
Hi, I would like to upload linux version 6.10.7-1 to unstable. This is the import of the stable series up to 6.10.7. It addresses as well two for now known CVEs assigned for issues fixed with 6.10.7. o packaging changes are done in this update (apart a patch referesh for offsets). Regards, Salva

Bug#1054915: bookworm-pu: package freerdp2/2.11.2+dfsg1-1~deb12u1

2024-08-27 Thread Salvatore Bonaccorso
Hi Tobi, On Sat, Jun 22, 2024 at 08:46:39PM +0200, Salvatore Bonaccorso wrote: > Hi Tobi, > > On Wed, Feb 21, 2024 at 08:00:42AM +, Jonathan Wiltshire wrote: > > Control: tag -1 moreinfo > > > > Hi, > > > > On Sat, Oct 28, 2023 at 05:58:38PM +0200, To

Uploading linux (6.10.6-1)

2024-08-19 Thread Salvatore Bonaccorso
Hi, I would like to upload linux version 6.10.6-1 to unstable. This is the import of the stable series up to 6.10.6. No packaging changes are done in this update. Regards, Salvatore signature.asc Description: PGP signature

Bug#1076504: bookworm-pu: package qemu/1:7.2+dfsg-7+deb12u7

2024-08-18 Thread Salvatore Bonaccorso
Hi, On Sun, Aug 18, 2024 at 02:39:09PM +0200, Salvatore Bonaccorso wrote: > Hi, > > On Sat, Aug 17, 2024 at 05:34:45PM +0100, Adam D. Barratt wrote: > > Control: tags -1 + confirmed > > > > On Wed, 2024-07-17 at 15:15 +0300, Michael Tokarev wrote: > > > [ Rea

Bug#1076504: bookworm-pu: package qemu/1:7.2+dfsg-7+deb12u7

2024-08-18 Thread Salvatore Bonaccorso
Hi, On Sat, Aug 17, 2024 at 05:34:45PM +0100, Adam D. Barratt wrote: > Control: tags -1 + confirmed > > On Wed, 2024-07-17 at 15:15 +0300, Michael Tokarev wrote: > > [ Reason ] > > There were 2 qemu stable/bugfix releases (7.2.12 and 7.2.13) since > > the previous debian release, fixing a number

Bug#1008164: RM: obfs4proxy/0.0.8-1

2024-08-14 Thread Salvatore Bonaccorso
Hi, On Wed, Aug 14, 2024 at 08:54:51AM +0200, Clément Hermann wrote: > Hi, > > Sorry, the emails went to a strange filter. Pinging on IRC was a good move. > ;) :-) glad it was of help! > Le 12/08/2024 à 22:38, Adam D. Barratt a écrit : > > Re-ping, given that we're less than three weeks from th

Bug#1077584: bullseye-pu: package putty/0.74-1+deb11u2

2024-08-12 Thread Salvatore Bonaccorso
Hi, On Sat, Aug 10, 2024 at 08:49:43PM +0100, Jonathan Wiltshire wrote: > Control: tag -1 confirmed > > Hi, > > On Tue, Jul 30, 2024 at 08:02:31AM +, Bastien Roucariès wrote: > > [ Reason ] > > Security fix CVE-2024-31497 > > If you're sure this shouldn't be a DSA, please go ahead. Just to

Uploading linux (6.10.4-1)

2024-08-12 Thread Salvatore Bonaccorso
Hi I would like to upload linux version 6.10.4-1 to unstable. This is the import of one single stable version on top of the version now migrated to testing. No packaging changes are done. Regards, Salvatore signature.asc Description: PGP signature

Uploading linux (6.9.12-1)

2024-07-27 Thread Salvatore Bonaccorso
Hi I would like to upload linux version 6.9.12-1. This is a small increment on top of 6.9.11 but notably it fixes CVE-2024-41090 and CVE-2024-41091, cf. https://www.openwall.com/lists/oss-security/2024/07/24/4 . No packaging changes are done. Regards, Salvatore signature.asc Description: PGP s

Uploading linux (6.9.11-1)

2024-07-25 Thread Salvatore Bonaccorso
Hi I would like to upload linux version 6.9.11-1 later today to unstable. It just imports one upstream stable version 6.9.11 on top of what now migrated to testing (6.9.10-1). No packaging changes are done. Regards, Salvatore signature.asc Description: PGP signature

Uploading linux (6.9.10-1)

2024-07-19 Thread Salvatore Bonaccorso
Hi I would like to upload linux version 6.9.10-1 later today to unstable. It just imports one upstream stable version 6.9.10 on top of what now migrated to testing (6.9.9-1). No packaging changes are done. Regards, Salvatore signature.asc Description: PGP signature

Bug#1076460: bullseye-pu: package nfs-utils/1:1.3.4-6+deb11u1

2024-07-16 Thread Salvatore Bonaccorso
eb11u1) bullseye; urgency=medium + + * exportfs: Make sure pass all valid export flags to nfsd (Closes: #1076448) + + -- Salvatore Bonaccorso Tue, 16 Jul 2024 20:37:00 +0200 + nfs-utils (1:1.3.4-6) unstable; urgency=medium * mountstats: Remove a shebang diff -Nru nfs-utils-1.3.4/debian/p

Bug#1076335: bookworm-pu: package libvirt/9.0.0-4

2024-07-16 Thread Salvatore Bonaccorso
Hi Andrea, On Sun, Jul 14, 2024 at 05:15:58PM +0200, Andrea Bolognani wrote: [...] > The only thing that strikes me as a bit odd and we might need to > rectify is that CVE-2024-2496, while properly tracked in the Debian > security tracker, doesn't have a corresponding Debian bug. Should one > be f

Bug#1076271: bookworm-pu: package dmitry

2024-07-16 Thread Salvatore Bonaccorso
Hi, On Sat, Jul 13, 2024 at 02:37:32PM +0200, Petter Reinholdtsen wrote: > > Package: release.debian.org > Affects: dmitry > > The https://tracker.debian.org/pkg/dmitry > package in stable, > version 1.3a-1.2, got a few security issues that could be fixed. These > are CVE-2024-31837, CVE-2020-1

Uploading linux (6.9.9-1)

2024-07-13 Thread Salvatore Bonaccorso
Hi I would like to upload linux version 6.9.9-1 later today to unstable. It just imports one upstream stable version 6.9.9 on top of what now migrated to testing and is in unstable. No packaging changes are done. Regards, Salvatore signature.asc Description: PGP signature

Uploading linux (6.9.8-1)

2024-07-07 Thread Salvatore Bonaccorso
Hi I would like to upload linux version 6.9.8-1 later today to unstable. It just imports one upstream stable version 6.9.8 on top of what we currently have in unstable. Packaging changes include: * [rt] Drop "pinctrl: renesas: rzg2l: Use spin_{lock,unlock}_irq{save,restore}" (applied ups

Bug#1074059: bookworm-pu: package nodejs/18.19.0+dfsg-6~deb12u2

2024-07-03 Thread Salvatore Bonaccorso
Hi, On Wed, Jul 03, 2024 at 11:36:46PM +0200, Jérémy Lal wrote: > Le mer. 3 juil. 2024 à 23:04, Andres Salomon a écrit : > > > > > > > On 6/25/24 16:34, Jérémy Lal wrote: > > > > > > > > > Le mar. 25 juin 2024 à 22:22, Salvatore

Uploading linux 6.9.6-1

2024-06-27 Thread Salvatore Bonaccorso
Hi I would like to upload linux version 6.9.6-1 later today to unstable, which moves the 6.9.y series to unstable, replacing the already EOLed 6.8.y series. Some packaging changes are included: * [x86] Refresh "intel-iommu: Add option to exclude integrated GPU only" * [x86] Refresh "intel

Bug#1074059: bookworm-pu: package nodejs/18.19.0+dfsg-6~deb12u2

2024-06-25 Thread Salvatore Bonaccorso
Hi all, On Sat, Jun 22, 2024 at 06:26:23PM +0300, Adrian Bunk wrote: > Package: release.debian.org > Severity: normal > Tags: bookworm > User: release.debian@packages.debian.org > Usertags: pu > X-Debbugs-Cc: secur...@debian.org, Debian Javascript Maintainers > , Jérémy Lal > > This upload

Bug#1069891: bookworm-pu: package ansible/7.7.0+dfsg-3+deb12u1

2024-06-22 Thread Salvatore Bonaccorso
Hi Lee, On Sat, Jun 15, 2024 at 11:06:23PM +0100, Jonathan Wiltshire wrote: > Control: tag -1 moreinfo > > On Fri, Apr 26, 2024 at 03:05:00PM +0200, Lee Garrett wrote: > > I'm requesting to bump the version of the ansible package > > ("ansible-community > > collection") to the last minor semanti

Bug#1070739: bookworm-pu: package python-glance-store/4.1.0-4

2024-06-22 Thread Salvatore Bonaccorso
On Sat, Jun 15, 2024 at 07:29:56PM +0100, Adam D. Barratt wrote: > Control: tags -1 -moreinfo +confirmed > > On Sat, 2024-06-15 at 16:21 +0100, Adam D. Barratt wrote: > > Control: tags -1 + moreinfo > > > > On Wed, 2024-05-08 at 17:59 +0200, Salvatore Bonaccorso wrote

Bug#1070193: bookworm-pu: package ansible-core/2.14.16-0+deb12u1

2024-06-22 Thread Salvatore Bonaccorso
Hi lee, On Sat, Jun 15, 2024 at 11:25:26PM +0100, Jonathan Wiltshire wrote: > Control: tag -1 confirmed > > On Wed, May 01, 2024 at 05:05:05PM +0200, Lee Garrett wrote: > > [ Reason ] > > This is a bugfix-only update from ansible-core 2.14.3 to 2.14.16. This fixes > > three CVEs: > > - Address is

Bug#1068888: bookworm-pu: package zookeeper/3.8.0-11+deb12u2

2024-06-22 Thread Salvatore Bonaccorso
Hi Bastien, On Sun, Jun 16, 2024 at 12:50:59PM +0100, Adam D. Barratt wrote: > On Sun, 2024-06-16 at 11:12 +, Bastien Roucariès wrote: > > control: tag -1 - moreinfo > > Le samedi 15 juin 2024, 22:49:24 UTC Jonathan Wiltshire a écrit : > > > > > [...] > > > > zookeeper-3.8.0/debian/patches/00

Bug#1066965: bookworm-pu: package newlib/3.3.0-2

2024-06-22 Thread Salvatore Bonaccorso
Hi Petter, On Sat, May 25, 2024 at 09:44:06PM +0100, Adam D. Barratt wrote: > Control: tags -1 + confirmed > > On Sat, 2024-03-16 at 09:09 +0100, Petter Reinholdtsen wrote: > > +newlib (3.3.0-2) bookworm; urgency=medium > > > > As Salvatore already noted, that's not a conventional version numbe

Bug#1055211: bookworm-pu: package gcc-12/12.2.0-14+deb12u1 (CVE-2023-4039)

2024-06-22 Thread Salvatore Bonaccorso
Hi, On Thu, Nov 02, 2023 at 11:11:56AM +0100, Emanuele Rocca wrote: > Package: release.debian.org > Severity: normal > Tags: bookworm > User: release.debian@packages.debian.org > Usertags: pu > X-Debbugs-Cc: debian-...@lists.debian.org, j...@debian.org, d...@debian.org > Control: affects -1 +

Bug#1054915: bookworm-pu: package freerdp2/2.11.2+dfsg1-1~deb12u1

2024-06-22 Thread Salvatore Bonaccorso
Hi Tobi, On Wed, Feb 21, 2024 at 08:00:42AM +, Jonathan Wiltshire wrote: > Control: tag -1 moreinfo > > Hi, > > On Sat, Oct 28, 2023 at 05:58:38PM +0200, Tobias Frost wrote: > > Backporting the fixes is of course possible, but bears a significant > > risk for regression, therefor I would pre

Bug#1053832: bookworm-pu: package ceph/16.2.11+ds-2 (CVE-2023-43040)

2024-06-22 Thread Salvatore Bonaccorso
On Sat, Apr 06, 2024 at 10:36:50PM +0100, Jonathan Wiltshire wrote: > Control: tag -1 confirmed > > On Thu, Oct 12, 2023 at 11:34:58AM +0200, Thomas Goirand wrote: > > [ Reason ] > > CVE-2023-43040 > > > > [ Impact ] > > security issue with RGW with improperly verified POST keys. > > Sorry for

Bug#1073234: bookworm-pu: package gdk-pixbuf/2.42.10+dfsg-1+deb12u1

2024-06-22 Thread Salvatore Bonaccorso
Hi Jeremy, On Fri, Jun 21, 2024 at 04:31:18PM -0400, Jeremy Bícha wrote: > On Fri, Jun 21, 2024 at 3:52 PM Salvatore Bonaccorso > wrote: > > On Wed, Jun 19, 2024 at 07:11:11PM +0100, Adam D. Barratt wrote: > > > On Sat, 2024-06-15 at 08:28 +0200, Salvatore Bonaccorso wro

Bug#1073234: bookworm-pu: package gdk-pixbuf/2.42.10+dfsg-1+deb12u1

2024-06-21 Thread Salvatore Bonaccorso
Hi all, On Wed, Jun 19, 2024 at 07:11:11PM +0100, Adam D. Barratt wrote: > On Sat, 2024-06-15 at 08:28 +0200, Salvatore Bonaccorso wrote: > > Hi Jeremy, Simon, > > > > On Fri, Jun 14, 2024 at 06:22:13PM -0400, Jeremy Bícha wrote: > > > > [...] > > > Sal

Re: Planning for 12.7/11.11

2024-06-21 Thread Salvatore Bonaccorso
Hi Jonathan, On Thu, Jun 20, 2024 at 10:35:35PM +0100, Jonathan Wiltshire wrote: > Hi, > > A finally-final point release is required for bullseye, and we're a bit > constrained on dates. The security team (CC) wish to cease security support > from Wednesday 14th August and hand over to LTS as soo

Bug#1073234: bookworm-pu: package gdk-pixbuf/2.42.10+dfsg-1+deb12u1

2024-06-14 Thread Salvatore Bonaccorso
Hi Jeremy, Simon, On Fri, Jun 14, 2024 at 06:22:13PM -0400, Jeremy Bícha wrote: > On Fri, Jun 14, 2024 at 5:18 PM Salvatore Bonaccorso > wrote: > > > > Package: release.debian.org > > Severity: normal > > Tags: bookworm > > X-Debbugs-Cc: gdk-pix...@packages.d

Bug#1073234: bookworm-pu: package gdk-pixbuf/2.42.10+dfsg-1+deb12u1

2024-06-14 Thread Salvatore Bonaccorso
edium + + * ANI: Reject files with multiple anih chunks (CVE-2022-48622) +(Closes: #1071265) + * ANI: Reject files with multiple INAM or IART chunks + * ANI: Validate anih chunk size + + -- Salvatore Bonaccorso Thu, 13 Jun 2024 23:04:36 +0200 + gdk-pixbuf (2.42.10+dfsg-1) unstable; urgency=m

Bug#1070702: bookworm-pu: package nano/7.2-1+deb12u1

2024-06-08 Thread Salvatore Bonaccorso
Hi Jordi, On Tue, May 07, 2024 at 04:00:15PM +0200, Jordi Mallach wrote: > Package: release.debian.org > Severity: normal > Tags: bookworm > X-Debbugs-Cc: n...@packages.debian.org > Control: affects -1 + src:nano > User: release.debian@packages.debian.org > Usertags: pu > > As we did in previ

Uploading linux (6.8.12-1)

2024-05-30 Thread Salvatore Bonaccorso
Hi I would like to upload lnux version 6.8.12-1 to unstable, which is importing the last stable version for the 6.8.y series which is EOL with 6.8.12. After that a switch to 6.9.y will need to happen. No packaging changes are included. Regards, Salvatore signature.asc Description: PGP signatur

Uploading linux (6.8.11-1)

2024-05-25 Thread Salvatore Bonaccorso
Hi I would like to upload over the weekend linux verison 6.8.11-1 to unstable (importing two stable versions 6.8.10 and 6.8.11). No other changes are aimed to be included, but brings unstable just up to pair to upstream stable version for the 6.8.y series. Regards, Salvatore signature.asc Desc

Bug#1070998: bookworm-pu: package fossil/2.24-5~deb11u1

2024-05-25 Thread Salvatore Bonaccorso
Hi Bastien, On Sun, May 12, 2024 at 05:47:31PM +, Bastien Roucariès wrote: > Package: release.debian.org > Severity: normal > Tags: bookworm > X-Debbugs-Cc: fos...@packages.debian.org > Control: affects -1 + src:fossil > User: release.debian@packages.debian.org > Usertags: pu > > this bug

Bug#1069891: bookworm-pu: package ansible/7.7.0+dfsg-3+deb12u1

2024-05-25 Thread Salvatore Bonaccorso
Hi Lee, (disclaimer, not a member of the release team) On Fri, May 10, 2024 at 12:15:56PM +0200, Lee Garrett wrote: > I have just pushed some meta-data updates, and also a change that fixes > CVE-2023-4237 in this package. See the commit logs here: > > https://salsa.debian.org/python-team/packag

Bug#1070739: bookworm-pu: package python-glance-store/4.1.0-4

2024-05-08 Thread Salvatore Bonaccorso
Hi, On Wed, May 08, 2024 at 09:52:01AM +0200, Thomas Goirand wrote: > Package: release.debian.org > Severity: normal > Tags: bookworm > User: release.debian@packages.debian.org > Usertags: pu > X-Debbugs-Cc: python-glance-st...@packages.debian.org > Control: affects -1 + src:python-glance-stor

Bug#1069690: bookworm-pu: package libkf5ksieve/4:22.12.3-1+deb12u1

2024-05-01 Thread Salvatore Bonaccorso
Hi Patrick, On Mon, Apr 22, 2024 at 09:36:54PM +0200, Patrick Franz wrote: > Package: release.debian.org > Severity: normal > Tags: bookworm > X-Debbugs-Cc: delta...@debian.org > User: release.debian@packages.debian.org > Usertags: pu > > [ Reason ] > There is a bug in libkf5sieve where the p

Uploading linux (6.7.12-1)

2024-04-23 Thread Salvatore Bonaccorso
Hi I plan to upload 6.7.12-1 later to unstable. Note, this is a situation far from ideal and personally not very happy with. 6.7.12 was the last version in the 6.7.y release and upstream has long moved already to 6.8.y while EOL'ing 6.7.y. This upload will thus release with a couple of known unfi

Bug#1065413: bookworm-pu: package openssl/3.0.13-1~deb12u1

2024-04-11 Thread Salvatore Bonaccorso
Hi Sebastian, On Tue, Apr 09, 2024 at 06:18:13PM +0200, Sebastian Andrzej Siewior wrote: > On 2024-04-07 23:46:28 [+0200], To Adam D. Barratt wrote: > > On 2024-03-24 20:06:12 [+], Adam D. Barratt wrote: > > > > > > Sorry for not getting to this sooner. Is this still the case? > > > > So. Th

Bug#1068836: bookworm-pu: package yapet/2.6-2~deb12u1

2024-04-11 Thread Salvatore Bonaccorso
2.6/debian/changelog --- yapet-2.6/debian/changelog 2022-03-14 14:19:11.0 +0100 +++ yapet-2.6/debian/changelog 2024-04-11 20:40:18.0 +0200 @@ -1,3 +1,16 @@ +yapet (2.6-2~deb12u1) bookworm; urgency=medium + + * Rebuild for bookworm + + -- Salvatore Bonaccorso Thu, 11 Apr 2024 20:4

Bug#1068633: bookworm-pu: package cjson/1.7.15-1+deb12u1

2024-04-08 Thread Salvatore Bonaccorso
Hi, Disclaimer, this is not an authoritative answer as I'm not part of the stable release managers. On Mon, Apr 08, 2024 at 12:27:50PM +0300, Maytham Alsudany wrote: > Package: release.debian.org > Severity: normal > Tags: bookworm > User: release.debian@packages.debian.org > Usertags: pu > X

Bug#1066965: bookworm-pu: package newlib/3.3.0-2

2024-04-05 Thread Salvatore Bonaccorso
Hi, On Tue, Apr 02, 2024 at 12:36:53PM +0200, Petter Reinholdtsen wrote: > > Btw, what is the timeline for approval or rejection for this security > upload proposal? Note that if you are confident that the upload is accepted as it, you *could* already upload according to the improved workflow. *

Bug#1066965: bookworm-pu: package newlib/3.3.0-2

2024-03-20 Thread Salvatore Bonaccorso
Hi [disclaimer, not an authoritative answer as not part of the stable release managers] On Sat, Mar 16, 2024 at 09:09:05AM +0100, Petter Reinholdtsen wrote: > > Package: release.debian.org > > The https://tracker.debian.org/pkg/newlib > package got an open > security problem with malloc and fri

Uploading linux (6.7.9-2)

2024-03-13 Thread Salvatore Bonaccorso
Hi While I realize there are much of changes going on unstable, I still would like to upload linux version (6.7.9-2) (yes no new upstream version) mitigating the Register File Data Sampling (RFDS) vulnerability (CVE-2023-28746). This goes along with a intel-microcode update which already was uplo

Uploading linux (6.7.9-1)

2024-03-07 Thread Salvatore Bonaccorso
Hi I would like to upload linux version 6.7.9-1 to unstable soon if possible. There is the import of 6.7.8 and 6.7.9 from the 6.7.y stable series. Note that src:linux is not binNMU safe buildable and thus this is (for the time beeing) disabled since https://salsa.debian.org/kernel-team/linux/-/c

Uploading linux (6.7.7-1)

2024-03-01 Thread Salvatore Bonaccorso
Hi I would like to upload linux version 6.7.7-1 to unstable over the weekend. The new upload would consist of a new upstream version switching to the 6.7.y series in unstable. Apart from switching from 6.6.y to 6.7.y series there are additional changes covering: * Enable CONFIG_MFD_RK8XX_SPI f

Bug#1061190: bullseye-pu: package gnutls28/3.7.1-5+deb11u5

2024-03-01 Thread Salvatore Bonaccorso
Hi Andreas, On Thu, Feb 01, 2024 at 06:35:38AM +, Adam D. Barratt wrote: > Control: tags -1 + confirmed > > On Sat, 2024-01-20 at 15:53 +0100, Andreas Metzler wrote: > > I would like to fix both CVE-2024-0567 and CVE-2024-0553 via a > > oldstable-updates since they do not require a DSA. > >

Bug#1063675: bookworm-pu: package nvidia-graphics-drivers/525.147.05-6~deb12u1

2024-02-13 Thread Salvatore Bonaccorso
Hi Andreas, On Mon, Feb 12, 2024 at 12:37:44AM +0100, Andreas Beckmann wrote: > On 11/02/2024 21.36, Salvatore Bonaccorso wrote: > > If I can add a comment: I (but note I'm not wearing a > > nvidia-graphics-drivers maintainer hat) would support that, as there > > are

Bug#1063675: bookworm-pu: package nvidia-graphics-drivers/525.147.05-6~deb12u1

2024-02-11 Thread Salvatore Bonaccorso
Hi Jonathan, On Sun, Feb 11, 2024 at 12:29:45AM +, Jonathan Wiltshire wrote: > Control: tag -1 confirmed > > On Sat, Feb 10, 2024 at 11:00:58PM +0100, Andreas Beckmann wrote: > > [ Reason ] > > 1) A backported (by upstream) change in Linux 6.1.76 (included in > > today's point release) broke

Bug#1057107: bullseye-pu: package libssh2/1.9.0-2

2024-02-06 Thread Salvatore Bonaccorso
Hi Nicolas, On Tue, Feb 06, 2024 at 01:46:04PM -0500, Nicolas Mora wrote: > Control: tag - moreinfo > > Thanks, > > Sorry, it seems that I'm not very well aware of the BTS process, according > to [1] this is how I should untag the bug. > > [1] https://www.debian.org/Bugs/server-control If you

Re: Uploading linux (6.6.15-1)

2024-02-03 Thread Salvatore Bonaccorso
Hi, On Sat, Feb 03, 2024 at 12:32:08AM +0100, Cyril Brulebois wrote: > Salvatore Bonaccorso (2024-02-02): > > One thing is still unresolved, thus additonally to the explicit CC to > > kibi, as well including debian-boot. We have the armel d-i situation > > not yet resolved,

Uploading linux (6.6.15-1)

2024-02-02 Thread Salvatore Bonaccorso
Hi, I would like to upload linux version 6.6.15-1 ideally over the weekend to unstable. The new version imports two versions of the 6.6.y stable series (which is upstream an LTS) up to 6.6.15. It contains a larger amount of changes as it consisted of versions released after the merge window upstr

Uploading linux (6.6.13-1)

2024-01-20 Thread Salvatore Bonaccorso
I would like to upload linux version 6.6.13-1 later today to unstable. The new version imports two versions of 6.6.y stable series (though the only commit from 6.6.12 was already included in the last update). The new upstream stable version fixes CVE-2023-6610 and CVE-2023-6915. Note, that the arm

Bug#1061190: bullseye-pu: package gnutls28/3.7.1-5+deb11u5

2024-01-20 Thread Salvatore Bonaccorso
Hi, On Sat, Jan 20, 2024 at 03:53:45PM +0100, Andreas Metzler wrote: > Package: release.debian.org > Severity: normal > Tags: bullseye > User: release.debian@packages.debian.org > Usertags: pu > X-Debbugs-Cc: gnutl...@packages.debian.org, t...@security.debian.org > Control: affects -1 + src:gn

Bug#1061177: bullseye-pu: package tar/1.34+dfsg-1+deb11u1

2024-01-20 Thread Salvatore Bonaccorso
; urgency=medium + + * Non-maintainer upload. + * Fix boundary checking in base-256 decoder (CVE-2022-48303) + * Fix handling of extended header prefixes (CVE-2023-39804) +(Closes: #1058079) + + -- Salvatore Bonaccorso Sat, 20 Jan 2024 10:59:10 +0100 + tar (1.34+dfsg-1) unstable; urgency

Bug#1061176: bookworm-pu: package tar/1.34+dfsg-1.2+deb12u1

2024-01-20 Thread Salvatore Bonaccorso
) bookworm; urgency=medium + + * Non-maintainer upload. + * Fix boundary checking in base-256 decoder (CVE-2022-48303) + * Fix handling of extended header prefixes (CVE-2023-39804) +(Closes: #1058079) + + -- Salvatore Bonaccorso Sat, 20 Jan 2024 10:27:07 +0100 + tar (1.34+dfsg-1.2) unstable

Re: Uploading linux (6.6.10-1)

2024-01-07 Thread Salvatore Bonaccorso
Hi, On Sun, Jan 07, 2024 at 02:14:30PM +0100, Bastian Blank wrote: > On Sun, Jan 07, 2024 at 02:03:32PM +0100, Salvatore Bonaccorso wrote: > > I would like to upload linux version 6.6.10-1 later today to unstable. > > I would like to have 6.6.9 in testing first, but we can als

Uploading linux (6.6.10-1)

2024-01-07 Thread Salvatore Bonaccorso
Hi I would like to upload linux version 6.6.10-1 later today to unstable. The new version imports one more 6.6.y stable series version (6.6.10). The new upstream stable version fixes in particular CVE-2024-0193 (which is already addressed in bookworm-security and bullseye-security). There is one

Bug#1059291: bookworm-pu: package spip/4.1.9+dfsg-1+deb12u3

2023-12-30 Thread Salvatore Bonaccorso
Hi, On Fri, Dec 22, 2023 at 01:28:00PM +0100, David Prévot wrote: > Package: release.debian.org > Severity: normal > Tags: bookworm > User: release.debian@packages.debian.org > Usertags: pu > X-Debbugs-Cc: s...@packages.debian.org, t...@security.debian.org > Control: affects -1 + src:spip > >

Bug#1059289: bullseye-pu: package spip/3.2.11-3+deb11u10

2023-12-30 Thread Salvatore Bonaccorso
Hi, On Fri, Dec 22, 2023 at 01:21:56PM +0100, David Prévot wrote: > Package: release.debian.org > Severity: normal > Tags: bullseye > User: release.debian@packages.debian.org > Usertags: pu > X-Debbugs-Cc: s...@packages.debian.org, t...@security.debian.org > Control: affects -1 + src:spip > >

Bug#1059427: bullseye-pu: package haproxy/2.2.9-2+deb11u6

2023-12-25 Thread Salvatore Bonaccorso
Hi, On Mon, Dec 25, 2023 at 10:35:16AM +0100, Tobias Frost wrote: > Package: release.debian.org > Severity: normal > Tags: bullseye > User: release.debian@packages.debian.org > Usertags: pu > X-Debbugs-Cc: hapr...@packages.debian.org, t...@security.debian.org > Control: affects -1 + src:haprox

Bug#1059235: bookworm-pu: package fish/3.6.0-3.1+deb12u1

2023-12-21 Thread Salvatore Bonaccorso
Hi, On Thu, Dec 21, 2023 at 03:16:22PM -0500, M. Zhou wrote: > Package: release.debian.org > Severity: normal > Tags: bookworm > User: release.debian@packages.debian.org > Usertags: pu > X-Debbugs-Cc: f...@packages.debian.org > Control: affects -1 + src:fish > > > [ Reason ] > > Cherry-pick

Bug#1057179: Acknowledgement (bookworm-pu: package mariadb-10.6 1:10.11.6-0+deb12u1)

2023-12-09 Thread Salvatore Bonaccorso
Hi Otto, On Sat, Dec 09, 2023 at 10:58:09PM +0800, Otto Kekäläinen wrote: > Hi Debian security team! > > MariaDB 1:10.11.6-1 entered Trixie only today after being stuck in > pending migration since Nov 28th from unstable. This > 1:10.11.6-0+deb12u1 missed the point update window. > > Are you OK

Re: Bug#1057843: linux: ext4 data corruption in 6.1.64-1

2023-12-09 Thread Salvatore Bonaccorso
Hi, On Sat, Dec 09, 2023 at 03:07:37PM +0100, Salvatore Bonaccorso wrote: > Source: linux > Version: 6.1.64-1 > Severity: grave > Tags: upstream > Justification: causes non-serious data loss > X-Debbugs-Cc: debian-release@lists.debian.org, car...@debian.org, > a...@debian

Bug#1057843: linux: ext4 data corruption in 6.1.64-1

2023-12-09 Thread Salvatore Bonaccorso
Source: linux Version: 6.1.64-1 Severity: grave Tags: upstream Justification: causes non-serious data loss X-Debbugs-Cc: debian-release@lists.debian.org, car...@debian.org, a...@debian.org Hi I'm filling this for visibility. There might be a ext4 data corruption issue with the kernel released i

Re: maintainer built binary package in stable release, still (Re: Bug#1054401: bookworm-pu: package nagios-plugins-contrib/42.20230308+deb12u1)

2023-12-07 Thread Salvatore Bonaccorso
Hi Adam, On Thu, Dec 07, 2023 at 01:56:34PM +, Adam D. Barratt wrote: > On Thu, 2023-12-07 at 12:40 +0100, Paul Gevers wrote: > > Hi, > > > > On 07-12-2023 12:20, Adrian Bunk wrote: > > > On Thu, Dec 07, 2023 at 11:18:42AM +0100, Paul Gevers wrote: > > > > I hope that in several hours, > > >

Re: Bug in linux 6.1.64-1 (source) into proposed-updates

2023-12-05 Thread Salvatore Bonaccorso
Hi, On Tue, Dec 05, 2023 at 06:14:43PM +0100, djw6g6b5...@temp.mailbox.org wrote: > There' s a bug in linux-image-amd64 version 6.1.64-1 for bookworm. > The updates breaks wlan on a Lenovo T490s. Current versions used to work > fine. I' m unable to submit a bug report. ('Message with no Package: t

Bug#1057274: bookworm-pu: package gimp/2.10.34-1+deb12u2

2023-12-02 Thread Salvatore Bonaccorso
Hi Adrian, On Sat, Dec 02, 2023 at 04:46:22PM +0200, Adrian Bunk wrote: > Package: release.debian.org > Severity: normal > Tags: bookworm > User: release.debian@packages.debian.org > Usertags: pu > X-Debbugs-Cc: Salvatore Bonaccorso > > * Add Conflicts+Replaces

Bug#1054421: bookworm-pu: package weborf/0.19

2023-11-29 Thread Salvatore Bonaccorso
Hi Salvo, On Wed, Nov 29, 2023 at 11:39:40PM +0100, Salvo Tomaselli wrote: > Hello, > > Go ahead with what? > > Do a new debdiff with the fixed version in the changelog? I understand Adam as "please just adjust the version as discussed to 0.19-2.1+deb12u1 and then feel free to upload the packag

Uploading linux (6.5.13-1)

2023-11-28 Thread Salvatore Bonaccorso
Hi, I would like to upload linux version 6.5.13-1 today to unstable. The new version imports new stable series up to 6.5.13. A (manual) ABI bump is included. With the upload CVE-2023-6111 is addressed as well. The RT patchset remains disabled and is pending to be enabled with the 6.6.y versions

Bug#1007884: bullseye-pu: package glewlwyd/2.5.2-2+deb11u2

2023-11-27 Thread Salvatore Bonaccorso
Hi Nicolas, On Mon, Nov 27, 2023 at 08:00:39AM -0500, Nicolas Mora wrote: > Hello, > > Here is a new debdiff for the glewlwyd/2.5.2-2+deb11u2 package, which now > also includes the fix for CVE-2023-49208. > diff -Nru glewlwyd-2.5.2/debian/changelog glewlwyd-2.5.2/debian/changelog > --- glewlwyd-

Bug#1056711: RM: gimp-dds/3.0.1-1

2023-11-25 Thread Salvatore Bonaccorso
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: rm X-Debbugs-Cc: t...@security.debian.org, Adrian Bunk , car...@debian.org Dear stable release managers, Please remove src:gimp-dds in the next bullseye point release. It has since gimp 2.10.10 up

Bug#1056710: RM: gimp-dds/3.0.1-3

2023-11-25 Thread Salvatore Bonaccorso
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: rm X-Debbugs-Cc: t...@security.debian.org, b...@debian.org, car...@debian.org Dear stable release managers, Please remove src:gimp-dds in the next bookworm point release. It has since gimp 2.10.10

Bug#1055965: bookworm-pu: package network-manager-openconnect/1.2.8-3+deb12u1

2023-11-14 Thread Salvatore Bonaccorso
/changelog --- network-manager-openconnect-1.2.8/debian/changelog 2022-05-21 15:35:15.0 +0200 +++ network-manager-openconnect-1.2.8/debian/changelog 2023-11-14 15:15:44.0 +0100 @@ -1,3 +1,14 @@ +network-manager-openconnect (1.2.8-3+deb12u1) bookworm; urgency=medium + + [ Salvatore

Bug#1054455: bullseye-pu: package weborf/0.17-3

2023-11-04 Thread Salvatore Bonaccorso
Hi Salvo, On Tue, Oct 24, 2023 at 09:58:30AM +0200, Salvo Tomaselli wrote: > > This version was already used: > > https://snapshot.debian.org/package/weborf/0.17-4/ > > Sorry! > > Attaching a new debdiff file with the correct version Now there is a off-by-one in the distro version :) I believe

Bug#1055155: bookworm-pu: package exim4/4.96-15+deb12u3 (2nd try for new bug)

2023-11-04 Thread Salvatore Bonaccorso
Hi Andreas, On Wed, Nov 01, 2023 at 12:03:37PM +0100, Andreas Metzler wrote: > Package: release.debian.org > Severity: normal > Tags: bookworm > User: release.debian@packages.debian.org > Usertags: pu > Control: affects -1 + src:exim4 > > Hello, > > I would like to push another round of cher

Uploading linux (6.5.10-1)

2023-11-02 Thread Salvatore Bonaccorso
Hi I would like to upload linux version 6.5.10-1 tomorrow to unstable. The new upload rebases unstable importing the new stable series versions up to 6.5.10. An ABI bump is included. CVE-2023-46813, CVE-2023-5717 and CVE-2023-46862 are fixed with the new stable import series. The RT patchset re

Bug#1054446: bookworm-pu: package wolfssl/5.5.4-2+deb12u1

2023-10-23 Thread Salvatore Bonaccorso
On Mon, Oct 23, 2023 at 10:12:27PM +0200, Bastian Germann wrote: > Am 23.10.23 um 22:02 schrieb Salvatore Bonaccorso: > > > diff -Nru wolfssl-5.5.4/debian/changelog wolfssl-5.5.4/debian/changelog > > > --- wolfssl-5.5.4/debian/changelog2023-02-06 14:41:53.0

Bug#1054446: bookworm-pu: package wolfssl/5.5.4-2+deb12u1

2023-10-23 Thread Salvatore Bonaccorso
Hi Bastian, On Mon, Oct 23, 2023 at 09:48:45PM +0200, Bastian Germann wrote: > Package: release.debian.org > Severity: normal > Tags: bookworm > User: release.debian@packages.debian.org > Usertags: pu > X-Debbugs-CC: sirkilam...@msn.com > > Hi, > > I am including a fix for wolfssl's CVE-2023

Bug#1054421: bookworm-pu: package weborf/0.19

2023-10-23 Thread Salvatore Bonaccorso
Hi, On Mon, Oct 23, 2023 at 07:07:44PM +0200, Salvo "LtWorf" Tomaselli wrote: > Package: release.debian.org > Severity: normal > Tags: bookworm > User: release.debian@packages.debian.org > Usertags: pu > X-Debbugs-Cc: web...@packages.debian.org, tipos...@tiscali.it > Control: affects -1 + src:

Uploading linux (6.5.8-1)

2023-10-22 Thread Salvatore Bonaccorso
Hi I would like to upload linux version 6.5.8-1 later today to unstable. The new upload would constist of importing new stable series version up to 6.5.8. An ABI bump is included. Notably the RT patchset is still disabled as mentioned in the 6.5.6-1 upload announcement. CVE-2023-34324 is fixed w

Uploading linux (6.5.6-1)

2023-10-07 Thread Salvatore Bonaccorso
Hi I would like to upload linux version 6.5.6-1 later today to unstable. The new upload would consist of importing new stable series version up to 6.5.6. An ABI bump is included. Notably given RT patchset is not updated anymore for 6.5.y series upstream, this update disables it temporarily. It mi

Re: Bug#983912: grub2: consider renaming signed source packages to grub2-signed-*

2023-10-06 Thread Salvatore Bonaccorso
Hi, On Sun, Nov 20, 2022 at 09:11:09PM +0100, Salvatore Bonaccorso wrote: > Hi, > > On Wed, Mar 03, 2021 at 10:52:39AM +0100, Ansgar wrote: > > Source: grub2 > > Version: 2.04-16 > > Severity: normal > > X-Debbugs-Cc: ftpmas...@debian.org, debian-release@lists.de

Re: Releasing linux/6.1.52-1 bookworm-security update without armel build, Image size problems

2023-10-02 Thread Salvatore Bonaccorso
Hi Adrian, Sorry for not replying early, busy with preparing the updates. On Fri, Sep 29, 2023 at 03:41:15AM +0300, Adrian Bunk wrote: > On Sat, Sep 09, 2023 at 10:15:59AM +0200, Salvatore Bonaccorso wrote: > >... > > Note that the last time the problem arised already earlier in &

Bug#1053240: bullseye-pu: package ghostscript/9.53.3~dfsg-7+deb11u6

2023-09-29 Thread Salvatore Bonaccorso
=medium + + * Non-maintainer upload. + * Copy pcx buffer overrun fix from devices/gdevpcx.c (CVE-2023-38559) +(Closes: #1043033) + * IJS device - try and secure the IJS server startup (CVE-2023-43115) + + -- Salvatore Bonaccorso Fri, 29 Sep 2023 14:24:57 +0200 + ghostscript (9.53.3~dfsg-7

Bug#1053239: bookworm-pu: package ghostscript/10.0.0~dfsg-11+deb12u2

2023-09-29 Thread Salvatore Bonaccorso
=medium + + * Non-maintainer upload. + * Copy pcx buffer overrun fix from devices/gdevpcx.c (CVE-2023-38559) +(Closes: #1043033) + * IJS device - try and secure the IJS server startup (CVE-2023-43115) + + -- Salvatore Bonaccorso Fri, 29 Sep 2023 14:33:30 +0200 + ghostscript (10.0.0~dfsg-11

Bug#1053219: bookworm-pu: package lemonldap-ng/2.16.1+ds-deb12u2

2023-09-29 Thread Salvatore Bonaccorso
Hi Yadd, On Fri, Sep 29, 2023 at 05:37:25PM +0400, Yadd wrote: > Package: release.debian.org > Severity: normal > Tags: bookworm > User: release.debian@packages.debian.org > Usertags: pu > X-Debbugs-Cc: lemonldap...@packages.debian.org, y...@debian.org > Control: affects -1 + src:lemonldap-ng

  1   2   3   4   5   6   7   8   9   10   >