Bug#1124465: bookworm-pu: package gnupg2/2.2.40-1.1+deb12u2
On Thu, 2026-01-01 at 19:59 +, Adam D. Barratt wrote: > Control: tags -1 + confirmed > > On Thu, 2026-01-01 at 16:12 +0100, Andreas Metzler wrote: > > this is the pendant to #1124429 for bookworm. > > > > We would like to fix CVE-2025-68973 and three other issues from > > gnupg(dot)fail in the January oldstable update. team@security > > would prefer the fix to go via stable updates because > > > [...] the key benefit to have gnupg2 exposed in public via the > > > proposed updates suites as soon accepted. > > Please go ahead. Just a quick reminder that the window for getting the update into the bookworm point release closes during this weekend. Regards, Adam
Bug#1124465: bookworm-pu: package gnupg2/2.2.40-1.1+deb12u2
Control: tags -1 + confirmed On Thu, 2026-01-01 at 16:12 +0100, Andreas Metzler wrote: > this is the pendant to #1124429 for bookworm. > > We would like to fix CVE-2025-68973 and three other issues from > gnupg(dot)fail in the January oldstable update. team@security > would prefer the fix to go via stable updates because > > [...] the key benefit to have gnupg2 exposed in public via the > > proposed updates suites as soon accepted. Please go ahead. Regards, Adam
Processed: Re: Bug#1124465: bookworm-pu: package gnupg2/2.2.40-1.1+deb12u2
Processing control commands: > tags -1 + confirmed Bug #1124465 [release.debian.org] bookworm-pu: package gnupg2/2.2.40-1.1+deb12u2 Added tag(s) confirmed. -- 1124465: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1124465 Debian Bug Tracking System Contact [email protected] with problems
Bug#1124465: bookworm-pu: package gnupg2/2.2.40-1.1+deb12u2
Package: release.debian.org Severity: normal Tags: bookworm X-Debbugs-Cc: [email protected], [email protected], Daniel Kahn Gillmor Control: affects -1 + src:gnupg2 User: [email protected] Usertags: pu Hello, this is the pendant to #1124429 for bookworm. We would like to fix CVE-2025-68973 and three other issues from gnupg(dot)fail in the January oldstable update. team@security would prefer the fix to go via stable updates because | [...] the key benefit to have gnupg2 exposed in public via the | proposed updates suites as soon accepted. [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in (old)stable [x] the issue is verified as fixed in unstable cu Andreas gnupg2_2.2.40-1.1+deb12u2.deb.diff.gz Description: application/gzip signature.asc Description: PGP signature

