#1050881 borgbackup: Mention required documentation for upgrading repositories for fixes for CVE-2023-36811

#1050881#5
Date:
2023-08-30 19:22:07 UTC
From:
To:
Hi

borgbackup/1.2.5-1 contained a fix for CVE-2023-36811. But
additionally to the package upgrades, users need to follow the upgrade
procedure as documented.

After an update of the package one is not really aware of it, so I
suggest a NEWS.Debian entry at least referring to the needed
documentation.

Would it be a good idea to document this as well in the release notes
for trixie, for users updating from bookworm to trixie? (Cloning this
bugreport accordingly to the release-notes).

Regards,
Salvatore

#1050881#16
Date:
2025-06-23 09:30:41 UTC
From:
To:
what do i have to do (maybe link to where is "the upgrade procdure" documented)
when do i have to do it (before i next use borgbackup? before
restoring? if i forget to it what happens - do i need to delete all my
old backups? are they silently broken)
why do i have to do it (because of security issues in an older version
of borgbackup? are old backups stored elsewhere still "vulnerable"?)

#1050881#21
Date:
2025-06-23 17:20:22 UTC
From:
To:
Hi,

Oh some years have passed :)

I think the easiest think would be to point out that the fixes for
CVE-2023-36811 will require manual actions, and point to the official
description in:
https://borgbackup.readthedocs.io/en/stable/changes.html#pre-1-2-5-archives-spoofing-vulnerability-cve-2023-36811

Regards,
Salvatore