#1133883 trixie-pu: package openvswitch/3.5.0-1 (CVE-2026-34956)

#1133883#5
Date:
2026-04-15 07:30:05 UTC
From:
To:
Hi,

I'd like to update openvswitch to version 3.5.4, which includes
the fix for CVE-2026-34956. It was a way easier for me to package
this version rather than backporting the patch, and also IMO safer.

The security team told me to do p-u rather than security upload.

[ Tests ]
There's included unit tests, including new ones that are actually
testing the bug.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

Note that the changelog in attached debdiff targets trixie-security,
though I'll obviously fix this before rebuild and upload, so please
ignore it.

Cheers,

Thomas Goirand (zigo)

#1133883#12
Date:
2026-04-15 08:49:37 UTC
From:
To:
Hi,

Thanks to adsb comment on IRC, let me give a bit more info.

FYI, between 3.5.0 and 3.5.4, there's 160+ commits, which makes it
indeed, impossible to review.

However, in the OpenVSwitch world, whenever a new upstream release is
cut, in this case, 3.5, a new branch is created, and receives only
bugfix. Upstream release 3.5.4, compared to 3.5.0, is only a bugfix
release of the 3.5, and contains no additional feature.

Also, openvswitch contains an extensive set of unit test that are
running at build time. Also, in my experience in production, running the
latest point release is always preferred, as it contains numerous bugfixes.

All of this makes me very confident that using 3.5.4 for the update in
Trixie is the way to go. Not only it contains bugfixes only, but it also
is well tested.

If the release team decides it's not a good idea to upgrade Trixie to
3.5.4, I'll still feel like it's the wrong choice, but I'll understand
it's too hard to review, and I'll try to do a cherry-pick of the CVE fix
anyways.

Please let me know one direction or another.

Cheers,

Thomas Goirand (zigo)