#1138224 trixie-pu: package lwip/2.2.1+dfsg1-1

#1138224#5
Date:
2026-05-29 17:06:58 UTC
From:
To:
Hi,

I fixed the CVE-2026-8836 in unstable and testing,
and would like to upload the fix to trixie.

The debdiff is attached.

Please tell me, should I backport this also to bookworm?

#1138224#12
Date:
2026-05-31 11:03:14 UTC
From:
To:
Hi,

Please detail the actual changes in the changelog (preferably the patch
header as well). A bare CVE ID is insufficient.

Thanks,

#1138224#19
Date:
2026-05-31 17:16:09 UTC
From:
To:
Hi,

Thanks for the review. I think I addressed your comments.

I'm attaching the updated debdiff

Regards.

El 31/5/26 a les 13:03, Jonathan Wiltshire ha escrit:

#1138224#26
Date:
2026-07-13 17:35:03 UTC
From:
To:
Hi,

Please go ahead.

Thanks,

#1138224#33
Date:
2026-07-17 09:30:04 UTC
From:
To:
package release.debian.org
tags 1138224 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: lwip
Version: 2.2.1+dfsg1-1+deb13u1

Explanation: fix SNMPv3 authentication buffer overflow [CVE-2026-8836]

#1138224#38
Date:
2026-07-17 09:30:04 UTC
From:
To:
package release.debian.org
tags 1138224 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: lwip
Version: 2.2.1+dfsg1-1+deb13u1

Explanation: fix SNMPv3 authentication buffer overflow [CVE-2026-8836]