- Package:
- debian-security-support
- Source:
- debian-security-support
- Submitter:
- Santiago Ruano Rincón
- Date:
- 2026-07-16 13:51:01 UTC
- Severity:
- normal
- Tags:
As per the input from the security team (thanks a lot!), this is a list of packages whose security support during the LTS period of bookworm is too complex or unfeasible: crypto libraries with a few limited rdeps and not really meaningful long term support: - mbedtls - wolfssl packages for which the security team issued a DSA for trixie-security, but for which some significant vulnerabilities were found to tricky to backport to bookworm: - smb4k (https://bugs.debian.org/1136949) - lxd - opennds completely inactive upstream with open security issues: - mimetex open security issues but no rdeps, so no real use (it was only added for gitlab): - ruby-saml Cheers,
Hello, Bug #1138294 in debian-security-support reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/debian/debian-security-support/-/commit/7552a90904acd5295ed6ec9db15ccfc405a076d0 ------------------------------------------------------------------------ Mark some packages as non supported in bookworm LTS By the input from the security team, these packages are difficult to support for the LTS period of bookworm: - lxd: has open vulnerabilities whose fixes are too complex to be backported. - mbedtls: crytpo library difficult to support in the long term - mimetex: upstream project no longer exists - opennds: open vulnerabilities whose fixes are too complex to be backported. - ruby-saml: was introduced for gitlab, and no reverse dependencies remain in bookworm - smb4k: open vulnerabilities whose fixes are too complex to be backported. - wolfssl: crypto library difficult to support in the long term. Closes: #1138294 Signed-off-by: Santiago Ruano Rincón <santiago@debian.org> ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1138294
Hello, Bug #1138294 in debian-security-support reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/debian/debian-security-support/-/commit/dab6c51e5eeb0489b2160b521566b2c1ebe8f4d4 ------------------------------------------------------------------------ Mark some packages as non supported in bookworm LTS By the input from the security team, these packages are difficult to support for the LTS period of bookworm: - lxd: has open vulnerabilities whose fixes are too complex to be backported. - mbedtls: crytpo library difficult to support in the long term - mimetex: upstream project no longer exists - opennds: open vulnerabilities whose fixes are too complex to be backported. - ruby-saml: was introduced for gitlab, and no reverse dependencies remain in bookworm - smb4k: open vulnerabilities whose fixes are too complex to be backported. - wolfssl: crypto library difficult to support in the long term. Closes: #1138294 Signed-off-by: Santiago Ruano Rincón <santiago@debian.org> (cherry picked from commit 7552a90904acd5295ed6ec9db15ccfc405a076d0) Signed-off-by: Holger Levsen <holger@layer-acht.org> ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1138294
Hello, Bug #1138294 in debian-security-support reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/debian/debian-security-support/-/commit/0f2b054aa35a50da82166a8f91d2eb4083142c64 ------------------------------------------------------------------------ Mark some packages as non supported in bookworm LTS By the input from the security team, these packages are difficult to support for the LTS period of bookworm: - lxd: has open vulnerabilities whose fixes are too complex to be backported. - mbedtls: crytpo library difficult to support in the long term - mimetex: upstream project no longer exists - opennds: open vulnerabilities whose fixes are too complex to be backported. - ruby-saml: was introduced for gitlab, and no reverse dependencies remain in bookworm - smb4k: open vulnerabilities whose fixes are too complex to be backported. - wolfssl: crypto library difficult to support in the long term. Closes: #1138294 Signed-off-by: Santiago Ruano Rincón <santiago@debian.org> (cherry picked from commit 7552a90904acd5295ed6ec9db15ccfc405a076d0) Signed-off-by: Holger Levsen <holger@layer-acht.org> (cherry picked from commit dab6c51e5eeb0489b2160b521566b2c1ebe8f4d4) Signed-off-by: Santiago Ruano Rincón <santiago@debian.org> ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1138294
Hello, Bug #1138294 in debian-security-support reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/debian/debian-security-support/-/commit/0f2b054aa35a50da82166a8f91d2eb4083142c64 ------------------------------------------------------------------------ Mark some packages as non supported in bookworm LTS By the input from the security team, these packages are difficult to support for the LTS period of bookworm: - lxd: has open vulnerabilities whose fixes are too complex to be backported. - mbedtls: crytpo library difficult to support in the long term - mimetex: upstream project no longer exists - opennds: open vulnerabilities whose fixes are too complex to be backported. - ruby-saml: was introduced for gitlab, and no reverse dependencies remain in bookworm - smb4k: open vulnerabilities whose fixes are too complex to be backported. - wolfssl: crypto library difficult to support in the long term. Closes: #1138294 Signed-off-by: Santiago Ruano Rincón <santiago@debian.org> (cherry picked from commit 7552a90904acd5295ed6ec9db15ccfc405a076d0) Signed-off-by: Holger Levsen <holger@layer-acht.org> (cherry picked from commit dab6c51e5eeb0489b2160b521566b2c1ebe8f4d4) Signed-off-by: Santiago Ruano Rincón <santiago@debian.org> ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1138294
We believe that the bug you reported is fixed in the latest version of
debian-security-support, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1138294@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Santiago Ruano Rincón <santiago@debian.org> (supplier of updated debian-security-support package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 30 Jun 2026 14:21:59 -0300
Source: debian-security-support
Architecture: source
Version: 1:12+2026.06.30
Distribution: bookworm
Urgency: medium
Maintainer: Debian Security Team <team@security.debian.org>
Changed-By: Santiago Ruano Rincón <santiago@debian.org>
Closes: 1134367 1135152 1135666 1138294
Changes:
debian-security-support (1:12+2026.06.30) bookworm; urgency=medium
.
* Add myself to Uploaders
* Mark suricata as non-supported in bookworm. Thanks to Andreas Dolp
(Closes: #1134367)
* Set qt6-webengine as limited support. Thanks to Jeremy Bícha.
* Mark webkit2gtk in bookworm with limited support. Thanks to Emilio
Pozuelo. (Closes: #1135152)
* Mark some packages as non supported in bookworm LTS. Thanks to the
Security Team. (Closes: #1138294)
* Mark epiphany-browser with limited support in bookworm. Thanks to Emilio
Pozuelo. (Closes: #1135666)
Checksums-Sha1:
cd54227f779abbcc1466d0b5b1c845d2800f381b 1376 debian-security-support_12+2026.06.30.dsc
6eca80a8702bef1ad2225347b56440575374e84e 35496 debian-security-support_12+2026.06.30.tar.xz
c0b207029c766401a960a35cf7f1a78e759df3a0 6046 debian-security-support_12+2026.06.30_source.buildinfo
Checksums-Sha256:
58106c05728b7430eba9d3e0170897e7f34abfe636e79561012eaab426a9be4c 1376 debian-security-support_12+2026.06.30.dsc
a65952c6c5407e0cdb3556e504505a45af1279262f5cb6536ab88b17b55c2fc9 35496 debian-security-support_12+2026.06.30.tar.xz
fcdb73ca7b1e20cd894efd054b112def89770461797d9ec33d55ef64e1ad63a7 6046 debian-security-support_12+2026.06.30_source.buildinfo
Files:
9d8e19cc58acdf0462cf3514ed5c1ec7 1376 admin optional debian-security-support_12+2026.06.30.dsc
95c32c32d8cb159cc59283c70bd2c475 35496 admin optional debian-security-support_12+2026.06.30.tar.xz
1187f0f5f2a2c26cfcbee90446b56d87 6046 admin optional debian-security-support_12+2026.06.30_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iIoEARYKADIWIQR+lHTq7mkJOyB6t2Un3j1FEEiG7wUCakVeQBQcc2FudGlhZ29A
ZGViaWFuLm9yZwAKCRAn3j1FEEiG755+AP9vHzdW04OZmfJuXKu8E76PqQCvhf3j
zeVN5MxyF8/uBwD/cs6mmGAUlbqo5FQrWNjl6Vnc6WD9C233yJakY1WUzAc=
=yhlz
-----END PGP SIGNATURE-----
Hello everyone, can anyone share what does in mean in practical terms for Bookworm users? Will we be exposed to vulnerabilities? Are there alternative packages suggested? What should we do with this? Speed up the upgrade to Trixie? Thanks
Hi, This means that we won't be able to release security updates for these packages, so they'll stay in their current bookworm version. If new vulnerabilities are discovered, you may be impacted. Indeed you can look for alternatives, or upgrade to trixie if you need to keep using these specific packages. Cheers! Sylvain Beucler Debian LTS Team
Hi,
the update to 1:12+2026.06.30 ob Debian 12 Bookworm has caused some
false positives with backports packages here, already obvious from
just reading the output:
$ check-support-status --type ended --no-heading
* Source:suricata, ended on 2026-04-30 at version 1:6.0.10-1
Details: Upstream security support ended in Aug 2024 and backporting fixes is now unfeasible. See: https://bugs.debian.org/1134367
Affected binary package:
- suricata (installed version: 1:7.0.10-1~bpo12+1)
So check-support-status reports that suricata at version 1:6.0.10-1 is
EoL despite version 1:7.0.10-1~bpo12+1 is installed.
Is that on purpose? Looks like an oversight to me. Or does
check-support-status not look at the installed version of a package at
all?
Regards, Axel