- Package:
- src:dhcpcd
- Source:
- src:dhcpcd
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-07-15 16:57:01 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerabilities were published for dhcpcd. CVE-2026-56113[0]: | dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use- | after-free vulnerability that allows unauthenticated same-link | attackers to crash the daemon by sending a crafted DHCPv6 RENEW | reply with RFC6603 OPTION_PD_EXCLUDE and both preferred and valid | lifetimes set to zero. Attackers acting as or impersonating a DHCPv6 | server can trigger dhcp6_deprecatedele() to free a delegated child | address while an outer TAILQ_FOREACH_SAFE iterator in | dhcp6_deprecateaddrs() still holds the freed pointer, causing a use- | after-free when TAILQ_REMOVE is reached. CVE-2026-56114[1]: | dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte | stack out-of-bounds write vulnerability in dhcp6_makemessage() in | src/dhcp6.c that allows unauthenticated same-link attackers to write | beyond a fixed local buffer by serializing an oversized RFC6603 | OPTION_PD_EXCLUDE option body. Attackers can send a crafted DHCPv6 | ADVERTISE message containing an IA_PD IAPREFIX /0 with a valid | OPTION_PD_EXCLUDE using an exclude prefix length of /121 through | /128 to trigger the out-of-bounds write and potentially corrupt | adjacent stack memory. CVE-2026-56115[2]: | Bootimus through 0.1.70 contains a broken access control | vulnerability that allows authenticated low-privileged users to | perform administrative actions by exploiting missing role | enforcement in the JWTMiddleware function in internal/auth/auth.go, | which validates JWT tokens and account status but fails to inspect | the is_admin flag. Attackers can send requests to any endpoint under | the /api/users path to create new administrator accounts or reset | administrator passwords, thereby gaining full control of the server | and the ability to modify boot menus and installation scripts served | to PXE clients. CVE-2026-56116[3]: | dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory | leak vulnerability in the IPv6 Router Advertisement route | information handling that allows an unauthenticated same-link | attacker to cause denial of service by sending crafted Router | Advertisements. Attackers can repeatedly send Router Advertisements | containing Route Information options with a lifetime of zero, | triggering unfreed allocations in routeinfo_findalloc() that cause | linear memory exhaustion and eventual daemon crash. CVE-2026-56117[4]: | dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use- | after-free vulnerability in the control socket handling within | src/control.c that allows local unprivileged attackers to trigger | memory corruption when privilege separation is disabled. Attackers | can connect to the control socket and send a privileged command such | as -x, causing control_recvdata() to free the client object while | the same READ+HANGUP event subsequently reaches control_hangup() | with the stale pointer, resulting in a use-after-free condition | exploitable in deployments using --disable-privsep or where privsep | initialization has failed with the control socket operating in mode | 0666. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-56113 https://www.cve.org/CVERecord?id=CVE-2026-56113 [1] https://security-tracker.debian.org/tracker/CVE-2026-56114 https://www.cve.org/CVERecord?id=CVE-2026-56114 [2] https://security-tracker.debian.org/tracker/CVE-2026-56115 https://www.cve.org/CVERecord?id=CVE-2026-56115 [3] https://security-tracker.debian.org/tracker/CVE-2026-56116 https://www.cve.org/CVERecord?id=CVE-2026-56116 [4] https://security-tracker.debian.org/tracker/CVE-2026-56117 https://www.cve.org/CVERecord?id=CVE-2026-56117 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Thanks for the heads-up. CVE-2026-56115 doesn't seem to concern dhcpcd, though. Martin-Éric pe 26.6.2026 klo 7.15 Salvatore Bonaccorso (carnil@debian.org) kirjoitti:
Control: retitle -1 dhcpcd: CVE-2026-56113 CVE-2026-56114 CVE-2026-56116 CVE-2026-56117 No, that seems to have been an issue while we triaged the issues. I have updated as well the security-tracker metadata, thanks! Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
dhcpcd, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1140767@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Martin-Éric Racine <martin-eric.racine@iki.fi> (supplier of updated dhcpcd package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 26 Jun 2026 15:24:47 +0300
Source: dhcpcd
Architecture: source
Version: 1:10.3.2-4
Distribution: unstable
Urgency: medium
Maintainer: Martin-Éric Racine <martin-eric.racine@iki.fi>
Changed-By: Martin-Éric Racine <martin-eric.racine@iki.fi>
Closes: 1140767
Changes:
dhcpcd (1:10.3.2-4) unstable; urgency=medium
.
* [patches] (Closes: #1140767)
+ Cherry-pick upstream fix for CVE-2026-56113 (commit 5733d3c).
+ Cherry-pick upstream fix for CVE-2026-56114 (commit 2f00c7b).
+ Cherry-pick upstream fix for CVE-2026-56116 (commit 708b4a5).
+ Cherry-pick upstream fix for CVE-2026-56117 (commit 78ea09e).
Checksums-Sha1:
1024acf28631d9b4c90d50a15550ca0410a6cb02 2470 dhcpcd_10.3.2-4.dsc
b07174c442fde138efcfe8ebfeb2484f145c5f49 23096 dhcpcd_10.3.2-4.debian.tar.xz
bdd10747043e2bd6e29024db5a90391a737f7063 6156 dhcpcd_10.3.2-4_source.buildinfo
Checksums-Sha256:
a8363deac6d6affffdde57ef2511377183214e6bee8d03a60bcb403e67e7e814 2470 dhcpcd_10.3.2-4.dsc
558d006dbc49053d9a1a07a18dab7cd6658a5a5ca1f3ea818f971549c6bd4921 23096 dhcpcd_10.3.2-4.debian.tar.xz
4f0e786df2bc4710ef69908a37966592aab063f30a4394ff684c2642c16552be 6156 dhcpcd_10.3.2-4_source.buildinfo
Files:
93cf00f8c899f3be6448e5cb2aea6e3d 2470 net optional dhcpcd_10.3.2-4.dsc
b4e145e5f26d7bd6e6c8a32e611a425c 23096 net optional dhcpcd_10.3.2-4.debian.tar.xz
deee17a4f1dc82db2b116d7b5b6885c8 6156 net optional dhcpcd_10.3.2-4_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEyJACx3qL7GpObXOQrh+Cd8S017YFAmo+gtUACgkQrh+Cd8S0
17bzDhAArX3EVJ2C7KhpVFhdkrNlcvg/ZXEZix9wFmiyHMHxB+EqPRJ6YgjAjX3J
3ERUF6rjBPYwLOQMQTaKY+mNy3JWFFX0XaanrjCd+AEaZCiPwsGDemX8he9k7fPM
pfoxkkvuiUPAfbw1tmyVwI8gKBYsyOCq+8jkdMDwVSnst85qx7Q+K7V5DAnnKR/h
NAi1z2ovvdN9X/5Rp0/qCtIcWL3p3EG5rvY8A7lnX71h16uHs8LoH+SgyxHyow/F
IBZVdTtFEGjea4yYoF/U7LlYLnhF+ytvf4QQJZUX7E2d+VNS7A/3JOE8o+zRdhWI
T6tWU9TPC/nJ60W7+U9ImluvlSj9JawrHNWMLcU1sFW+6FrGxK0wuybC/w2Inhou
5T+u+08Wrk3V0GuCQzgcmov6T6hLVozhoc8yhAVEDzB4JxpbU6ebwVrW+l1iSf24
pEr492+l//KY2YNTTV0rcTdl7lXGMzPeKsPzG85LUnCwGRsiJ2RHDH/E4RS++/Ts
WfMNccAsF4knWjyrlbMOspBobRqunEfQOJ9+Weqty1aEwqB8STP7jvfooev7F87T
1oRvfg6+eeWB/nK3lLrwcRA90F5CnX91sh8bv+JvfAKe4SzqiFGt17VNZ50D7/QM
Ud4EZrf4qF6OhT4e/2Lx4lyRORvrDIGIeVtHuDVGGEo8JTmcaJc=
=Fcb4
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
dhcpcd5, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1140767@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Martin-Éric Racine <martin-eric.racine@iki.fi> (supplier of updated dhcpcd5 package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 28 Jun 2026 12:02:44 +0300
Source: dhcpcd5
Architecture: source
Version: 9.4.1-24~deb12u5
Distribution: bookworm
Urgency: medium
Maintainer: Martin-Éric Racine <martin-eric.racine@iki.fi>
Changed-By: Martin-Éric Racine <martin-eric.racine@iki.fi>
Closes: 1140767
Changes:
dhcpcd5 (9.4.1-24~deb12u5) bookworm; urgency=medium
.
* [control]
= Migrate Build-Depends from pkg-config to pkgconf.
* [salsa-ci.yml]
+ Implement basic CI support using the stock Debian pipeline include.
* [patches] (Closes: #1140767)
+ Cherry-pick upstream fix for CVE-2025-70102 (commit 117742d).
+ Cherry-pick upstream fix for CVE-2026-56114 (commit 2f00c7b).
= Refresh all patches.
Checksums-Sha1:
03c79097625f6895ccbce85d8e2df45f91fc1eb2 2100 dhcpcd5_9.4.1-24~deb12u5.dsc
943d0aa042f968801446f2a5d48a69faf55add13 25804 dhcpcd5_9.4.1-24~deb12u5.debian.tar.xz
de44603605ff5678ff477677aa8293eaafce0073 5938 dhcpcd5_9.4.1-24~deb12u5_source.buildinfo
Checksums-Sha256:
b82238f0fc10154852c20fcad189b1b06adad450fea9e002b5d27d7fb42734c9 2100 dhcpcd5_9.4.1-24~deb12u5.dsc
390fd3a566088c89a5f34f349284630c09abb015d7294d4af9b7a7c2e3e04ff7 25804 dhcpcd5_9.4.1-24~deb12u5.debian.tar.xz
21d612ee0e76ab59af4b03b30817c12fc18563ae2e490d6e00cc3f79ddd9f6f4 5938 dhcpcd5_9.4.1-24~deb12u5_source.buildinfo
Files:
658e757b015327ec1b65d12ca2c513f1 2100 net optional dhcpcd5_9.4.1-24~deb12u5.dsc
eb761259f8bbe88bfc0291632c985163 25804 net optional dhcpcd5_9.4.1-24~deb12u5.debian.tar.xz
fea563e94f59f8f3979d333c68e49b51 5938 net optional dhcpcd5_9.4.1-24~deb12u5_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEyJACx3qL7GpObXOQrh+Cd8S017YFAmpA9xsACgkQrh+Cd8S0
17b8Cw/7BctQY8EPfBbeH1E9BK4vSDOE7sskAvhT1Mnqh2SIkgD6lFB96X44pOyl
n2X7WntQAISBL489NmOhZ2ml7J0lgCLdXib9LoEnFthc464b0bThuV0kU9w/hVOC
yvCDpAItxxeYkV5Y4v5+L6T3oJuQVaG/oyPTqyafjh5le4jcs/JkWBmKFRSeOBXN
71CqsXiBCJmY6xi3JqEecU0GYy8ch75pPrgmu/RNd4Sy7q/Swqv6oDszKguj5fJZ
/7+md14GP3/6QtYKpY5vX+RvO2mcNUMxuGUwwlwN3jTQgO3GOE47xEwlTB9oms0S
l0nx7lbUA5ZIu9U7961gzRXSnJ8JikeKiWiks8hnwfd5czopb/AzA4NDZWjs4oW4
rqe/+N1B9Hg14fnsDJHXxHo+mVfftFIwX0JMRpVuv1zLgL8rjl6LCyio++9xAAxK
6CwZgEuMt9KCOzvaOumMXd1gricGqIlslFB3Fp5UYxJDpWtqn46b7kP5nwdxxTsz
9vntnib5R7NCQq46nXr+rTHMs6LnsTmwcuQ6njTzRxU8zLWduXIvqPS1QUKCwA5N
g2T9X6NaiP32h0OcDfwNuXkOFaKeEH9iaSgdibsGp/T6gd1jUjC1fswjjhI4XEbw
Cff4qXPJNsU7eF86yMLYIWd9sv5i7x4cIzLjzumHSeyCxnufPrc=
=ILpQ
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
dhcpcd, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1140767@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Martin-Éric Racine <martin-eric.racine@iki.fi> (supplier of updated dhcpcd package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 26 Jun 2026 18:23:21 +0300
Source: dhcpcd
Architecture: source
Version: 1:10.1.0-11+deb13u3
Distribution: trixie
Urgency: medium
Maintainer: Martin-Éric Racine <martin-eric.racine@iki.fi>
Changed-By: Martin-Éric Racine <martin-eric.racine@iki.fi>
Closes: 1140767
Changes:
dhcpcd (1:10.1.0-11+deb13u3) trixie; urgency=medium
.
* [patches] (Closes: #1140767)
+ Cherry-pick upstream fix for CVE-2025-70102 (commit 117742d).
+ Cherry-pick upstream fix for CVE-2026-56113 (commit 5733d3c).
+ Cherry-pick upstream fix for CVE-2026-56114 (commit 2f00c7b).
+ Cherry-pick upstream fix for CVE-2026-56116 (commit 708b4a5).
+ Cherry-pick upstream fix for CVE-2026-56117 (commit 78ea09e).
Checksums-Sha1:
a6e1acc7b0d62c756fb1cc234290f112670b5889 2164 dhcpcd_10.1.0-11+deb13u3.dsc
aa35ba650091de4f14e9e4b7aec7f0c1f19c181d 24840 dhcpcd_10.1.0-11+deb13u3.debian.tar.xz
18bad8c621441d39576cc523884066015fe8a594 6192 dhcpcd_10.1.0-11+deb13u3_source.buildinfo
Checksums-Sha256:
9de235c22001c41fae0c8185c4cf92d1b789009f8f6fdac7d81b9de57bfb30e2 2164 dhcpcd_10.1.0-11+deb13u3.dsc
f4867560736a382a1ee9cd658aa2469d23804ec6423903b3e2e34de5792d5f5d 24840 dhcpcd_10.1.0-11+deb13u3.debian.tar.xz
104bc9214fb11e33cdc1c66536815caef3b1b2f3655f075fd6ebcba44b771a43 6192 dhcpcd_10.1.0-11+deb13u3_source.buildinfo
Files:
7515d6c1a3646256668e1148f1b2ed59 2164 net optional dhcpcd_10.1.0-11+deb13u3.dsc
ff8f1d0525a27580b74020a42666385b 24840 net optional dhcpcd_10.1.0-11+deb13u3.debian.tar.xz
e2fada9295592e137df52915fa67b919 6192 net optional dhcpcd_10.1.0-11+deb13u3_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEyJACx3qL7GpObXOQrh+Cd8S017YFAmo+oGcACgkQrh+Cd8S0
17bx7w/9FXXnv2B7ZZe7Aa1rn8ysMLKzEwhBeqThgFMexV3MnXoB/XGjzTadpgQ1
Fzh3d3CZHRQwAWGHb0j+qoCwimcompyvuM42m1iLqEANujRBXrf8aH9qxjf5yoC9
q+NiqF1PPt4H4Eak+qX5UsMlqCa5hBUuVMiRgpz1Q7vWcCNNpPA1g+vQcBnpBoAW
n8iiG5wQBof76ZeHDJxhD70Vjs4yXa+EGr6JhpjkP/DlU34ihQUDNbfJg6t9WodJ
UiO6zFLU+epfTvfl9xOyO/nBpcjOYrx9AvKq/WuRI1lfGnyYiPpQPAd4wVxpT48I
6fe3ib9BobYsGOieV5WmeTNEMdKkXvlhDQieQxDFB6ziKEwQsMToX2rcYsTFnvir
ipuisp7x+FYYwUBDH5MITt17lIFszZU9dbb3txQssivyf0cLGAW8/ptPDtoZP5f/
p4uSkJ5jbk4IJqWsEm31QajrkWohAXedmaVu2/oqJRwRaOh4nvC29GHPEwZxj6F4
MNXuJegi2h8wBsTOoLtRfdR01iOhsb6AIuvbt5AssvZ69fxnjn9IwkwpO7Wmrk2z
bSLO1eAAjiQAl+V+YtsS9Zxk6gxIp83M9FNheR/AB0UV7aYuBsZiYmRKXj/ofweI
UUgXiduPuBu8S3JhngpTxzLEWN9UJDJdXTnYMIM+rb6ClFW0ahs=
=1q+l
-----END PGP SIGNATURE-----
Greetings, My dashboard shows CVE-2025-70102 as still being unfixed for oldoldstable. Since Bullseye is LTS at this point, this goes via the Security team. The enclosed patch includes the fix for the CVE and some basic packaging touchups to silence Lintian and CI. You're welcome to use it. Martin-Éric
Hi, Thanks for preparing the update. As you say bullseye is a LTS maintained suite, so this actually has to go via the LTS team, not the security team. I'm CC'ing the correct list, but that said, I see it is marked postponed/no-dsa, so this can be usually included in a future update covering more CVEs or now, but please coordinate further with the LTS team. LTS team, how do you want Martin-Eric to proceed? Regards, Salvatore
Hi, There's no particular urgency for dhcpcd5 at the moment, but if Martin-Éric wants, he can push an update following: https://lts-team.pages.debian.net/wiki/Development.html We can help with the administrative tasks. Some notes :) - According to https://security-tracker.debian.org/tracker/source-package/dhcpcd5 please also fix CVE-2026-56114, to avoid a single-CVE DLA with low-severity. - Please explain why we need a new dependency to sysvinit-utils during a stable release. - Please attempt to de-noise the debdiff, by avoiding patch refreshes and changes related to upstream tarballs, while we'll remain on the same v7.1.0 anyway. - Please name the patches according to the CVE rather than the Git commit ID, so it's easier to understand which is fixing which. - No need for a 7.1.0-2+deb11u2 if 7.1.0-2+deb11u1 never was released. - Target dist should be bullseye-security. - Please explain how you tested the update. Cheers! Sylvain Beucler Debian LTS Team
Hey Sylvain, ti 14.7.2026 klo 12.14 Sylvain Beucler (beuc@beuc.net) kirjoitti: I agree. These are minor fixes, and Bullseye is one month away from moving to archive.d.o anyhow. Noted. That one doesn't show on my dashboard for dhcpcd5. It's easily added, since it's a one character fix. Lintian complains loudly about an outdated Depends. Adding that alternative to lsb-base quiets it. dpkg-source complains without it. Salsa CI fails without the added PGP key and updated watch recipe. Noted. Shrugs. I could consolidate the changes since I'm still in Salsa Git at this point. Noted. See Bug#1141987. I don't have any Bullseye host left, but the fixes are one-character changes that have been verified to boot on Bookworm and Trixie. Martin-Éric
Hey Sylvain, ti 14.7.2026 klo 12.51 Martin-Éric Racine (martin-eric.racine@iki.fi) kirjoitti: Is the attached debdiff closer to what you had in mind? Martin-Éric
Hi Martin-Éric, Yes this fixes most of my remarks :) that shouldn't fail, do fail -_- You can run a bullseye VM and do some manual tests. Additionally, Salsa CI only ran trivial tests, due to lack of 'isolation-machine' support: https://salsa.debian.org/debian/dhcpcd/-/pipelines/1129013 https://salsa.debian.org/debian/dhcpcd/-/jobs/9954999 We have some docs for testing locally with autopkgtest: https://lts-team.pages.debian.net/wiki/TestSuites/autopkgtest.html#full-vm-environment-isolation-machine debusine.debian.net should also be able to run the 'isolation-machine' autopkgtests. It has specific rules for dhcpcd, imported from ci.debian.net, otherwise you can force it to use VMs: https://wiki.debian.org/DebusineDebianNet#autopkgtest_backend_selection Cheers! Sylvain Beucler Debian LTS Team
Hello Sylvain, ti 14.7.2026 klo 17.00 Sylvain Beucler (beuc@beuc.net) kirjoitti: Please note that dhcpcd5 hadn't seen any update in ages. Version 7.1.0-2 was uploaded many Debian releases before Bullseye and left unattended until I took over maintenance just before Bookworm, renamed it dhcpcd and packaged the latest upstream. Given this, two of the autopkgtest targets didn't work. One was easily fixed, while the other fails because it expects features that haven't been offered by the dependency for a while, so I marked it FLAKY. We only need isolation-machine to perform consecutive installations of mutually-exclusive NTP daemons and test that our exit hooks correctly pass DHCP-provided NTP servers to the daemon. DHCP is not tested per-se. However, _all_ of our NTP hook tests would fail if we couldn't fetch an IP via DHCP. Here, only one NTP test fails for the above reason. Which only works until Bookworm. Qemu stalls at the login prompt in Trixie and later (bug already filed). Anyhow, Bullseye still works, which is how I was able to test and fix those autopkgtest targets as above. chrony-ntp-servers-from-dhcp FLAKY non-zero exit status 2 timesyncd-ntp-servers-from-dhcp PASS ntpd-ntp-servers-from-dhcp PASS openntpd-ntp-servers-from-dhcp PASS sbin-dhcpcd-exists-without-usrmerge PASS sbin-dhcpcd-exists-with-usrmerge PASS qemu-system-x86_64: terminating on signal 15 from pid 250471 (/usr/bin/python3) We're now up to the attached debdiff. Are we good with this one? Martin-Éric
Hello Martin-Éric,
That sounds good.
(Indeed there appears to be tons of issues around autopkgtest-qemu, I
can't run my October bullseye VM anymore ("not a bootable disk"), I
can't rebuild it (grub dpkg issues), and there are currently issues with
incus-vm in debusine.)
I believe you are not a DD, so I'll need to sponsor your upload.
Do you have a text for the DLA announcement?
Cheers!
Sylvain Beucler
Debian LTS Team
Hello Sylvain, ke 15.7.2026 klo 14.58 Sylvain Beucler (beuc@beuc.net) kirjoitti: I attached the test log for reference. Thanks. Tagged and pushed into dhcpcd Salsa Git repository. Gosh. Not really. I mean, this started as a best last effort to backport 2 CVE fixes onto this old derelict release of the package, just because they showed up on my maintainer's dashboard, and right before Bullseye gets mothballed, then evolved into fixing a few easy packaging and CI issues while I'm at it. Thanks for guiding me through and sponsoring my first security upload. Cheers! Martin-Éric
Hello Martin-Éric, Published! https://lists.debian.org/debian-lts-announce/2026/07/msg00028.html Thanks for your contribution to LTS :) Cheers! Sylvain Beucler Debian LTS Team