#1142123 bookworm-pu: package modsecurity/3.0.9-1+deb12u3

Package:
release.debian.org
Source:
release.debian.org
Submitter:
Alberto Gonzalez Iniesta
Date:
2026-07-17 06:47:02 UTC
Severity:
normal
Tags:
#1142123#5
Date:
2026-07-15 15:25:55 UTC
From:
To:
[ Reason ]
Fixes for CVE-2026-52747 and CVE-2026-52761

[ Impact ]
Security rules bypass.

[ Tests ]
Fixed and tested by upstream.

[ Risks ]
Low risk, simple patch.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

[ Changes ]
Preserve line breaks from non-file form-field values.
Fix returned length of "unicode" variable.

#1142123#12
Date:
2026-07-16 19:26:49 UTC
From:
To:
Hi Alberto,

As this proposed update targets 'bookworm'. Debian bookworm is now
handed over to the LTS team, so no point releases are happening
anymore, but updates are released via DLA's. I'm cc'ing the LTS list.

Regards,
Salvatore

#1142123#17
Date:
2026-07-17 06:40:16 UTC
From:
To:
Hello Alberto,
https://lts-team.pages.debian.net/wiki/Development.html

We can help with the administrative tasks.

According to:
https://security-tracker.debian.org/tracker/source-package/modsecurity
this is also an opportunity to fix CVE-2024-1019.

Cheers!
Sylvain Beucler
Debian LTS Team