We believe that the bug you reported is fixed in the latest version of
hdf5, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1143000@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Gilles Filippini <pini@debian.org> (supplier of updated hdf5 package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 14 Aug 2026 12:07:49 +0200
Source: hdf5
Architecture: source
Version: 2.2.0+repack-1
Distribution: unstable
Urgency: medium
Maintainer: Gilles Filippini <pini@debian.org>
Changed-By: Gilles Filippini <pini@debian.org>
Closes: 1100440 1103531 1103532 1103533 1103534 1103536 1103537 1103538 1103539 1103540 1103541 1103542 1108155 1108156 1108409 1108480 1108481 1108482 1108884 1108885 1108886 1142999 1143000 1143001 1143002 1143003
Changes:
hdf5 (2.2.0+repack-1) unstable; urgency=medium
.
* New upstream release
* Fixed CVEs:
- CVE-2026-17572 (closes: #1142999)
- CVE-2026-17573 (closes: #1143000)
- CVE-2026-17574 (closes: #1143001)
* Refresh patches
* Drop patches pr-6218.patch and pr-6354.patch (fixed upstream)
* Drop patch java_use-system-jars.patch and set jar files paths using
cmake variables
* Refresh d/flavor-layout and d/libhdf5-flavor-dev.install.in regarding
new cmake files installation path
* Tweak d/libhdf5-flavor-dev.install.in to avoid installing the new
/usr/include/mod folder which is redundant
* Update syombols files
.
* Acknowledge previously fixed CVE in HDF5 2.1.0:
- CVE-2025-2153 (closes: #1100440)
- CVE-2025-2308 (closes: #1103542)
- CVE-2025-2309 (closes: #1103541)
- CVE-2025-2310 (closes: #1103540)
- CVE-2025-2912 (closes: #1103539)
- CVE-2025-2913 (closes: #1103538)
- CVE-2025-2914 (closes: #1103537)
- CVE-2025-2915 (closes: #1103536)
- CVE-2025-2923 (closes: #1103534)
- CVE-2025-2924 (closes: #1103533)
- CVE-2025-2925 (closes: #1103532)
- CVE-2025-2926 (closes: #1103531)
- CVE-2025-6269 (closes: #1108155)
- CVE-2025-6270 (closes: #1108156)
- CVE-2025-6750 (closes: #1108409)
- CVE-2025-6816 (closes: #1108482)
- CVE-2025-6817 (closes: #1108481)
- CVE-2025-6818 (closes: #1108480)
- CVE-2025-7067 (closes: #1108886)
- CVE-2025-7068 (closes: #1108885)
- CVE-2025-7069 (closes: #1108884)
- CVE-2026-26197 (closes: #1143002)
- CVE-2026-26199 (closes: #1143003)
Checksums-Sha1:
8809db375ff1993d9e8ab8d7a3faef5b17d33f7d 3902 hdf5_2.2.0+repack-1.dsc
621f84e6d7f85cbd7bfff39a5b27a152e078da67 41803521 hdf5_2.2.0+repack.orig.tar.gz
29fef4da86a9b0d13f635e9dede111e25b802809 166020 hdf5_2.2.0+repack-1.debian.tar.xz
997796637e48467bdeb0f6f352354d61ec7b557e 34065 hdf5_2.2.0+repack-1_amd64.buildinfo
Checksums-Sha256:
f9502176f8976085c684d9d4cdb6b8cb7c9b5681d8d192305769678e53510c5d 3902 hdf5_2.2.0+repack-1.dsc
69fb755fa24f9f41573c459f212f64103ba17b89c0ce8fb17cafa920e01d0013 41803521 hdf5_2.2.0+repack.orig.tar.gz
211f2d172341fefcc258a5358302fd407cba96ba93a0c74d668ea06fb580c0e5 166020 hdf5_2.2.0+repack-1.debian.tar.xz
48d29e5de8440b93443fb9242d1c1ea2deae2976061dc91100365630425c6284 34065 hdf5_2.2.0+repack-1_amd64.buildinfo
Files:
82d4d9536bd0d5c7091afec0885a3ea0 3902 science optional hdf5_2.2.0+repack-1.dsc
bd6aebe8ce25457615d6200f102005b9 41803521 science optional hdf5_2.2.0+repack.orig.tar.gz
eddc589d2b7411f8d31cbb6bf70e4b3e 166020 science optional hdf5_2.2.0+repack-1.debian.tar.xz
fb9aa3e0fa059a525835abdfcd795155 34065 science optional hdf5_2.2.0+repack-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQFEBAEBCgAuFiEEoJObzArDE05WtIyR7+hsbH/+z4MFAmp/ANkQHHBpbmlAZGVi
aWFuLm9yZwAKCRDv6Gxsf/7Pg1sMCACXpYdo6WChJfG1eUmNlQEqUSLUXQ+l5i//
Fs3nPfD9uDdQ5vnJU17ia5RncggnGkH9I5bOe+paO+uoJuKuho4OFs5jKWX8ztov
tpNnHDe525z4aCYeuHb+p3NZJTMRQcW+ztywIUmMkepRecv7tOn/Tjh64oD1UtF2
U8nZfuW44XgBIWB8mnERXv9tll08TDgXkWPKvweP74nO9VFqydG9Y/igAkO4UdTx
JTxMldaymwtFt2MVlE356oOu7wr6Q/pCaofAcYtWdIeF6Wos1RRQXpQCQaTyYV6F
t0EHP9fyqC0mopNh+AKhahfKarMQRt0cN/ijhwxYgCb45jCu4Xrb
=WfQd
-----END PGP SIGNATURE-----