#1143148 trixie-pu: package python-aiohttp/3.11.16-1+deb13u2

#1143148#5
Date:
2026-07-31 02:16:48 UTC
From:
To:
[ Reason ]

This update adresses a list of CVEs which should either be fixed via DSA or via
SPU. These are the CVEs fixed:

  * CVE-2025-53643
  * CVE-2026-22815
  * CVE-2026-34513
  * CVE-2026-34514
  * CVE-2026-34516
  * CVE-2026-34517
  * CVE-2026-34518
  * CVE-2026-34519
  * CVE-2026-34520
  * CVE-2026-34525
  * CVE-2026-34993
  * CVE-2026-47265
  * CVE-2026-50269
  * CVE-2026-54274
  * CVE-2026-54275
  * CVE-2026-54277
  * CVE-2026-54279
  * CVE-2026-54280

[ Impact ]

If the update is not applied, users will continue to be vulnerable to the
issues addressed with this update.

[ Tests ]

I have added an autopkgtest to run the upstream tests. Whenever upstream added
tests to their patchsets, I have backported them as well. All tests succeed.

[ Risks ]

The main risk are regressions. I have enabled the upstream tests to catch any
regressions. All tests succeed, though. So the probability of regressions
should be low(ered).

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

[ Changes ]

See debian/changelog in the attached debdiff.

[ Other info ]

I have decided to not address CVE-2026-54273. The backport requires extensive
code changes. Without them, only a questionable (IMHO) partial fix is possible.
Thus, this issue is not part of the list of addressed CVEs.
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEvu1N7VVEpMA+KD3HS80FZ8KW0F0FAmpsBY8ACgkQS80FZ8KW
0F3wbg//Yqbx5e3Tq6XeYKMlpDkc0tj27t6iINNVp8nyzWH7EmiKZeBHOR4PjehC
IGhYj2OXnFJMb38Ygb5hwdNHZfhQluzvEnG7XWEXhA1mOONLM7qNlwjQYh5bYtqn
WyYFozps41/DhNEdh+SVN+ELm3Xqxe0LBXwoU67sXo5rsvmxhs7hv8/zTX5Ue4uv
THpqg1iaqZgpc/WKpruDwlo7SUjE2+CeK3fj0Q2ckN871oMRR7hk8a0+6XcRVuTf
5s0pOoYw44oDIX1t7qSHRMNOt62Vq6Y2I4gxOfooq0gDhxihKv+bsOt4T/4OS6iI
3ebDJ8XRQtcKYCC3nIOT0LCT8eXH6xAMsuKYF4REOOmLVEq4lEcaBlNOT+Gl3s4x
yhXvO4YaQzk4I1gu8aZ9xfnWR5UMoxpxAOoXlTGpFvUdO2z7+UUDodDF+ekMejPx
b1flfOaS7zdzSgNftYUWx4YdqXAsCNexh9fBlKm28TQUF1r5vx5KIti/VI21oDlp
gTH+fg4c2W7HEaa2ExnfGRHvLKz3Db7CMlboDb8Q7YNE6LLAVuONVLiFlAca8dMw
Df9ZWmipcAVQxoPrSJMmRVOiE7cwXWtkNIG2gt3vrdI9GdJDiTAxatsd+Kj5K880
5PzDnveUQpeNaMb5wCDDcbK6Z2z69aXTgEGsFrNqwL80Gmpjja0=
=j6ph
-----END PGP SIGNATURE-----

#1143148#12
Date:
2026-08-02 17:06:31 UTC
From:
To:
They are marked already no-dsa, thus the trixie-pu route is good. Can
you please add as well the fix for CVE-2026-59881 in the same batch,
this is as well no-dsa (should first be fixed as well in unstable).

Regards,
Salvatore