[ Reason ]
This update adresses a list of CVEs which should either be fixed via DSA or via
SPU. These are the CVEs fixed:
* CVE-2025-53643
* CVE-2026-22815
* CVE-2026-34513
* CVE-2026-34514
* CVE-2026-34516
* CVE-2026-34517
* CVE-2026-34518
* CVE-2026-34519
* CVE-2026-34520
* CVE-2026-34525
* CVE-2026-34993
* CVE-2026-47265
* CVE-2026-50269
* CVE-2026-54274
* CVE-2026-54275
* CVE-2026-54277
* CVE-2026-54279
* CVE-2026-54280
[ Impact ]
If the update is not applied, users will continue to be vulnerable to the
issues addressed with this update.
[ Tests ]
I have added an autopkgtest to run the upstream tests. Whenever upstream added
tests to their patchsets, I have backported them as well. All tests succeed.
[ Risks ]
The main risk are regressions. I have enabled the upstream tests to catch any
regressions. All tests succeed, though. So the probability of regressions
should be low(ered).
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in (old)stable
[x] the issue is verified as fixed in unstable
[ Changes ]
See debian/changelog in the attached debdiff.
[ Other info ]
I have decided to not address CVE-2026-54273. The backport requires extensive
code changes. Without them, only a questionable (IMHO) partial fix is possible.
Thus, this issue is not part of the list of addressed CVEs.
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEvu1N7VVEpMA+KD3HS80FZ8KW0F0FAmpsBY8ACgkQS80FZ8KW
0F3wbg//Yqbx5e3Tq6XeYKMlpDkc0tj27t6iINNVp8nyzWH7EmiKZeBHOR4PjehC
IGhYj2OXnFJMb38Ygb5hwdNHZfhQluzvEnG7XWEXhA1mOONLM7qNlwjQYh5bYtqn
WyYFozps41/DhNEdh+SVN+ELm3Xqxe0LBXwoU67sXo5rsvmxhs7hv8/zTX5Ue4uv
THpqg1iaqZgpc/WKpruDwlo7SUjE2+CeK3fj0Q2ckN871oMRR7hk8a0+6XcRVuTf
5s0pOoYw44oDIX1t7qSHRMNOt62Vq6Y2I4gxOfooq0gDhxihKv+bsOt4T/4OS6iI
3ebDJ8XRQtcKYCC3nIOT0LCT8eXH6xAMsuKYF4REOOmLVEq4lEcaBlNOT+Gl3s4x
yhXvO4YaQzk4I1gu8aZ9xfnWR5UMoxpxAOoXlTGpFvUdO2z7+UUDodDF+ekMejPx
b1flfOaS7zdzSgNftYUWx4YdqXAsCNexh9fBlKm28TQUF1r5vx5KIti/VI21oDlp
gTH+fg4c2W7HEaa2ExnfGRHvLKz3Db7CMlboDb8Q7YNE6LLAVuONVLiFlAca8dMw
Df9ZWmipcAVQxoPrSJMmRVOiE7cwXWtkNIG2gt3vrdI9GdJDiTAxatsd+Kj5K880
5PzDnveUQpeNaMb5wCDDcbK6Z2z69aXTgEGsFrNqwL80Gmpjja0=
=j6ph
-----END PGP SIGNATURE-----