[ Reason ]
Fixing CVE-2026-59884, CVE-2026-59885 and, CVE-2026-59886
[ Impact ]
Denial of service, cpu and memory exhaustion
[ Tests ]
Build it in debusine https://debusine.debian.net/debian/developers/work-request/1108490/
[ Risks ]
No issues as I can see, patches are simple, upstream added unittests.
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in (old)stable
[x] the issue is verified as fixed in unstable