Your message dated Fri, 07 Aug 2026 15:06:33 +0000
with message-id <[email protected]>
and subject line Bug#1137309: fixed in apr-util 1.6.4-1
has caused the Debian Bug report #1137309,
regarding apr-util: Please drop dependencies on virtual packages from 
mysql-defaults
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1137309: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1137309
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: apr-util
Severity: normal
Control: affects -1 + src:mysql-defaults

Dear Maintainer,

Following a recent discussion on debian-devel@[1], there is a plan to dismantle
the default-mysql-* virtual package construct provided by the mysql-defaults
source package. With the recent releases of MySQL 9.7 and MariaDB 12.3, there is
now enough divergence between the two codebases to warrant dismantling this
metapackage in the Forky (Debian 14) cycle.

This is filed with severity 'normal' as this change is not urgent.

We are asking maintainers to drop any dependencies on these virtual packages:
* default-libmysqlclient-dev
* default-mysql-client
* default-mysql-client-core
* default-mysql-server
* default-mysql-server-core

However, how this is handled in is in your discretion based on the details of
how the package is maintained and tested in Debian. There are mainly three
options:

- Direct switch: The most straightforward approach is to switch defaut-mysql-*
  directly to the MariaDB equivalent (libmariadb-dev, libmariadb-dev-compat,
  mariadb-client, mariadb-server, etc). For example 'Recommends: 
mariadb-server'.

- Dual compatibility: If the package actively supports both engines and you wish
  to keep an alternative runtime path open for users drawing from third-party
  repositories, you can declare an OR dependency. For example
  'Depends: mariadb-client | mysql-client'.

- Specific constraint: If your package does not work with MariaDB, feel free to
  tailor the package relationships to match that constraint. This is however
  very unlikely as all Debian releases in past decade have only shipped with
  MariaDB, and the open source ecosystem has largely shifted to lean towards
  MariaDB.

This change is targeted specifically for the Forky cycle and does not affect any
existing stable releases.

Thank you for your time and your work maintaining apr-util in Debian!

[1] https://lists.debian.org/debian-devel/2026/05/msg00161.html

--- End Message ---
--- Begin Message ---
Source: apr-util
Source-Version: 1.6.4-1
Done: Stefan Fritsch <[email protected]>

We believe that the bug you reported is fixed in the latest version of
apr-util, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Stefan Fritsch <[email protected]> (supplier of updated apr-util package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 07 Aug 2026 16:47:11 +0200
Source: apr-util
Architecture: source
Version: 1.6.4-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Apache Maintainers <[email protected]>
Changed-By: Stefan Fritsch <[email protected]>
Closes: 1137309 1143837
Changes:
 apr-util (1.6.4-1) unstable; urgency=medium
 .
   * New upstream release. Closes: #1143837
     - CVE-2025-49506: apr_password_validate() vulnerable to timing attack
     - CVE-2026-32327: XML stack recursion crash
     - CVE-2026-34191: SQL Injection in apr_dbd_oracle
     - CVE-2026-34501: Heap buffer overflow in APR redis client
     - CVE-2026-34502: Heap buffer overflow in APR memcached client
   * Switch Build-Depends to libmariadb-dev-compat. Closes: #1137309
Checksums-Sha1:
 05cf8eed3049bbc4064b19469f89b500fde25a33 2785 apr-util_1.6.4-1.dsc
 913c44f9fdfb4ce7c270a71a52402d33adcd99b6 441511 apr-util_1.6.4.orig.tar.bz2
 0f6ce32a62a43287583020980f4ee92863a6ddd9 898 apr-util_1.6.4.orig.tar.bz2.asc
 628aff0f2656a2445f534e90e3bc4c83efd96be8 341248 apr-util_1.6.4-1.debian.tar.xz
 7cc98e36a29cf49fc43ebf63d87cf883bdf590fc 8868 apr-util_1.6.4-1_source.buildinfo
Checksums-Sha256:
 1949bd1da9929e3fa89e7dc3228a9ff229ef4e051859e08c4276088a27a5ebe0 2785 
apr-util_1.6.4-1.dsc
 3e2ae08f40efa0c3701e54a954cefa08242de22a69f91a8ae44fc1e624ba309b 441511 
apr-util_1.6.4.orig.tar.bz2
 17eb58050f65c3889195f3077e36521a9af3e36b100efef690f50916c3116bf8 898 
apr-util_1.6.4.orig.tar.bz2.asc
 c7b5d7f28207a71d2da66097c0cec9f5c16d8df5a4e2749668de9bd9387b2c52 341248 
apr-util_1.6.4-1.debian.tar.xz
 ae3cad3210b39b1d6decc8ba3dcbeb87cebdfeb8b007aa4302b705331f615a78 8868 
apr-util_1.6.4-1_source.buildinfo
Files:
 6ed9c453a7b2fac39ceaf4b52f75e18c 2785 libs optional apr-util_1.6.4-1.dsc
 8c933056e21005f69225ec6ffd0a16d3 441511 libs optional 
apr-util_1.6.4.orig.tar.bz2
 97e710b9cfafb504e05535cd333ac2b6 898 libs optional 
apr-util_1.6.4.orig.tar.bz2.asc
 77fe06bcd2cc04a3e31f6a2865a9b304 341248 libs optional 
apr-util_1.6.4-1.debian.tar.xz
 f0636d01caa704fced3bce64f3549a48 8868 libs optional 
apr-util_1.6.4-1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEOpiNza8JqByyYYsxxodfNUHO/eAFAmp18PAACgkQxodfNUHO
/eBhtw/+MlsN3Ims0oKb/8dh+6wpC2OVgsHVfZ+3Fh/HIyhBWPtXKjTKVs4qsgpH
/oaM2YoFmNg9u18ZuK3tPbso9ZVyBLod/hjhdBf2bY9v1rSa6FmF1rugKMuGFPid
JqBgHkUqV2BbgTsuUNsgzzDq1jA0n+WMeD6ZNbuYz1IavoaU1p8GkoTAECGdayVf
Qvvt5aP1jJK7uortJY8+qQ+KghcoNCnNa6BHewmF9U9j1GnBcn5bMuhIc1fh1x0D
jKoKiu+Pba7AlwwCy7pKM+YGPrFgkUrL1LsWt7VPqB2HhA7LdUAng0+qfOk+4lWJ
qdgcBPh8EZ0RZZWNGJMjsr7W5GMW4iNHnNmoNqw2zO1E9610R9dfs/kENqkv5yg9
Qt0lv7zGdD29e6epY87pUN/UQxHOlOUsMUuobMxqJ3qhmtE5NKidr7i6fXAR2qUc
lh+AT7EqhUCqu7Z1ztSdDaChfK7EDNTnh+vGRApjo4Mgy02dTRjv++RRsNfqvyYN
wL9ceJmTCxH4e5PaBGtTSlC6lz0B6+Cpzzz19E4N0LZ2zMEEuyvhIJYe2UMIgE7N
rqZbKzkVDrAAe4/EW1Y6pE6HAkl8OCC4DzU5Bum2QaKb8+ozsTYT6rTl00AL9ftG
L6wV3FVm6ZVavnT5kfdFFrox+iXsBZnONqA2KluS3u+SL+HqZXA=
=tihJ
-----END PGP SIGNATURE-----

Attachment: pgpfTjKUwCIuf.pgp
Description: PGP signature


--- End Message ---

Reply via email to