On Tue, Jun 13, 2023 at 03:17:52PM +0200, David Lamparter wrote:
> Fixed upstream in 9f1ba873637fd6ce4a2d366eafcf41402775852b on stable/8.4
> branch.
> 
> Debian fix incoming with bump to 8.4.4 if that's OK?  That wouldn't be a
> targeted security fix, but FRR minor versions are bugfix-only.

These two CVEs are not marked "no-dsa" so far, it would be for Salvatore 
or someone else from the security team to decide what is acceptable if
they want to publish a security advisory for bookworm.

> -equi

cu
Adrian

Reply via email to