Hi,
On 14/07/2026 09:00, Salvatore Bonaccorso wrote:
On Tue, Jul 14, 2026 at 08:41:51AM +0300, Martin-Éric Racine wrote:
Greetings,
My dashboard shows CVE-2025-70102 as still being unfixed for
oldoldstable. Since Bullseye is LTS at this point, this goes via the
Security team. The enclosed patch includes the fix for the CVE and
some basic packaging touchups to silence Lintian and CI. You're
welcome to use it.
Thanks for preparing the update. As you say bullseye is a LTS
maintained suite, so this actually has to go via the LTS team, not the
security team.
I'm CC'ing the correct list, but that said, I see it is marked
postponed/no-dsa, so this can be usually included in a future update
covering more CVEs or now, but please coordinate further with the LTS
team.
LTS team, how do you want Martin-Eric to proceed?
Thanks Martin-Éric and Salvatore.
There's no particular urgency for dhcpcd5 at the moment, but if
Martin-Éric wants, he can push an update following:
https://lts-team.pages.debian.net/wiki/Development.html
We can help with the administrative tasks.
Some notes :)
- According to
https://security-tracker.debian.org/tracker/source-package/dhcpcd5
please also fix CVE-2026-56114, to avoid a single-CVE DLA with low-severity.
- Please explain why we need a new dependency to sysvinit-utils during a
stable release.
- Please attempt to de-noise the debdiff, by avoiding patch refreshes
and changes related to upstream tarballs, while we'll remain on the same
v7.1.0 anyway.
- Please name the patches according to the CVE rather than the Git
commit ID, so it's easier to understand which is fixing which.
- No need for a 7.1.0-2+deb11u2 if 7.1.0-2+deb11u1 never was released.
- Target dist should be bullseye-security.
- Please explain how you tested the update.
Cheers!
Sylvain Beucler
Debian LTS Team