Package: release.debian.org Severity: normal X-Debbugs-Cc: [email protected], [email protected] Control: affects -1 + src:suricata User: [email protected] Usertags: rm
Hello stable release managers, I'd like to request removal of suricata/1:7.0.10-1+deb13u4 from the upcoming Debian Trixie 13.8 point release because of security reasons. Upstream support for Suricata 7.0.x ended in July 2026 [1]; the last release was 7.0.17 (2026-07-07). At the time of writing, the security tracker lists 35 open CVEs for Trixie, some of them rated CRITICAL or HIGH by upstream. Suricata 8.0.7 fixes another 67 security issues whose applicability to 7.0 would have to be triaged individually. This situation will not improve on further releases. As the code bases have diverged significantly (e.g. libhtp was replaced by a Rust implementation in 8.0 and is archived upstream [2]), backporting fixes is no longer feasible without a high risk of regressions. I will also file a bug against debian-security-support requesting suricata in Trixie to be marked EOL, so users with existing installations get notified. For users, there is an upgrade path via trixie-backports (suricata/1:8.0.x-1~bpo13+1); forky already ships 8.0.7. This request was discussed with package maintainer Sascha (@satta) as well as with the Debian Security Team. suricata has these rdepends: - Depends: none - Recommends: - fever (removal not needed) - Suggests: none Thanks and regards, Andreas [1] https://suricata.io/our-story/eol-policy/ [2] https://github.com/OISF/libhtp

