Package: release.debian.org
Severity: normal
X-Debbugs-Cc: [email protected], [email protected]
Control: affects -1 + src:suricata
User: [email protected]
Usertags: rm

Hello stable release managers,

I'd like to request removal of suricata/1:7.0.10-1+deb13u4 from the
upcoming Debian Trixie 13.8 point release because of security reasons.

Upstream support for Suricata 7.0.x ended in July 2026 [1]; the last
release was 7.0.17 (2026-07-07).

At the time of writing, the security tracker lists 35 open CVEs for
Trixie, some of them rated CRITICAL or HIGH by upstream. Suricata 8.0.7
fixes another 67 security issues whose applicability to 7.0 would have
to be triaged individually. This situation will not improve on further
releases.

As the code bases have diverged significantly (e.g. libhtp was replaced
by a Rust implementation in 8.0 and is archived upstream [2]), backporting
fixes is no longer feasible without a high risk of regressions.

I will also file a bug against debian-security-support requesting suricata
in Trixie to be marked EOL, so users with existing installations get
notified.

For users, there is an upgrade path via trixie-backports
(suricata/1:8.0.x-1~bpo13+1); forky already ships 8.0.7.

This request was discussed with package maintainer Sascha (@satta) as
well as with the Debian Security Team.

suricata has these rdepends:
- Depends: none
- Recommends:
  - fever (removal not needed)
- Suggests: none

Thanks and regards,
Andreas

[1] https://suricata.io/our-story/eol-policy/

[2] https://github.com/OISF/libhtp

Reply via email to