Hi! I've just done an upstream-only source tarball release for the 1.20.x series (Debian bullseye), as I had it laying around pending release, and it was also requested by Arnaud (CCed) for the Debian LTS project.
This includes a security fix for the .deb cleanup of control members with restricted directories during extraction (CVE-2025-6297), a read overrun when parsing long GNU tar name and link entries not NUL-terminated, a segfault fix when adding triggers in no-act mode, a couple of robustness fixes for Rules-Requires-Root field handling, and a localization fix. All these fixes were (when relevant) also part of previous 1.21.x and 1.22.x security/stable releases. The code is available as a signed tag on git.dpkg.org: <https://git.dpkg.org/cgit/dpkg/dpkg.git/tag/?h=1.20.14> And as a signed tarball on: <https://www.dpkg.org/releases/dpkg-1.20.14.tar.xz> <https://www.dpkg.org/releases/dpkg-1.20.14.tar.xz.asc> Thanks, Guillem
signature.asc
Description: PGP signature

