Hi!

I've just done an upstream-only source tarball release for the 1.20.x
series (Debian bullseye), as I had it laying around pending release,
and it was also requested by Arnaud (CCed) for the Debian LTS project.

This includes a security fix for the .deb cleanup of control members with
restricted directories during extraction (CVE-2025-6297), a read overrun
when parsing long GNU tar name and link entries not NUL-terminated, a
segfault fix when adding triggers in no-act mode, a couple of robustness
fixes for Rules-Requires-Root field handling, and a localization fix.

All these fixes were (when relevant) also part of previous 1.21.x and
1.22.x security/stable releases.

The code is available as a signed tag on git.dpkg.org:

  <https://git.dpkg.org/cgit/dpkg/dpkg.git/tag/?h=1.20.14>

And as a signed tarball on:

  <https://www.dpkg.org/releases/dpkg-1.20.14.tar.xz>
  <https://www.dpkg.org/releases/dpkg-1.20.14.tar.xz.asc>

Thanks,
Guillem

Attachment: signature.asc
Description: PGP signature

Reply via email to