Dear security team,

concerning CVE-2026-59986
https://github.com/alanxz/rabbitmq-c/security/advisories/GHSA-jgjf-7fwf-f3c7
and CVE-2026-61547
https://github.com/alanxz/rabbitmq-c/security/advisories/GHSA-hfjv-vcp3-39wh

Upstream's v0.17.0 fixing both had been uploaded to unstable recently
and has in the meantime already migrated to testing,
cf. https://tracker.debian.org/pkg/librabbitmq
Unfortunately, at the time of upstream's v0.17.0 release, the CVE
identifiers were not yet known, so they were not part of the changelog.
I have since added them for reference, cf.
https://salsa.debian.org/debian/librabbitmq/-/commit/1e6e7e0d8809f0a2d79110235fe177a94371a588

Here now come the patches for Trixie, backported and reduced to the
essentials for fixing the vulnerabilities. Given how few changes
upstream's latest releases show, I don't see much risk in just applying
them, cf. https://github.com/alanxz/rabbitmq-c/compare/v0.15.0...v0.17.0

So I just prepared the patches and uploaded them to Salsa, cf.
https://salsa.debian.org/debian/librabbitmq/-/commits/debian/trixie?ref_type=heads
where the Pipeline was able to build the package (albeit in Sid, that
is), cf. https://salsa.debian.org/debian/librabbitmq/-/pipelines/1137640

If you want to issue a DSA based on this already, please feel free to
just do so. Otherwise just let me know if I should rather apply any changes.


Dear LTS Team,

likewise I have prepared the patches and uploaded them to Salsa for
Bookworm and Bullseye, cf.
https://salsa.debian.org/debian/librabbitmq/-/commits/debian/bookworm?ref_type=heads
and
https://salsa.debian.org/debian/librabbitmq/-/commits/debian/bullseye?ref_type=heads

Please feel free to base a DLA on this, or just let me know if I should
rather apply any changes.


Cheers,
Flo

Attachment: signature.asc
Description: PGP signature

Reply via email to