The Debian LTS Team, funded by [Freexian’s Debian LTS offering] (https://www.freexian.com/lts/debian/), is pleased to report its activities for November.
Activity summary
During the month of November, 18 contributors have been paid to work on Debian LTS (links to individual contributor reports are located below).
The team released 33 DLAs fixing 219 CVEs.
The LTS Team kept going with the usual cadence of preparing security updates for Debian 11 “bullseye”, but also for Debian 12 “bookworm”, Debian 13 “trixie” and even Debian unstable. As in previous months, we are pleased to say that there have been multiple contributions of LTS uploads by Debian Fellows outside the regular LTS Team.
Notable security updates:
- Guilhem Moulin prepared DLA 4365-1 for unbound, a caching DNS resolver, fixing a cache poisoning vulnerability that could lead to domain hijacking.
- Another update related to DNS software was made by Andreas Henriksson. Andreas completed the work on bind9, released as DLA 4364-1 to fix cache poisoning and Denial of Service (DoS) vulnerabilities.
- Chris Lamb released DLA 4374-1 to fix a potential arbitrary code execution vulnerability in pdfminer, a tool for extracting information from PDF documents.
- Ben Hutchings published a regular security update for the linux 6.1 bullseye backport, as DLA 4379-1.
- A couple of other important recurrent updates were prepared by Emilio Pozuelo, who handled firefox-esr and thunderbird (in collaboration with Christoph Goehre), published as DLAs DLA 4370-1 and DLA 4372-1, respectively.
Contributions from fellows outside the LTS Team:
- Thomas Goirand uploaded a bullseye update for keystone and swift
- Jeremy Bícha prepared the bullseye update for gst-plugins-base1.0
- As mentioned above, Christoph Goehre prepared the bullseye update for thunderbird.
- Mathias Behrle provided feedback about the tryton-server and tryton-sao vulnerabilities that were disclosed last month, and helped to review the bullseye patches for tryton-server.
Other than the regular LTS updates for bullseye, the LTS Team has also contributed updates to the latest Debian releases:
- Bastien Roucariès prepared a bookworm update for squid, the web proxy cache server.
- Carlos Henrique Lima Melara filed a bookworm point update request for gdk-pixbuf to fix CVE-2025-7345, a heap buffer overflow vulnerability that could lead to arbitrary code execution.
- Daniel Leidert prepared bookworm and trixie updates for r-cran-gh to fix CVE-2025-54956, an issue that may expose user credentials in HTTP responses.
- Along with the bullseye updates for unbound mentioned above, Guilhem helped to prepare the trixie update for unbound.
- In collaboration with Lukas Märdian, Tobias Frost prepared trixie and bookworm updates for log4cxx, the C++ port of the logging framework for JAVA.
- Jochen Sprickerhof prepared a bookworm update for syslog-ng.
- Utkarsh completed the bookworm update for wordpress, addressing multiple security issues in the popular blogging tool.
Beyond security updates, there has been a significant effort in revamping our documentation, aiming to make the processes more clear and consistent for all the members of the team. This work was mainly carried out by Sylvain, Jochen and Roberto.
We would like to express our gratitude to the sponsors for making the Debian LTS project possible. Also, special thanks to the fellows outside the LTS team for their valuable help.
Individual Debian LTS contributor reports
- Andreas Henriksson
- Andrej Shadura
- Bastien Roucariès
- Ben Hutchings
- Carlos Henrique Lima Melara
- Chris Lamb
- Daniel Leidert
- Emilio Pozuelo Monfort
- Guilhem Moulin
- Jochen Sprickerhof
- Markus Koschany
- Paride Legovini
- Roberto C. Sánchez
- Santiago Ruano Rincón
- Sylvain Beucler
- Thorsten Alteholz
- Tobias Frost
- Utkarsh Gupta
Thanks to our sponsors
Sponsors that joined recently are in bold.
- Platinum sponsors:
- Toshiba Corporation (for 122 months)
- Civil Infrastructure Platform (CIP) (for 90 months)
- VyOS Inc (for 54 months)
- Gold sponsors:
- F. Hoffmann-La Roche AG (for 132 months)
- CONET Deutschland GmbH (for 116 months)
- Plat’Home (for 115 months)
- University of Oxford (for 72 months)
- Deveryware (for 60 months)
- EDF SA (for 44 months)
- Dataport AöR (for 19 months)
- CERN (for 17 months)
- Silver sponsors:
- Domeneshop AS (for 137 months)
- Nantes Métropole (for 131 months)
- Akamai - Linode (for 127 months)
- Univention GmbH (for 123 months)
- Université Jean Monnet de St Etienne (for 123 months)
- Ribbon Communications, Inc. (for 117 months)
- Exonet B.V. (for 107 months)
- Leibniz Rechenzentrum (for 101 months)
- Ministère de l’Europe et des Affaires Étrangères (for 85 months)
- Cloudways by DigitalOcean (for 74 months)
- Dinahosting SL (for 72 months)
- Upsun Formerly Platform.sh (for 66 months)
- Moxa Inc. (for 60 months)
- sipgate GmbH (for 58 months)
- OVH US LLC (for 56 months)
- Tilburg University (for 56 months)
- GSI Helmholtzzentrum für Schwerionenforschung GmbH (for 47 months)
- THINline s.r.o. (for 20 months)
- Copenhagen Airports A/S (for 14 months)
- Conseil Départemental de l’Isère
- Bronze sponsors:
- Seznam.cz, a.s. (for 138 months)
- Evolix (for 137 months)
- Intevation GmbH (for 134 months)
- Linuxhotel GmbH (for 134 months)
- Daevel SARL (for 133 months)
- Megaspace Internet Services GmbH (for 132 months)
- Greenbone AG (for 131 months)
- NUMLOG (for 131 months)
- WinGo AG (for 130 months)
- Entr’ouvert (for 122 months)
- Adfinis AG (for 119 months)
- Laboratoire LEGI - UMR 5519 / CNRS (for 114 months)
- Tesorion (for 114 months)
- Bearstech (for 105 months)
- LiHAS (for 105 months)
- Catalyst IT Ltd (for 100 months)
- Demarcq SAS (for 94 months)
- Université Grenoble Alpes (for 80 months)
- TouchWeb SAS (for 72 months)
- SPiN AG (for 69 months)
- CoreFiling (for 65 months)
- Institut des sciences cognitives Marc Jeannerod (for 60 months)
- Observatoire des Sciences de l’Univers de Grenoble (for 56 months)
- Tem Innovations GmbH (for 51 months)
- WordFinder.pro (for 51 months)
- CNRS DT INSU Résif (for 49 months)
- Soliton Systems K.K. (for 45 months)
- Alter Way (for 42 months)
- Institut Camille Jordan (for 32 months)
- SOBIS Software GmbH (for 17 months)
- Tuxera Inc. (for 8 months)
- OPM-OP AS