The Debian LTS Team, funded by [Freexian’s Debian LTS offering] (https://www.freexian.com/lts/debian/), is pleased to report its activities for March.
Activity summary
During the month of March, 20 contributors have been paid to work on Debian LTS (links to individual contributor reports are located below).
The team released 24 DLAs fixing 250 CVEs.
We also welcomed two new members: Lukas Märdian and Emmanuel Arias to the team, who actually started to contribute to the LTS project several months ago.
The team continued preparing security updates in its usual rhythm. Beyond the
updates targeting Debian 11 (“bullseye”), which is the current release under LTS,
the team also proposed updates for more recent releases (Debian 12 (“bookworm”)
and Debian 13 (“trixie”)), including Debian unstable. We highlight several notable security updates here below.
- ansible (DLA 4502-1), prepared by Lee Garret in collaboration with Jochen, fixing a vulnerability that allows attackers to bypass unsafe content protections
- asterisk (DLA 4515-1), prepared by Lukas Märdian, fixing four CVEs that include possible privilege escalations.
- gimp (DLA 4500-1), prepared by Thorsen, fixing four CVEs related to denial of service or execution of arbitrary code.
- gst-plugins-base1.0 and gst-plugins-ugly1.0 (DLA-4514-1, DLA-4516-1, respectively), both prepared by Utkarsh, addressing vulnerabilities that may yield to arbitrary code execution.
- imagemagick, released by Bastien Roucariès (DLA 4497-1) fixing multiple vulnerabilities that could lead to information leaks, bypass of security policies, denial of service or arbitrary code execution.
- libpng1.6 (DLA 4521-1), prepared by Tobias Frost, fixing an arbitrary code execution vulnerability
- linux: Ben Hutching released DLA 4498-1 and DLA 4499-1 for linux 5.10 and linux 6.1, respectively. Those updates especially address the “CrackArmor” flaw.
- ruby-rack (DLA 4505-1), prepared by Utkarsh Gupta , addressing two vulnerabilities
- strongswan (DLA 4512-1), prepared by Thorsten Alteholz, fixing a Denial of Service vulnerability
- roundcube (DLA 4517-1) prepared by Guilhem Moulin, who discovered that one of the fixes provided by upstream was incomplete.
Contributions from outside the LTS Team:
As usual, the thunderbird update, released as DLA 4511-1, was prepared by its maintainer Christoph Goehre. Thanks a lot for his continuous contributions.
The LTS Team has also contributed with updates to the latest Debian releases:
Andreas Henriksson completed the uploads of glib2.0 for both trixie and bookworm
Arnaud Rebillout: python-cryptography for trixie
Arnaud and Bastien worked together to prepare a ca-certificates-java release for unstable
Bastien completed the upload of gpsd for trixie that was proposed in January.
Bastien uploaded a regression update of apache2 for trixie
Bastien prepared a zabbix point update for trixie
Bastien in collaboration with Markus released netty updates for trixie and bookworm DSA 6160-1
Daniel Leidert proposed python-tornado releases for both trixie and bookworm.
Daniel also prepared a python-authlib update for trixie
Guilhem prepared a mapserver update for bookworm.
Lucas Kanashiro proposed merge requests to fix three CVEs in erlang for both trixie and bookworm
Sylvain Beucler continued the work to replace p7zip with 7zip in the different supported releases, and proposed a point update for bookworm
Tobias prepared trixie and bookworm security updates, released as DSA-6189-1
Utkarsh prepared trixie and bookworm security update for ruby-rack, released as DSA-6180-1
Individual Debian LTS contributor reports
- Andreas Henriksson
- Andrej Shadura
- Arnaud Rebillout
- Bastien Roucariès
- Ben Hutchings
- Carlos Henrique Lima Melara
- Chris Lamb
- Daniel Leidert
- Emilio Pozuelo Monfort
- Guilhem Moulin
- Jochen Sprickerhof
- Lee Garrett
- Lucas Kanashiro
- Lukas Märdian
- Markus Koschany
- Santiago Ruano Rincón
- Sylvain Beucler
- Thorsten Alteholz
- Tobias Frost
- Utkarsh Gupta
Thanks to our sponsors
Sponsors that joined recently are in bold.
- Platinum sponsors:
- Toshiba Corporation (for 126 months)
- Civil Infrastructure Platform (CIP) (for 94 months)
- VyOS Inc (for 59 months)
- Gold sponsors:
- F. Hoffmann-La Roche AG (for 137 months)
- CONET Deutschland GmbH (for 120 months)
- University of Oxford (for 77 months)
- EDF SA (for 48 months)
- Dataport AöR (for 23 months)
- CERN (for 21 months)
- Silver sponsors:
- Domeneshop AS (for 141 months)
- Nantes Métropole (for 135 months)
- Akamai - Linode (for 131 months)
- Univention GmbH (for 127 months)
- Université Jean Monnet de St Etienne (for 127 months)
- Ribbon Communications, Inc. (for 121 months)
- Exonet B.V. (for 111 months)
- Leibniz Rechenzentrum (for 105 months)
- Ministère de l’Europe et des Affaires Étrangères (for 89 months)
- Dinahosting SL (for 76 months)
- Upsun Formerly Platform.sh (for 71 months)
- Moxa Inc. (for 65 months)
- Deveryware (for 64 months)
- sipgate GmbH (for 62 months)
- OVH US LLC (for 60 months)
- Tilburg University (for 60 months)
- GSI Helmholtzzentrum für Schwerionenforschung GmbH (for 52 months)
- THINline s.r.o. (for 24 months)
- Copenhagen Airports A/S (for 18 months)
- Conseil Départemental de l’Isère (for 4 months)
- Bronze sponsors:
- Seznam.cz, a.s. (for 142 months)
- Evolix (for 141 months)
- Linuxhotel GmbH (for 139 months)
- Intevation GmbH (for 138 months)
- Daevel SARL (for 137 months)
- Megaspace Internet Services GmbH (for 136 months)
- Greenbone AG (for 135 months)
- NUMLOG (for 135 months)
- WinGo AG (for 134 months)
- Entr’ouvert (for 126 months)
- Adfinis AG (for 123 months)
- Plat’Home (for 120 months)
- Laboratoire LEGI - UMR 5519 / CNRS (for 118 months)
- Tesorion (for 118 months)
- Bearstech (for 110 months)
- LiHAS (for 110 months)
- Catalyst IT Ltd (for 104 months)
- Demarcq SAS (for 98 months)
- Université Grenoble Alpes (for 84 months)
- TouchWeb SAS (for 76 months)
- SPiN AG (for 73 months)
- CoreFiling (for 69 months)
- Observatoire des Sciences de l’Univers de Grenoble (for 61 months)
- Tem Innovations GmbH (for 55 months)
- WordFinder.pro (for 55 months)
- CNRS DT INSU Résif (for 54 months)
- Soliton Systems K.K. (for 49 months)
- Alter Way (for 47 months)
- SOBIS Software GmbH (for 21 months)
- Tuxera Inc. (for 13 months)
- OPM-OP AS (for 4 months)