Queue Overview for "proposed-updates"

List of missing builds
List of missing packages relative to security archive

Resolution Pending (25 uploads for 24 packages)

Package Version Version Problems Installability Problems Architectures Action
allow-html-temp 10.0.4-1~deb12u1 Installability problems Built: source Ok

Reason: update for Thunderbird 128 compatibility

Request: 1082118

Lintian issues: source

Lock-step with TB128
         
bochs 2.7+dfsg-4+deb12u1 Installability problems Built: source Ok

Reason: build BIOS images for 386 CPUs

Request: 1086347

Closes: 1082917

containerd 1.6.20~ds1-1+b2 Installability problems Built: amd64armeli386mips64elmipsel More info needed

Distribution mismatch: bookworm, sid

Reason: some builds fail (#1070411)

Binary debdiffs: amd64armeli386mips64elmipsel

criu 3.17.1-2+deb12u1 Installability problems Built: source ?

Closes: 1081683

eas4tbsync 4.11-1~deb12u1 Installability problems Built: source Ok

Reason: update for Thunderbird 128 compatibility

Request: 1082086

Lintian issues: source

Lock-step with TB128
         
firefox-esr 128.4.0esr-1~deb12u1 Installability problems Built: allamd64arm64armhfi386ppc64els390xsource Missing: mips64el Ok

DSA: 5801

CVEs referenced: CVE-2024-10458 CVE-2024-10459 CVE-2024-10460 CVE-2024-10461 CVE-2024-10462 CVE-2024-10463 CVE-2024-10464 CVE-2024-10465 CVE-2024-10466 CVE-2024-10467

Lintian issues: armhfi386

golang-github-containers-buildah 1.28.2+ds1-3+b3 Installability problems Built: amd64armeli386mips64elppc64els390x More info needed

Reason: some builds fail (#1072147)

Binary debdiffs: amd64armeli386mips64elppc64els390x

kexec-tools 1:2.0.25-3+deb12u2 Installability problems Built: source ?

µdebs: present

lemonldap-ng 2.16.1+ds-deb12u4 Installability problems Built: source Ok

Reason: fix privilege escalation when adaptive auth levels used [CVE-2024-52946]; fix XSS in upgrade plugin [CVE-2024-52947]

Request: 1087200

CVEs referenced: CVE-2024-52946 CVE-2024-52947

libmodule-scandeps-perl 1.31-2+deb12u1 Installability problems Built: allsource Ok

DSA: 5816

CVEs referenced: CVE-2024-10224

mailmindr 1.7.1-1~deb12u1 Installability problems Built: source Ok

Reason: update for Thunderbird 128 compatibility

Request: 1082115

Lintian issues: source

Lock-step with TB128
         
needrestart 3.6-4+deb12u2 Installability problems Built: allsource Ok

DSA: 5815

CVEs referenced: CVE-2024-11003 CVE-2024-48990 CVE-2024-48991 CVE-2024-48992

Binary debdiffs: all

nvidia-graphics-drivers 535.216.01-1~deb12u1 Installability problems Built: source Ok

Reason: upstream stable release [CVE-2024-0126]

Request: 1087493

Closes: 1073744 1074350 1077841 1078424 1078425 1078462 1078489 1084844 1085968

CVEs referenced: CVE-2024-0126

Lintian issues: source

nvidia-open-gpu-kernel-modules 535.216.01-1~deb12u1 Installability problems Built: source ?

Closes: 1085976

CVEs referenced: CVE-2024-0126

Lintian issues: source

oar 2.5.9-1+deb12u1 Installability problems Built: source ?

Closes: 1068444 1068711 1068713

postgresql-15 15.9-0+deb12u1 Installability problems Built: allamd64arm64armelarmhfi386mips64elppc64els390xsource Missing: mipsel Ok

DSA: 5812

CVEs referenced: CVE-2024-10976 CVE-2024-10977 CVE-2024-10978 CVE-2024-10979

Binary debdiffs: allamd64arm64armelarmhfi386mips64elppc64els390x

Lintian issues: amd64arm64armelarmhfi386mips64elppc64els390x

qemu 1:7.2+dfsg-7+deb12u8 Installability problems Built: source ?

CVEs referenced: CVE-2024-7409

quicktext 5.16-1~deb12u1 Installability problems Built: source Ok

Reason: update for Thunderbird 128 compatibility

Request: 1082111

Lintian issues: source

Lock-step with TB128
         
systemd 252.32-1~deb12u1 Installability problems Built: source ?

µdebs: present

tbsync 4.12-1~deb12u1 Installability problems Built: source Ok

Reason: update for Thunderbird 128 compatibility

Request: 1082029

Lintian issues: source

Lock-step with TB128
         
thunderbird 1:128.4.3esr-1~deb12u1 Installability problems Built: allamd64arm64ppc64elsource Missing: i386mips64els390x Ok

DSA: 5814

Binary debdiffs: allamd64arm64ppc64el

Lintian issues: amd64arm64ppc64elsource

thunderbird 1:128.4.0esr-1~deb12u1 Installability problems Built: allamd64arm64ppc64elsource Missing: i386mips64els390x Ok

DSA: 5803

Binary debdiffs: allamd64arm64ppc64el

Lintian issues: amd64arm64ppc64elsource

webkit2gtk 2.46.3-1~deb12u1 Installability problems Built: allamd64arm64armelarmhfi386mips64elppc64els390xsource Missing: mipsel Ok

DSA: 5804

Binary debdiffs: amd64arm64armelarmhfi386mips64elppc64els390x

Lintian issues: mips64el

xen 4.17.5-1~deb12u1 Version problems testing (4.17.3+36-g54dacb5c02-1) Installability problems Built: source More info needed

Reason: new upstream stable release

CVEs referenced: CVE-2023-28746 CVE-2023-46841 CVE-2023-46842 CVE-2024-2193 CVE-2024-2201 CVE-2024-31142 CVE-2024-31143 CVE-2024-31145 CVE-2024-31146

Newer than unstable
         
zfs-linux 2.1.11-1+deb12u1 Installability problems Built: source Ok

Reason: add missing symbols in libzfs4linux and libzpool5linux; fix dnode dirty test [CVE-2023-49298]; fix sharenfx IPv6 address parsing [CVE-2013-20001]; fixes related to NULL pointer, memory allocation, etc.

Request: 1086617

Closes: 1056752 1063497

CVEs referenced: CVE-2013-20001 CVE-2023-49298

Pending Processing (0 uploads for 0 packages)

Processed (16 uploads for 15 packages)

Package Version Version Problems Installability Problems Action
chromium 130.0.6723.116-1~deb12u1 Version problems testing (130.0.6723.91-2) Installability problems ACCEPTED

DSA: 5810

CVEs referenced: CVE-2024-10826 CVE-2024-10827

ghostscript 10.0.0~dfsg-11+deb12u6 Installability problems ACCEPTED

DSA: 5808

CVEs referenced: CVE-2024-46951 CVE-2024-46952 CVE-2024-46953 CVE-2024-46955 CVE-2024-46956

glib2.0 2.74.6-2+deb12u5 Installability problems ACCEPTED

Reason: fix buffer overflow when configured to use a SOCKS4a proxy with a very long username [CVE-2024-52533]

Request: 1087658

µdebs: present

Closes: 1087419

CVEs referenced: CVE-2024-52533

guix 1.4.0-3+deb12u2 Installability problems ACCEPTED

DSA: 5805

icinga2 2.13.6-2+deb12u2 Installability problems ACCEPTED

Reason: prevent TLS certificate bypass [CVE-2024-49369]

Request: 1087411

Closes: 1087384

CVEs referenced: CVE-2024-49369

libarchive 3.6.2-1+deb12u2 Installability problems ACCEPTED

DSA: 5806

Closes: 1086155

CVEs referenced: CVE-2024-20696

mariadb 1:10.11.9-0+deb12u1 Installability problems ACCEPTED

Reason: new upstream stable release; fix security issue [CVE-2024-21096]

Missing builds: s390x

Request: 1080370

CVEs referenced: CVE-2024-21096

Binary debdiffs: allamd64arm64armelarmhfi386mips64elmipselppc64el

Lintian issues: allsource

mpg123 1.31.2-1+deb12u1 Installability problems ACCEPTED

DSA: 5811

Closes: 1086443

CVEs referenced: CVE-2024-10573

nss 2:3.87.1-1+deb12u1 Installability problems ACCEPTED

DSA: 5807

CVEs referenced: CVE-2024-0743 CVE-2024-6602 CVE-2024-6609

prometheus-node-exporter-collectors 0.0~git20230203.6f710f8-1+deb12u2 Installability problems ACCEPTED

Reason: reinstate missing `apt_package_cache_timestamp_seconds` metrics; fix apt_upgrades_pending and apt_upgrades_held metrics; improve heuristic for apt update last run time

Request: 1086879

Closes: 1077694

Lintian issues: all

python-django 3:3.2.19-1+deb12u2 Installability problems c-i failed: python-django-storages/1.13.2-1 [amd64] python-django-storages/1.13.2-1 [arm64] python-django-storages/1.13.2-1 [armel] python-django-storages/1.13.2-1 [armhf] python-django-storages/1.13.2-1 [i386] python-django-storages/1.13.2-1 [ppc64el] python-django-storages/1.13.2-1 [s390x] ACCEPTED

Reason: fix regular expression-based denial of service issue [CVE-2023-36053], denial of service issues [CVE-2024-38875 CVE-2024-39614 CVE-2024-41990 CVE-2024-41991], user enumeration issue [CVE-2024-39329], directory traversal issue [CVE-2024-39330], excessive memory consumption issue [CVE-2024-41989], SQL injection issue [CVE-2024-42005]

Request: 1079454

Closes: 1076069 1078074

CVEs referenced: CVE-2023-36053 CVE-2024-38875 CVE-2024-39329 CVE-2024-39330 CVE-2024-39614 CVE-2024-41989 CVE-2024-41990 CVE-2024-41991 CVE-2024-42005

Binary debdiffs: all

Lintian issues: all

srt 1.5.1-1+deb12u1 Installability problems ACCEPTED

Reason: fix dependencies for consumers of the -dev packages

Request: 1087067

Closes: 1086751

Binary debdiffs: allamd64arm64armelarmhfi386mips64elmipselppc64els390x

symfony 5.4.23+dfsg-1+deb12u4 Installability problems ACCEPTED

DSA: 5813

CVEs referenced: CVE-2024-50342 CVE-2024-51996

symfony 5.4.23+dfsg-1+deb12u3 Installability problems ACCEPTED

This upload was superseded by a more current one.

DSA: 5809

CVEs referenced: CVE-2024-50340 CVE-2024-50342 CVE-2024-50343 CVE-2024-50345

texlive-bin 2022.20220321.62855-5.1+deb12u2 Installability problems ACCEPTED

Reason: fix data loss when using discretionaries with priorities; fix heap buffer overflow [CVE-2024-25262]

Request: 1085395

Closes: 1041441

CVEs referenced: CVE-2024-25262

Lintian issues: armhf

xsane 0.999-12.1~deb12u1 Installability problems ACCEPTED

Reason: add Recommends for firefox-esr as well as firefox

Request: 1083004

Closes: 1076101

Binary debdiffs: amd64arm64armelarmhfi386mips64elmipselppc64els390x