Queue Overview for "proposed-updates"

TODO items

List of missing builds
List of missing packages relative to security archive

Resolution Pending (5 uploads for 4 packages)

Package Version Version Problems Installability Problems Architectures Action
clatd 2.1.0-2+deb13u1 Installability problems Built: source ?

Closes: 1101004 1110678

gimp 3.0.4-3+deb13u4 Installability problems Built: i386source Missing: allamd64arm64armelarmhfppc64elriscv64 ?

DSA: 6093

CVEs referenced: CVE-2025-14425

Lintian issues: i386source

gimp 3.0.4-3+deb13u3 Installability problems Built: allamd64arm64armelarmhfi386ppc64elriscv64source ?

CVEs referenced: CVE-2025-14422 CVE-2025-14423 CVE-2025-14424

Lintian issues: allamd64arm64armelarmhfi386ppc64elriscv64source

libsodium 1.0.18-1+deb13u1 Installability problems Built: amd64arm64armelarmhfi386ppc64elriscv64s390xsource ?

DSA: 6094

Closes: 1124374

CVEs referenced: CVE-2025-69277

Binary debdiffs: armelarmhf

tayga 0.9.2-10+deb13u1 Installability problems Built: source ?

Closes: 1082060

Pending Processing (0 uploads for 0 packages)

Processed (169 uploads for 138 packages)

Package Version Version Problems Installability Problems Action
ansible 12.0.0+dfsg-0+deb13u1 Installability problems ACCEPTED

Reason: new upstream stable release

Request: 1121608

Binary debdiffs: all

apache2 2.4.66-1~deb13u1 Installability problems ACCEPTED

Reason: new upstream stable release; fix integer overflow issue [CVE-2025-55753]; don't pass querystring to #exec directives [CVE-2025-58098]; fix improper parsing of environment variables [CVE-2025-65082]; fix mod_userdir+suexec bypass issue [CVE-2025-66200]

Request: 1121946

Closes: 1121926

CVEs referenced: CVE-2025-55753 CVE-2025-58098 CVE-2025-59775 CVE-2025-65082 CVE-2025-66200

Binary debdiffs: all

Lintian issues: amd64arm64armelarmhfi386ppc64elriscv64s390xsource

at-spi2-core 2.56.2-1+deb13u1 Installability problems ACCEPTED

Reason: ensure xkb group is taken into account for key events

Request: 1121040

µdebs: present

Closes: 1111485

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

Lintian issues: riscv64

awffull 3.10.2-10+deb13u1 Installability problems ACCEPTED

Reason: fix systemd timer invocation to avoid premature cron-script exit

Request: 1121894

Closes: 1120742

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

base-files 13.8+deb13u3 Installability problems c-i failed: mmdebstrap/1.5.7-1+deb13u1 [riscv64] ACCEPTED

Reason: update for the point release

Lintian issues: source

bash 5.2.37-2+b7 Installability problems ACCEPTED

Reason: rebuild with updated glibc

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

bash 5.2.37-2+b6 Installability problems ACCEPTED

Reason: rebuild with updated glibc

bglibs 2.04+dfsg-8+b5 Installability problems ACCEPTED

Reason: rebuild with updated glibc

Binary debdiffs: amd64arm64armelarmhfi386ppc64els390x

bglibs 2.04+dfsg-8+b4 Installability problems ACCEPTED

Reason: rebuild with updated glibc

busybox 1.37.0-6+b5 Installability problems ACCEPTED

Reason: rebuild with updated glibc

µdebs: present

Binary debdiffs: amd64arm64armelarmhfi386ppc64els390x

busybox 1.37.0-6+b4 Installability problems ACCEPTED

Reason: rebuild with updated glibc

µdebs: present

c-ares 1.34.5-1+deb13u1 Installability problems ACCEPTED

DSA: 6084

CVEs referenced: CVE-2025-62408

calibre 8.5.0+ds-1+deb13u1 Installability problems ACCEPTED

Reason: fix FB2 embedded binary handling in conversion plugin [CVE-2025-64486]

Request: 1120419

CVEs referenced: CVE-2025-64486

catatonit 0.2.1-2+b7 Installability problems ACCEPTED

Reason: rebuild with updated glibc

Binary debdiffs: amd64arm64armelarmhfi386ppc64els390x

catatonit 0.2.1-2+b5 Installability problems ACCEPTED

Reason: rebuild with updated glibc

cdebootstrap 0.7.9+b5 Installability problems ACCEPTED

Reason: rebuild with updated glibc

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

cdebootstrap 0.7.9+b3 Installability problems ACCEPTED

Reason: rebuild with updated glibc

chkrootkit 0.58b-5+b4 Installability problems ACCEPTED

Reason: rebuild with updated glibc

Binary debdiffs: amd64arm64armelarmhfi386ppc64els390x

chkrootkit 0.58b-5+b3 Installability problems ACCEPTED

Reason: rebuild with updated glibc

chromium 143.0.7499.169-1~deb13u1 Installability problems ACCEPTED

DSA: 6089

CVEs referenced: CVE-2025-14765 CVE-2025-14766

Lintian issues: source

chromium 143.0.7499.109-1~deb13u1 Installability problems ACCEPTED

This upload was superseded by a more current one.

DSA: 6080

CVEs referenced: CVE-2025-14372 CVE-2025-14373

Lintian issues: ppc64el

chromium 143.0.7499.40-1~deb13u1 Installability problems ACCEPTED

This upload was superseded by a more current one.

DSA: 6072

CVEs referenced: CVE-2025-13630 CVE-2025-13631 CVE-2025-13632 CVE-2025-13633 CVE-2025-13634 CVE-2025-13635 CVE-2025-13636 CVE-2025-13637 CVE-2025-13638 CVE-2025-13639 CVE-2025-13640 CVE-2025-13720 CVE-2025-13721

chromium 142.0.7444.175-1~deb13u1 Installability problems ACCEPTED

This upload was superseded by a more current one.

DSA: 6060

CVEs referenced: CVE-2025-13223 CVE-2025-13224

chromium 142.0.7444.162-1~deb13u1 Installability problems ACCEPTED

This upload was superseded by a more current one.

DSA: 6055

CVEs referenced: CVE-2025-13042

cloud-init 25.1.4-1+deb13u1 Installability problems ACCEPTED

Reason: ensure deb822 sources.list template renders correctly

Request: 1120483

Closes: 1118187

composer 2.8.8-1+deb13u1 Installability problems ACCEPTED

Reason: fix ANSI sequence injection [CVE-2025-67746]

Request: 1124354

CVEs referenced: CVE-2025-67746

condor 23.9.6+dfsg-2.1+b6 Installability problems ACCEPTED

Reason: rebuild with updated glibc

Binary debdiffs: arm64armelarmhfi386ppc64elriscv64s390x

condor 23.9.6+dfsg-2.1+b4 Installability problems ACCEPTED

Reason: rebuild with updated glibc

containerd 1.7.24~ds1-6+deb13u1 Installability problems ACCEPTED

DSA: 6067

Closes: 1120343

CVEs referenced: CVE-2024-25621 CVE-2025-64329

cups-filters 1.28.17-6+deb13u1 Installability problems ACCEPTED

Reason: fix TIFF parser bounds/validation issues [CVE-2025-57812]; clamp oversized PDF MediaBox-derived page size in pdftoraster [CVE-2025-64503]; avoid rastertopclx infinite loop and heap overflow on crafted raster input [CVE-2025-64524]

Request: 1121391

Closes: 1120698 1120704

CVEs referenced: CVE-2025-57812 CVE-2025-64503 CVE-2025-64524

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

dar 2.7.17-1+b9 Installability problems ACCEPTED

Reason: rebuild with updated curl, glibc, openssl

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

debian-installer 20250803+deb13u3 Version problems testing (20250803+deb13u2) Installability problems ACCEPTED

Reason: increase Linux kernel ABI to 6.12.63+deb13; rebuild against proposed updates

Binary debdiffs: amd64arm64armhfppc64elriscv64s390x

Lintian issues: source

debian-installer-netboot-images 20250803+deb13u3 Version problems testing (20250803+deb13u2) Installability problems ACCEPTED

Reason: rebuild against proposed-updates

Binary debdiffs: all

debian-security-support 1:13+2026.01.04 Installability problems ACCEPTED

Reason: mark hdf5 and zabbix as receiving limited support; mark wpewebkit as unsupported

Request: 1124620

Closes: 1117607 1118273 1124558

debos 1.1.5-1+deb13u1 Installability problems c-i failed: debos/1.1.5-1+deb13u1 [amd64] ACCEPTED

Distribution mismatch: trixie-proposed-updates

Reason: move systemd-resolved from Recommends to Depends

Request: 1122901

Closes: 1115880

Binary debdiffs: amd64arm64

dgit 12.16 Installability problems ACCEPTED

Reason: git-debrebase: use different directory for nested workareas

Request: 1117455

Closes: 1116933

dhcpcd 1:10.1.0-11+deb13u2 Installability problems ACCEPTED

Reason: re-enable ntp_servers option by default

Request: 1123973

Closes: 1123962

diffoscope 297+deb13u1 Installability problems ACCEPTED

Reason: fix tests when ukify is newer

Request: 1121754

Closes: 1120867

distribution-gpg-keys 1.115+ds-1~deb13u1 Installability problems ACCEPTED

Reason: update included keys

Request: 1124493

Binary debdiffs: all

distrobuilder 3.2-2+b4 Installability problems ACCEPTED

Reason: rebuild with updated containerd, incus

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

docker.io 26.1.5+dfsg1-9+b11 Installability problems ACCEPTED

Reason: rebuild with updated glibc

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

docker.io 26.1.5+dfsg1-9+b10 Installability problems ACCEPTED

Reason: rebuild with updated containerd, glibc

dpdk 24.11.4-0+deb13u1 Installability problems c-i failed: dpdk/24.11.4-0+deb13u1 [riscv64] ACCEPTED

Reason: new upstream stable release

Request: 1123951

Closes: 1114911

Binary debdiffs: amd64arm64

Lintian issues: allarm64

dropbear 2025.89-1~deb13u1 Installability problems ACCEPTED

DSA: 6086

Closes: 1123069

CVEs referenced: CVE-2025-14282

e2fsprogs 1.47.2-3+b7 Installability problems ACCEPTED

Reason: rebuild wth updated glibc

µdebs: present

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

e2fsprogs 1.47.2-3+b5 Installability problems ACCEPTED

Reason: rebuild wth updated glibc

µdebs: present

edk2 2025.02-8+deb13u1 Installability problems ACCEPTED

Reason: fix timing side-channel issue in ECDSA signature computation [CVE-2024-13176]; fix out-of-bounds memory access issue [CVE-2024-38805]; fix code execution issue [CVE-2025-3770]

Request: 1120393

CVEs referenced: CVE-2024-13176 CVE-2024-38805 CVE-2025-3770

Lintian issues: all

exfatprogs 1.2.9-1+deb13u1 Installability problems ACCEPTED

Reason: ensure mkfs.exfat defaults to 512-byte sectors for Windows compatibility

Request: 1120962

Closes: 1120932

Lintian issues: amd64arm64armelarmhfi386ppc64elriscv64s390x

extrepo-data 1.0.6~deb13u1 Installability problems ACCEPTED

Reason: update repository information; fix handling for future Debian releases

Request: 1110915

Closes: 1078614

Binary debdiffs: all

Lintian issues: allsource

ffmpeg 7:7.1.3-0+deb13u1 Installability problems c-i failed: mystiq/20.03.23-3 [riscv64] ACCEPTED

DSA: 6073

firefox-esr 140.6.0esr-1~deb13u1 Version problems testing (140.5.0esr-1) Installability problems ACCEPTED

DSA: 6078

CVEs referenced: CVE-2025-14321 CVE-2025-14322 CVE-2025-14323 CVE-2025-14324 CVE-2025-14325 CVE-2025-14328 CVE-2025-14329 CVE-2025-14330 CVE-2025-14331 CVE-2025-14333

Lintian issues: armhfi386riscv64source

firefox-esr 140.5.0esr-1~deb13u1 Installability problems ACCEPTED

This upload was superseded by a more current one.

DSA: 6054

CVEs referenced: CVE-2025-13012 CVE-2025-13013 CVE-2025-13014 CVE-2025-13015 CVE-2025-13016 CVE-2025-13017 CVE-2025-13018 CVE-2025-13019 CVE-2025-13020

Lintian issues: armhfi386riscv64

flatpak 1.16.2-1~deb13u1 Installability problems ACCEPTED

Reason: new upstream stable release

Request: 1123776

Closes: 1114484 1116737

Binary debdiffs: allamd64arm64armelarmhfi386ppc64elriscv64s390x

Lintian issues: allamd64arm64armelarmhfi386ppc64elriscv64s390xsource

fpdf2 2.8.3-1+deb13u1 Installability problems ACCEPTED

Reason: fix use of variable fonts

Request: 1115579

Closes: 1110990

freedombox 25.9.3+deb13u1 Installability problems ACCEPTED

Reason: distupgrade: Handle comments in sources.list file; update trixie's release date; backups: Set proper permissions for backups-data directory [CVE-2025-68462]

Request: 1123596

CVEs referenced: CVE-2025-68462

Binary debdiffs: all

freeradius 3.2.7+dfsg-1+deb13u2 Installability problems ACCEPTED

Reason: fix TLS verification segfault when certificate chains include multiple intermediate certificates

Request: 1120965

Closes: 1120927

glib2.0 2.84.4-3~deb13u2 Installability problems ACCEPTED

Reason: prevent various integer overflows [CVE-2025-13601 CVE-2025-14087 CVE-2025-14512]

Request: 1122373

µdebs: present

Closes: 1121488 1122346 1122347

CVEs referenced: CVE-2025-13601 CVE-2025-14087 CVE-2025-14512

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

glibc 2.41-12+deb13u1 Installability problems ACCEPTED

Reason: fix a double lock init issue after fork(); fix SYSCALL_CANCEL for return values larger than INT_MAX; fix crash in ifunc functions on arm64 when hardening with -ftrivial-auto-var-init=zero; fix _dl_find_object when ld.so has LOAD segment gaps, causing wrong backtrace unwinding; optimize inverse trig function, SVE exp, hyperbolic, and log1p functions on arm64

Request: 1123843

µdebs: present

Closes: 1115729

gnome-shell 48.7-0+deb13u1 Installability problems ACCEPTED

Reason: new upstream bugfix release

Request: 1122371

gnome-shell-extension-gsconnect 62-1+deb13u1 Installability problems ACCEPTED

DSA: 6066

gnupg2 2.4.7-21+deb13u1+b1 Installability problems ACCEPTED

Reason: rebuild with updated glibc

µdebs: present

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

gnupg2 2.4.7-21+deb13u1 Installability problems ACCEPTED

Reason: avoid potential downgrade to SHA1 in 3rd party key signatures; error out on unverified output for non-detached signatures; fix possible memory corruption in the armor parser [CVE-2025-68973]; do not use a default when asking for another output filename

Request: 1124429

µdebs: present

Closes: 1124221

CVEs referenced: CVE-2025-68973

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

gnutls28 3.8.9-3+deb13u1 Installability problems ACCEPTED

Reason: fix PKCS#11 token label bounds in gnutls_pkcs11_token_init [CVE-2025-9820]; initialise PKCS#11 modules in thread-safe mode with fallback

Request: 1121234

Closes: 1121146

CVEs referenced: CVE-2025-9820

golang-github-awslabs-soci-snapshotter 0.4.1-5+b3 Installability problems ACCEPTED

Reason: rebuild with updated containerd

Binary debdiffs: amd64arm64ppc64elriscv64s390x

golang-github-containerd-imgcrypt 1.1.11-4+b13 Installability problems ACCEPTED

Reason: rebuild with updated containerd

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

golang-github-containerd-nydus-snapshotter 0.13.4-2.1+b10 Installability problems ACCEPTED

Reason: rebuild with updated containerd

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

golang-github-containerd-stargz-snapshotter 0.14.3-4+b6 Installability problems ACCEPTED

Reason: rebuild with updated containerd

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

golang-github-containers-buildah 1.39.3+ds1-1+b7 Installability problems ACCEPTED

Reason: rebuild with updated containerd

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

golang-github-openshift-imagebuilder 1.2.15+ds1-1+b7 Installability problems ACCEPTED

Reason: rebuild with updated containerd

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

imagemagick 8:7.1.1.43+dfsg1-1+deb13u4 Installability problems ACCEPTED

Reason: fix denial of service issues [CVE-2025-62594 CVE-2025-68618]; fix use-after-free issue [CVE-2025-65955]; fix integer overflow issues [CVE-2025-66628 CVE-2025-69204]; fix infinite loop issue [CVE-2025-68950]

Request: 1124366

Closes: 1119296 1122584 1122827

CVEs referenced: CVE-2025-62594 CVE-2025-65955 CVE-2025-66628 CVE-2025-68618 CVE-2025-68950 CVE-2025-69204

Lintian issues: allamd64arm64armelarmhfi386ppc64elriscv64s390xsource

incus 6.0.4-2+deb13u3 Installability problems ACCEPTED

Reason: fix AppArmor profile generation for nested containers

Request: 1121206

Closes: 1121011

incus 6.0.4-2+deb13u2 Installability problems ACCEPTED

This upload was superseded by a more current one.

DSA: 6051

integrit 4.1-7+b8 Installability problems ACCEPTED

Reason: rebuild with updated glibc

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

integrit 4.1-7+b5 Installability problems ACCEPTED

Reason: rebuild with updated glibc

intel-microcode 3.20251111.1~deb13u1 Installability problems ACCEPTED

Reason: update Intel processor microcode to 20251111

Request: 1122236

Binary debdiffs: amd64i386

iperf3 3.18-2+deb13u2 Installability problems ACCEPTED

Reason: fix authentication RSA encryption buffer length initialisation for OpenSSL 3.5.3+; avoid FTBFS with newer OpenSSL

Request: 1120887

Closes: 1120866

kdeconnect 25.04.2-1+deb13u1 Installability problems ACCEPTED

DSA: 6063

keystone 2:27.0.0-3+deb13u1 Installability problems ACCEPTED

DSA: 6056

Closes: 1120053

Binary debdiffs: all

kleopatra 4:24.12.3-1+deb13u1 Installability problems ACCEPTED

Reason: fix failure to start with a file argument on GNOME

Request: 1121604

Closes: 1120106

krita 1:5.2.9+dfsg-1+deb13u1 Installability problems ACCEPTED

DSA: 6065

CVEs referenced: CVE-2025-59820

lasso 2.8.2-9+deb13u1 Installability problems ACCEPTED

DSA: 6058

CVEs referenced: CVE-2025-46404 CVE-2025-46705 CVE-2025-47151

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

libcap2 2.75-10+b3 Installability problems ACCEPTED

Reason: rebuild with updated glibc

µdebs: present

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

libcoap3 4.3.4-1.1+deb13u2 Installability problems ACCEPTED

Reason: fix configuration file parsing issue [CVE-2025-59391]; fix NULL pointer dereference issues [CVE-2025-65493 CVE-2025-65494 CVE-2025-65496 CVE-2025-65497 CVE-2025-65498 CVE-2025-65500 CVE-2025-65501]; fix integer signedness issue [CVE-2025-65495]; fix array index error issue [CVE-2025-65499]

Request: 1124284

Closes: 1121415 1122290

CVEs referenced: CVE-2025-59391 CVE-2025-65493 CVE-2025-65494 CVE-2025-65495 CVE-2025-65496 CVE-2025-65497 CVE-2025-65498 CVE-2025-65499 CVE-2025-65500 CVE-2025-65501

Lintian issues: amd64arm64armelarmhfi386ppc64elriscv64s390x

libcupsfilters 2.0.0-3+deb13u1 Installability problems ACCEPTED

Reason: fix TIFF parser bounds/validation issues [CVE-2025-57812]; clamp oversized PDF MediaBox-derived page size in pdftoraster [CVE-2025-64503]

Request: 1121342

Closes: 1120697 1120703

CVEs referenced: CVE-2025-57812 CVE-2025-64503

libphp-adodb 5.22.9-0.1+deb13u1 Installability problems ACCEPTED

Reason: fix SQL injection issue in sqlite(3) drivers [CVE-2025-54119]

Request: 1116017

Closes: 1110464

CVEs referenced: CVE-2025-54119

libpng1.6 1.6.48-1+deb13u1 Installability problems ACCEPTED

DSA: 6076

µdebs: present

Closes: 1121216 1121217 1121218 1121219 1121877

CVEs referenced: CVE-2025-64505 CVE-2025-64506 CVE-2025-64720 CVE-2025-65018 CVE-2025-66293

libreoffice 4:25.2.3-2+deb13u3 Installability problems s390x ACCEPTED

Reason: set Bulgaria locale default currency to EUR

Request: 1123604

Binary debdiffs: all

libvirt 11.3.0-3+deb13u2 Installability problems amd64 arm64 ACCEPTED

Reason: perform ACL checks earlier, preventing malicious users from potentially being able to crash the daemon [CVE-2025-12748]; ensure that newly-created snapshots are not world-readable [CVE-2025-13193]; apply the detect_zeroes settings across all layers of the backing chain instead of just the topmost one

Request: 1121534

Closes: 1120119 1120584 1121280

CVEs referenced: CVE-2025-12748 CVE-2025-13193

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

linux 6.12.63-1 Installability problems ACCEPTED

Reason: new upstream stable release

µdebs: present

Closes: 1000966 1106411 1114557 1117959 1120602 1120680 1122144

CVEs referenced: CVE-2025-22121 CVE-2025-38678 CVE-2025-39981 CVE-2025-40075 CVE-2025-40077 CVE-2025-40097 CVE-2025-40212 CVE-2025-40213 CVE-2025-68324 CVE-2025-68325

Binary debdiffs: allamd64arm64armelarmhfi386ppc64elriscv64s390x

Lintian issues: allarmelarmhfi386ppc64elriscv64s390xsource

linux-signed-amd64 6.12.63+1 Installability problems amd64 ACCEPTED

Distribution mismatch: trixie-proposed-updates

Reason: new upstream stable release

µdebs: present

Closes: 1000966 1106411 1114557 1117959 1120602 1120680 1122144

CVEs referenced: CVE-2025-22121 CVE-2025-38678 CVE-2025-39981 CVE-2025-40075 CVE-2025-40077 CVE-2025-40097 CVE-2025-40212 CVE-2025-40213 CVE-2025-68324 CVE-2025-68325

Binary debdiffs: amd64

Lintian issues: amd64source

linux-signed-arm64 6.12.63+1 Installability problems arm64 ACCEPTED

Distribution mismatch: trixie-proposed-updates

Reason: new upstream stable release

µdebs: present

Closes: 1000966 1106411 1114557 1117959 1120602 1120680 1122144

CVEs referenced: CVE-2025-22121 CVE-2025-38678 CVE-2025-39981 CVE-2025-40075 CVE-2025-40077 CVE-2025-40097 CVE-2025-40212 CVE-2025-40213 CVE-2025-68324 CVE-2025-68325

Binary debdiffs: arm64

Lintian issues: arm64source

lua-wsapi 1.6.1-3+deb13u1 Installability problems ACCEPTED

Reason: fix Lua 5.1 support

Request: 1124361

Closes: 1123592

Binary debdiffs: all

Lintian issues: all

lxc 1:6.0.4-4+deb13u1 Installability problems ACCEPTED

Reason: add lxc-net dependency to sysvinit script; stop printing misleading errors in enter_net_ns(); fix generation of apparmor.d/abstractions/lxc/container-base; fix restarting unprivileged containers

Request: 1124036

Closes: 1118024 1122149 1123979

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

Lintian issues: source

lxd 5.0.2+git20231211.1364ae4-9+deb13u2 Installability problems ACCEPTED

Reason: fix broken idmapping with kernel 6.9+; tighten storage pool volume permissions [CVE-2025-64507]

Request: 1120520

CVEs referenced: CVE-2025-64507

Lintian issues: all

matlab-support 0.1.1+deb13u1 Installability problems ACCEPTED

Reason: avoid renaming MATLAB vendored Vulkan/FreeType libraries

Request: 1120688

Closes: 1120681

Binary debdiffs: all

mbedtls 3.6.5-0.1~deb13u1 Installability problems ACCEPTED

Reason: new upstream stable release; fix timing issues [CVE-2025-54764 CVE-2025-59438]

Request: 1124567

Closes: 1118750 1118752

CVEs referenced: CVE-2025-54764 CVE-2025-59438

Binary debdiffs: allamd64arm64armelarmhfi386ppc64elriscv64s390x

mediawiki 1:1.43.6+dfsg-1~deb13u1 Installability problems ACCEPTED

DSA: 6085

Binary debdiffs: all

Lintian issues: source

mirrorbits 0.6.1-1~deb13u1 Installability problems ACCEPTED

Reason: fix fallback redirects when Redis/file metadata is unavailable; normalise fallback mirror URLs to avoid malformed redirects

Request: 1120493

mongo-c-driver 1.30.4-1+deb13u1 Installability problems ACCEPTED

Reason: avoid invalid memory reads [CVE-2025-12119]

Request: 1123626

CVEs referenced: CVE-2025-12119

mutter 48.7-0+deb13u1 Installability problems ACCEPTED

Reason: new upstream bugfix release

Request: 1122372

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

node-nodemailer 6.10.0+~6.4.17-1+deb13u1 Installability problems ACCEPTED

Reason: fix addressparser recipient parsing for quoted nested addresses [CVE-2025-13033]

Request: 1120717

CVEs referenced: CVE-2025-13033

openconnect 9.12-3+deb13u2 Installability problems ACCEPTED

Reason: fix failure to build with MinGW32/64; use RFC9266 'tls-exporter' channel bindings for Cisco STRAP with TLSv1.3

Request: 1119300

Closes: 1099497

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

Lintian issues: source

openconnect 9.12-3+deb13u1 Installability problems ACCEPTED

This upload was superseded by a more current one.

Reason: respect path in AnyConnect/OpenConnect XML form handling

Closes: 1119239

openvpn 2.6.14-1+deb13u1 Installability problems ACCEPTED

DSA: 6069

Closes: 1114249 1121086

CVEs referenced: CVE-2025-13086

pdfminer 20221105+dfsg-1.1~deb13u1 Installability problems ACCEPTED

DSA: 6062

Binary debdiffs: all

Lintian issues: all

pdns-recursor 5.2.7-0+deb13u1 Installability problems ACCEPTED

DSA: 6077

CVEs referenced: CVE-2025-59030

pgbouncer 1.24.1-1+deb13u1 Installability problems ACCEPTED

Reason: fix arbitary SQL execution issue [CVE-2025-12819]

Request: 1124080

CVEs referenced: CVE-2025-12819

podman 5.4.2+ds1-2+b2 Installability problems ACCEPTED

Reason: rebuild with updated containerd

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

postgresql-17 17.7-0+deb13u1 Installability problems c-i failed: pgl-ddl-deploy/2.2.1-2 [amd64] pgl-ddl-deploy/2.2.1-2 [arm64] pgl-ddl-deploy/2.2.1-2 [ppc64el] pgl-ddl-deploy/2.2.1-2 [s390x] ACCEPTED

Reason: new upstream stable release; check for CREATE privileges on the schema in CREATE STATISTICS [CVE-2025-12817]; avoid integer overflow in allocation-size calculations within libpq [CVE-2025-12818]

CVEs referenced: CVE-2025-12817 CVE-2025-12818

Binary debdiffs: all

pylint-django 2.0.13-5+deb13u1 Installability problems ACCEPTED

Reason: fix use with new astroid

Request: 1121427

Closes: 1121404

qemu 10.0.7+ds-0+deb13u1+b1 Installability problems amd64 arm64 armel armhf i386 ppc64el riscv64 s390x ACCEPTED

Reason: rebuild with updated glibc

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

qemu 1:10.0.7+ds-0+deb13u1 Installability problems ACCEPTED

Reason: new upstream stable release; fix use after free issue [CVE-2025-11234]; fix buffer overflow issue [CVE-2025-12464]

Request: 1123033

Closes: 1035676 1117153 1119917 1120146

CVEs referenced: CVE-2025-11234 CVE-2025-12464

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

Lintian issues: amd64arm64armelarmhfi386ppc64elriscv64s390xsource

qiv 3.0.1-2+deb13u1 Installability problems ACCEPTED

Reason: fix Wayland startup crash by forcing X11 GDK backend

Request: 1121244

Closes: 1103712

Lintian issues: ppc64elriscv64s390x

r-bioc-beachmat 2.22.0+ds-3~deb13u1 Installability problems ACCEPTED

Reason: fix test that depends on the "beachmat.hdf5" R package, which is not yet in Debian

Request: 1115192

Closes: 1111758

r-cran-gh 1.4.1-1+deb13u1 Installability problems ACCEPTED

Reason: fix exposure of request headers in returned response objects [CVE-2025-54956]; ensure pagination passes authentication context explicitly; update tests and documentation

Request: 1121384

Closes: 1110481

CVEs referenced: CVE-2025-54956

rails 2:7.2.2.2+dfsg-2~deb13u1 Installability problems ACCEPTED

DSA: 6090

Closes: 1111106

CVEs referenced: CVE-2025-24293 CVE-2025-55193

Binary debdiffs: all

Lintian issues: all

reform-tools 1.71-2+deb13u1 Installability problems ACCEPTED

Reason: fix building lpc with Linux >= 6.17

Request: 1121809

rlottie 0.1+dfsg-4.2+deb13u1 Installability problems ACCEPTED

Reason: fix outlying coordinate rejection in FreeType rasteriser [CVE-2025-0634 CVE-2025-53074 CVE-2025-53075]

Request: 1121433

Closes: 1109341

CVEs referenced: CVE-2025-0634 CVE-2025-53074 CVE-2025-53075

Binary debdiffs: armelarmhf

Lintian issues: source

roundcube 1.6.12+dfsg-0+deb13u1 Installability problems ACCEPTED

DSA: 6087

Closes: 1122899

CVEs referenced: CVE-2025-68460 CVE-2025-68461

rsync 3.4.1+ds1-5+deb13u1 Installability problems ACCEPTED

Reason: fix out-of-bounds read via negative array index in sender file list handling [CVE-2025-10158]

Request: 1122068

CVEs referenced: CVE-2025-10158

rust-repro-env 0.4.3-2+b2 Installability problems ACCEPTED

Reason: rebuild with updated rust-sequoia-openpgp

Binary debdiffs: amd64arm64ppc64elriscv64s390x

rust-ripasso-cursive 0.8.0-1+b2 Installability problems ACCEPTED

Distribution mismatch: sid, trixie

Reason: rebuild with updated rust-sequoia-openpgp

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

rust-sequoia-chameleon-gnupg 0.13.1-3+b2 Installability problems ACCEPTED

Reason: rebuild with updated rust-sequoia-openpgp

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

rust-sequoia-git 0.4.0-4+b5 Installability problems ACCEPTED

Reason: rebuild with updated rust-sequoia-openpgp

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

rust-sequoia-keystore-server 0.2.0-1+b4 Installability problems ACCEPTED

Reason: rebuild with updated rust-sequoia-openpgp

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

rust-sequoia-octopus-librnp 1.11.1-4+b3 Installability problems ACCEPTED

Reason: rebuild with updated rust-sequoia-openpgp

rust-sequoia-openpgp 2.0.0-2+deb13u1 Installability problems ACCEPTED

Reason: fix buffer underflow in aes_key_unwrap [CVE-2025-67897]

Request: 1123726

Closes: 1122582

CVEs referenced: CVE-2025-67897

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

Lintian issues: amd64arm64armelarmhfi386ppc64elriscv64s390x

rust-sequoia-sop 0.37.2-1+b3 Installability problems ACCEPTED

Reason: rebuild with updated rust-sequoia-openpgp

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

rust-sequoia-sq 1.3.1-2+b2 Installability problems ACCEPTED

Reason: rebuild with updated rust-sequoia-openpgp

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

rust-sequoia-sqv 1.3.0-3+b2 Installability problems ACCEPTED

Reason: rebuild with updated rust-sequoia-openpgp

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

rust-sudo-rs 0.2.5-5+deb13u1 Installability problems ACCEPTED

DSA: 6052

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

sash 3.8-7+b7 Installability problems ACCEPTED

Reason: rebuild with updated glibc

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

sash 3.8-7+b5 Installability problems ACCEPTED

Reason: rebuild with updated glibc

sbuild 0.89.3+deb13u4 Installability problems ACCEPTED

Reason: lib/Sbuild/Build.pm: preserve TMPDIR for piuparts; obey $TMPDIR for autopkgtest dsc mkdtemp

Request: 1124104

Closes: 1119344 1121503

Lintian issues: all

sbuild 0.89.3+deb13u3 Installability problems ACCEPTED

This upload was superseded by a more current one.

Reason: lib/Sbuild/Build.pm: preserve TMPDIR for piuparts; obey $TMPDIR for autopkgtest dsc mkdtemp

Request: 1124104

Closes: 1119344 1121503

sbuild 0.89.3+deb13u2 Installability problems ACCEPTED

This upload was superseded by a more current one.

Reason: explicitly select the sbuild-build-depends-main-dummy package architecture; preserve TMPDIR when running autopkgtest

Request: 1121547

Closes: 1119344 1121503

smb4k 4.0.0-1+deb13u1 Installability problems ACCEPTED

DSA: 6092

Closes: 1122381

CVEs referenced: CVE-2025-66002 CVE-2025-66003

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

snapd 2.68.3-3+b4 Installability problems ACCEPTED

Reason: rebuild with updated glibc

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

snapd 2.68.3-3+b3 Installability problems ACCEPTED

Reason: rebuild with updated glibc

sogo 5.12.1-3+deb13u1 Installability problems ACCEPTED

Reason: fix cross-site scripting issues [CVE-2025-63498 CVE-2025-63499]

Request: 1124367

Closes: 1121952

CVEs referenced: CVE-2025-63498 CVE-2025-63499

strongswan 6.0.1-6+deb13u2 Installability problems ACCEPTED

DSA: 6041

CVEs referenced: CVE-2025-62291

suricata 1:7.0.10-1+deb13u2 Installability problems ACCEPTED

Reason: fix verdict logging bounds checks [CVE-2025-64330]; fix various logging stack overflows [CVE-2025-64331 CVE-2025-64332 CVE-2025-64333 CVE-2025-64344]

Request: 1123572

CVEs referenced: CVE-2025-64330 CVE-2025-64331 CVE-2025-64332 CVE-2025-64333 CVE-2025-64344

Binary debdiffs: amd64

survex 1.4.17-1+deb13u1 Installability problems ACCEPTED

Reason: fix the width of the "find stations" search box to make it actually usable again

Request: 1120490

Closes: 1109835

swift 2.35.1-0+deb13u1 Installability problems c-i failed: swift/2.35.1-0+deb13u1 [riscv64] ACCEPTED

DSA: 6056

Closes: 1120057

Binary debdiffs: all

swupdate 2024.12.1+dfsg-3+deb13u1 Installability problems ACCEPTED

Reason: fix suricatta reboot-mode signalling via progress interface

Request: 1120908

Closes: 1118485

symfony 6.4.21+dfsg-2+deb13u1 Installability problems ACCEPTED

Reason: fix PATH_INFO parsing [CVE-2025-64500]; drop failing Finder testsuite data entries

Request: 1120661

CVEs referenced: CVE-2025-64500

Lintian issues: allsource

thunderbird 1:140.6.0esr-1~deb13u1 Installability problems ACCEPTED

DSA: 6081

Lintian issues: i386riscv64source

thunderbird 1:140.5.0esr-1~deb13u1 Installability problems ACCEPTED

This upload was superseded by a more current one.

DSA: 6059

Lintian issues: i386riscv64

tini 0.19.0-3+b5 Installability problems ACCEPTED

Reason: rebuild with updated glibc

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

tini 0.19.0-3+b4 Installability problems ACCEPTED

Reason: rebuild with updated glibc

tripwire 2.4.3.7-6+b12 Installability problems ACCEPTED

Reason: rebuild with updated glibc

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

tripwire 2.4.3.7-6+b10 Installability problems ACCEPTED

Reason: rebuild with updated glibc

tryton-sao 7.0.28+ds1-1+deb13u2 Installability problems ACCEPTED

DSA: 6061

tryton-server 7.0.30-1+deb13u1 Installability problems ACCEPTED

DSA: 6064

tsocks 1.8beta5+ds1-3+b5 Installability problems ACCEPTED

Reason: rebuild with updated glibc

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

tsocks 1.8beta5+ds1-3+b4 Installability problems ACCEPTED

Reason: rebuild with updated glibc

tzsetup 1:0.132+deb13u1 Installability problems ACCEPTED

Reason: fix timezone for Argentina and Ukraine

Request: 1124111

µdebs: only

Closes: 1111332

unbound 1.22.0-2+deb13u1 Installability problems ACCEPTED

DSA: 6071

Closes: 1121446

CVEs referenced: CVE-2025-11411

user-mode-linux 6.12um1+b11 Installability problems ACCEPTED

Reason: rebuild with Linux 6.12.63-1

Binary debdiffs: amd64i386

user-mode-linux 6.12um1+b10 Installability problems ACCEPTED

Reason: rebuild with Linux 6.12.57-1

vlc 3.0.22-0+deb13u1 Installability problems ACCEPTED

DSA: 6082

Binary debdiffs: allamd64arm64armelarmhfi386ppc64elriscv64s390x

Lintian issues: source

webkit2gtk 2.50.4-1~deb13u1 Installability problems ACCEPTED

DSA: 6083

Binary debdiffs: allamd64arm64armelarmhfi386ppc64elriscv64s390x

webkit2gtk 2.50.3-1~deb13u1 Installability problems ACCEPTED

This upload was superseded by a more current one.

DSA: 6074

Binary debdiffs: allamd64arm64armelarmhfi386ppc64elriscv64s390x

webkit2gtk 2.50.2-1~deb13u1 Installability problems ACCEPTED

This upload was superseded by a more current one.

DSA: 6070

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

wordpress 6.8.3+dfsg1-0+deb13u1 Installability problems ACCEPTED

DSA: 6091

CVEs referenced: CVE-2025-58246 CVE-2025-58674

Binary debdiffs: all

xen 4.20.2+7-g1badcf5035-0+deb13u1 Installability problems ACCEPTED

DSA: 6068

Closes: 1105193 1120075

CVEs referenced: CVE-2024-28956 CVE-2024-36350 CVE-2024-36357 CVE-2025-27465 CVE-2025-27466 CVE-2025-58142 CVE-2025-58143 CVE-2025-58144 CVE-2025-58145 CVE-2025-58147 CVE-2025-58148 CVE-2025-58149

Binary debdiffs: amd64arm64

yorick-gy 0.0.6-1~deb13u1 Installability problems ACCEPTED

Reason: fix GIR module version loading for Gtk/Gdk; switch to multiarch-friendly libgirepository-1.0-dev build-dependency; incorporate GCC-14/15 build fixes; update watch file and metadata

Request: 1121184

Lintian issues: source

zsh 5.9-8+b18 Installability problems ACCEPTED

Reason: rebuild with updated glibc

Binary debdiffs: amd64arm64armelarmhfi386ppc64elriscv64s390x

zsh 5.9-8+b16 Installability problems ACCEPTED

Reason: rebuild with updated glibc, pcre