Control: tags -1 pending Thanks On Wed, May 27, 2026 at 04:55:19PM +0200, Salvatore Bonaccorso wrote: > Source: radvd > X-Debbugs-Cc: [email protected], Debian Security Team > <[email protected]> > .... > > If you fix the vulnerability please also make sure to include the > CVE (Common Vulnerabilities & Exposures) id in your changelog entry. >
<patch shows="that CVE id is in changelog> commit 341399779de94ed0797c9dad488d17dade147c63 Author: Geert Stappers <[email protected]> Date: Mon Jun 8 16:18:30 2026 +0200 Documented the CVE that Upstream release fixes modified: debian/changelog diff --git a/debian/changelog b/debian/changelog index aa25f98..853734c 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,6 +1,8 @@ radvd (1:2.21-1) UNRELEASED; urgency=medium * New upstream release + * Upstream release fixes CVE-2026-48715, Stack Buffer Overflow + in radvdump Route Information Option Parser, closes: #1138049 [Santiago Vila] * Disable build test in d/rules, not in d/source/lintian-overrides </patch> Groeten Geert Stappers [0] https://security-tracker.debian.org/tracker/CVE-2026-48715 https://www.cve.org/CVERecord?id=CVE-2026-48715 -- Silence is hard to parse

