Debian (E)LTS report for May 2025

2025-06-01 Thread Lee Garrett
stretch to be less work. I plan on releasing the packages once the CVEs are fixed in all ELTS releases. Thanks to our sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team

Re: Debian (E)LTS report for April 2025

2025-05-18 Thread Lee Garrett
(resending as I lost the CC on the first reply) On 13/05/2025 13:55, Adrian Bunk wrote: On Tue, May 13, 2025 at 01:02:30PM +0200, Lee Garrett wrote: ... I also prepared an update for Thunderbird fixing the following issues: - CVE-2025-2817 - CVE-2025-4082 - CVE-2025-4083 - CVE-2025-4087 - CVE

Debian (E)LTS report for April 2025

2025-05-13 Thread Lee Garrett
- CVE-2025-4083 - CVE-2025-4087 - CVE-2025-4091 - CVE-2025-4093 - CVE-2025-3523 - CVE-2025-3522 - CVE-2025-2830 Thanks to our sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team

Debian (E)LTS report for March 2025

2025-04-05 Thread Lee Garrett
ating! Regards, Lee Garrett, Debian LTS Team

Debian (E)LTS report for February 2025

2025-03-05 Thread Lee Garrett
E-2024-56326 I also worked on fixing CVE-2024-11079 in ansible/bullseye, that however introduced regressions and needs more work. Thanks to our sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team

Debian (E)LTS report for January 2025

2025-02-12 Thread Lee Garrett
the autopkgtests in the process. Thanks to our sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team [1] https://tracker.debian.org/news/1600965/accepted-ansible-core-21418-0deb12u2-source-into-proposed-updates/ [2] https://bugs.debian.org/

Debian (E)LTS report for December 2024

2025-01-02 Thread Lee Garrett
lease 2.14.18 (which fixes CVE-2024-8775 and CVE-2024-9902), and also manually patched CVE-2024-11079. For ansible bullseye I also started patching the latter CVE. Thanks to our sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team

Debian (E)LTS report for November 2024

2024-12-04 Thread Lee Garrett
onsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team

Debian (E)LTS report for October 2024

2024-11-11 Thread Lee Garrett
searchers of the two vulnerabilities who have provided me with a test environment to verify the functionality of the backport. I'm also in the process backporting the last two CVE patches for buster. Thanks to our sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team

Debian LTS report for August 2024

2024-09-04 Thread Lee Garrett
o our sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team [0] https://bugs.debian.org/1079941 [1] https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2024q1/017430.html

Debian LTS report for July 2024

2024-08-02 Thread Lee Garrett
cornercases when using ftf[1] VMs with autopkgtest, and found a rather intricate bug in autopkgtest that I reported in [2]. I fixed a bug in the freexian CLI when displaying available packages. [3] Thanks to our sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett

Re: Debian LTS report for June 2024

2024-07-11 Thread Lee Garrett
Hi Chime, On 11.07.24 19:18, Chime Hart wrote: Hi Lee-and-All: I am not a programmer, nor a developer, just an enthusiastic Linux fan. What I am wondering is how do you decide what packages to work on? LTS work is mainly sponsored by Freexian, who in turn has customers paying for long-term s

Debian LTS report for June 2024

2024-07-11 Thread Lee Garrett
-4237 Which I will upload once I have fixed the remaining CVEs. Thanks to our sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team [0] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1069891 [1] https://bugs.debian.org/cgi-bin/bugreport.cgi

Debian (E)LTS report for May 2024

2024-06-02 Thread Lee Garrett
t due to commitments on the Mini-Debconf Berlin [0]. I intend to release the update in the next week. Thanks to our sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team [0] https://wiki.debian.org/DebianEvents/de/2024/MiniDebconfBerlin

Debian (E)LTS report for April 2024

2024-05-04 Thread Lee Garrett
-14 layout to ease with collaboration. The updates for bullseye and buster will be released shortly. Thanks to our sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team

Debian LTS report for November 2023

2023-12-12 Thread Lee Garrett
Hi everyone, I spent time on samba, and will hopefully be able to resume work on it beginning of next week. Regards, Lee Garrett, Debian LTS Team

Debian (E)LTS report for October 2023

2023-11-02 Thread Lee Garrett
ng an update for bullseye. Regards, Lee Garrett, Debian LTS Team

Debian LTS report for September 2023

2023-10-03 Thread Lee Garrett
] https://listman.redhat.com/archives/libguestfs/2023-September/thread.html#32556 Regards, Lee Garrett, Debian LTS Team

Debian LTS report for August 2023

2023-09-09 Thread Lee Garrett
https://lists.debian.org/debian-lts/2023/08/msg00027.html [1] https://github.com/ansible-collections/community.libvirt/issues/156 https://github.com/ansible-collections/community.libvirt/pull/157 [2] https://tracker.debian.org/news/1460347/ Regards, Lee Garrett, Debian LTS Team

samba status update

2023-08-22 Thread Lee Garrett
Hello everyone, I'll summarize the status of the recent samba discussion about support, it's package status, and functional tests in this mail. == samba support scope & discussions == The

Debian (E)LTS report for June 2023

2023-08-13 Thread Lee Garrett
tests that involve multiple VMs (and possibly different OSes) interacting with each other, as this currently can't be easily achieved in autopkgtest. Thanks to the sponsors for financing this work, and to Freexian for coordinating! [0] https://tracker.debian.org/pkg/rhsrvany Regards

Call for your samba config

2023-07-27 Thread Lee Garrett
Hi, regarding the netlogon fix for samba in LTS, there's a fix underway. I'm however asking LTS users to send me info about their setup. This should include: - their smb.conf (redacting any sensitive info of course) - role of the samba server (e.g. AD DC, NT4-style DC, just file server, etc.)

Debian LTS report for June 2023

2023-07-11 Thread Lee Garrett
In June I worked on samba QA, building a testing framework, implemented with ansible and libvirt/qemu, to test samba against common Windows systems. Thanks to the sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team

Debian LTS report for March 2023

2023-04-08 Thread Lee Garrett
In March I worked on the following issues for samba: - CVE-2020-10704 - CVE-2020-10730 - CVE-2020-10745 - CVE-2020-10760 - CVE-2020-14303 I have also reviewed a DLA notice written by Bastien. Thanks to the sponsors for financing this work, and to Freexian for coordinating! Regards, Lee

Debian LTS report for February 2023

2023-03-02 Thread Lee Garrett
In February I worked on the following issues for apache2: - CVE-2022-37436 - CVE-2021-33193 I have just uploaded the final update 2.4.38-3+deb10u9. I also worked on samba: - CVE-2016-2124 - CVE-2019-10218 - CVE-2019-14833 - CVE-2019-14847 - CVE-2019-14861 - CVE-2019-14870 - CVE-2019-14902 - CVE-

Debian LTS report for January 2023

2023-02-20 Thread Lee Garrett
In January I worked on the following issues for apache2: - CVE-2006-20001 - CVE-2022-36760 - CVE-2022-37436 (WIP) Thanks to the sponsors for financing this work, and to Freexian for coordinating! Regards, Lee

LTS work - December 2021 / Jan 2022

2022-02-04 Thread Lee Garrett
Hi everyone, In December I worked for 11.45 hours on: - Fixing a regression introduced by the fix of CVE-2019-10206. - Updating the patch for CVE-2020-10684, as it was incomplete. In January I did not work on LTS. Greetings, Lee

Re: LTS work - November 2021

2021-12-12 Thread Lee Garrett
On 12/12/2021 01:21, Utkarsh Gupta wrote: > Hiya, > > On Sun, Dec 12, 2021 at 3:42 AM Lee Garrett wrote: >> In November I worked for 9 hours on: >> - triaging ansible CVEs >> - fixing CVE-2019-10206, CVE-2019-14856

LTS work - November 2021

2021-12-11 Thread Lee Garrett
Hi everyone, In November I worked for 9 hours on: - triaging ansible CVEs - fixing CVE-2019-10206, CVE-2019-14856, CVE-2020-10684 in stretch Greetings, Lee

Re: Security updates of ansible in buster and stretch

2021-02-01 Thread Lee Garrett
Hi Markus, On 28/01/2021 00:02, Markus Koschany wrote: > Hello Lee, hello security team, > > I have been working on security updates of ansible in Stretch and my intention > was to fix the remaining issues in Buster as well. However testing those > upstream patches proved to be rather difficult i

Re: Jessie update of ansible (minor security issues)?

2019-08-31 Thread Lee Garrett
Hi Mike! (please don't CC Michael, he is not active on the ansible package anymore and asked to be removed from uploaders.) On 30/08/2019 12:09, Mike Gabriel wrote: > The Debian LTS team recently reviewed the security issue(s) affecting your > package in Jessie: > https://security-tracker.debian.