LTS

bind9

  • Release DLA-4725-1 to fix CVE-2026-3039, CVE-2026-3592, CVE-2026-5946, CVE-2026-5950, CVE-2026-10723, CVE-2026-10822, CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204 and CVE-2026-13321 in bullseye and bookworm.

libssh2

  • Mark CVE-2026-55200, CVE-2026-55199, CVE-2026-66033 and CVE-2026-66035 as not vulnerable in bullseye.

  • Patches ready for release. Waiting for trixie-pu being accepted.

python-httplib2

  • Release patch for CVE-2026-59939 for trixie (DSA 6441-1).

  • Release DLA 4747-1 to fix CVE-2021-21240 and CVE-2026-59939 in bullseye.

  • Release DLA 4748-1 to fix CVE-2026-59939 in bookworm.

pyasn1

  • Work on CVE-2026-59884, CVE-2026-59885 and CVE-2026-59886 patches.

  • Send trixie-pu #1145581.

  • Patches ready for release. Waiting for trixie-pu being accepted.

ELTS

libssh2

  • Mark CVE-2026-66035, CVE-2026-66034 and CVE-2026-58050 as not affected for Buster and Stretch.

  • Patches ready for release.

pyasn1

  • Work on CVE-2026-59884, CVE-2026-59885 and CVE-2026-59886 patches.

  • Patches ready for release. Waiting for trixie-pu.

python-httplib2

  • Release ELA_1814-1 to fix CVE-2020-11078, CVE-2021-21240 and CVE-2026-59939 for 0.9.2+dfsg-1+deb9u1 (stretch) and 0.11.3-2+deb10u1 (buster).

Debian Python Team

restrictedpython

  • New upstream release 8.4 and cosmetic changes.

python-scp

  • New upstream release 0.16.1 and cosmetic changes.

citecproc-py

  • New upstream release 0.10.1 and cosmetic changes.

jpy

  • Create bug #1145066 to build package against python3.15.

sabctools

  • File #1144249 bug: “sabctools: errors when built against python 3.15”.

ttconv

python-setproctitle

  • Fix #1145091 bug: “python-setproctitle: FTBFS building against python 3.15”.

  • Add cosmetic changes.

python-git

  • New upstream release 3.1.61-1. Fix several security bugs: CVE-2026-67323, CVE-2026-67324, CVE-2026-67325, CVE-2026-67322, CVE-2026-69097, CVE-2026-73623, CVE-2026-73624, CVE-2026-73625, CVE-2026-73622, CVE-2026-73621, CVE-2026-73619, CVE-2026-73620, CVE-2026-76217, CVE-2026-76218, CVE-2026-76219, CVE-2026-76220, CVE-2026-76221, CVE-2026-76222, CVE-2026-78675, CVE-2026-78676, CVE-2026-78677, CVE-2026-78678 and CVE-2026-78679 (Closes: #1143454, #1143602, #1144344, #1144929, #1145672).

Games team

bsdgames

  • Review !9.

openyahtzee

  • Review !2.

Other Packages

note

DFSG

  • rust-test-tag: Review it. It was accepted.

  • rust-icu-provider-adapters: Review it. It was accepted.

  • rust-p9: Review it. It was accepted.

  • rust-icu: Review it. It was accepted.

  • rust-sed: Review it. It was accepted.

  • rust-async-bincode: Review it. It was accepted.

  • libkrun: Review it. It was accepted.

  • rust-inferno: Review it. It was accepted.

  • rust-crc16: Review it. It was accepted.

  • rust-redis: Review it. It was accepted.

  • rust-ghac: Review it. It was accepted.

  • rust-bisync: Review it. It was accepted.

  • rust-mmap-io: Review it. It was accepted.

  • rust-bzip2-rs: Review it. It was accepted.

  • rust-ml-dsa: Review it. It was accepted.

  • rust-muncher: Review it. It was rejected.

  • rust-jiff-core: Review it. It was accepted.

  • rust-ossl: Review it. It was accepted.

  • rust-tiny-xlib: Review it. It was accepted.

  • rust-bincode-1: Review it. It was rejected.

  • rust-graviola: Review it. It was rejected.

Sponsorship

  • sandlock: New upstream release 5.1.1. Kudos to Håvard F. Aasen havard.f.aasen@pfft.no.

  • impacket: New upstream release 0.13.1. Kudos to Lester Guerzon lester@guerzon.net.

  • pypsrp: Introduce version 0.9.1 to Debian. Kudos to Lester Guerzon lester@guerzon.net.

  • mitmprox: Review performed.

  • rapidfuzz: Upload new usptream release 3.14.5+ds-1 to unstable. Kudos to Carl Keinath carl.keinath@gmail.com.

  • rayforge: Review performed.

  • python-asysocks: Review performed.

  • python-deepl: Review performed.