Thorsten Alteholz: My Debian Activities in April 2026
Debian LTS/ELTS
This was my hundred-forty-second month that I did some work for the Debian LTS initiative, started by Raphael Hertzog at Freexian.
During my allocated time I uploaded or worked on:
- [DLA 4530-1] gst-plugins-bad1.0 security update to fix two CVEs related to denial of service or execution of arbitrary code if a malformed media file is opened.
- [DLA 4544-1] ntfs-3g to fix one CVE related to local root privilege escalation.
- [DLA 4545-1] packagekit security update to fix one CVE related to local privilege escalation.
- [DLA 4547-1] gimp security update to fix three CVEs related to denial of service or execution of arbitrary code if a malformed PSP, JPEG 2000 or PSD file is opened.
- [ELA-1682-1] gst-plugins-bad1.0 security update to fix two CVEs in Buster and Stretch related to denial of service or execution of arbitrary code.
- [ELA-1689-1] ntfs-3g security update to fix one CVE in Buster and Stretch related to local root privilege escalation..
- [ELA-1693-1] pakagekit security update to fix one CVE in Buster and Stretch related to local privilege escalation.
- [#1126167] bookworm-pu upload of zvbi
- [#1126273] bookworm-pu upload of taglib
- [#1126370] bookworm-pu upload of libuev
- [libcoap3] upload to sid to fix two CVEs related to out-of-bounds read and stacked based buffer overflow.
- [#1134340] trixie-pu bug for libcoap3 to fix two CVEs in Trixie.
- [cups] upload to sid to fix six CVEs.
- indi-apogee to experimental.
- indi-nexdome to experimental.
- libahp-xc to unstable.
- libcoap3 to unstable.
- osmo-iuh to unstable.
- bottlerocket to unstable.
- cd5 to unstable.
- usb-modeswitch-data to unstable.
- libpicohttpparser to unstable (sponsored upload for Joachim Zobel.
The following contributors got their Debian Developer accounts in the last two months: