Debian E/LTS, July 2026

During this month, I have worked on the following tasks for Debian LTS and ELTS.
Thanks to Freexian and sponsors for making this possible [0].

dnsmasq

  • Investigate CVE-2026-2291, CVE-2026-4890, CVE-2026-4891, CVE-2026-4892,
    CVE-2026-4893 and CVE-2026-5172 for ELTS
  • CVE-2026-5172 not-affected on buster & stretch, marked as such
    extract_addresses() lacks the vulnerable generic-RR/rrblock path
  • CVE-2026-4890 and CVE-2026-4891 not-affected on stretch, marked as such
    DNSSEC support was disabled in 2.76-5+deb9u5
  • Cherry-pick and backport patches for the other 3-5 CVEs (from DLA-4625-1)
  • Fix autopkgtests and adopt tests/environment to buster and stretch
  • Getting the buster/stretch ELTS branches reviewed & fixed (thanks arnaudr!)
  • Final testing/validation/installability/migration of the ELTS packages
  • Published the corresponding ELA-1772-1 for buster/stretch:
    https://www.freexian.com/lts/extended/updates/ela-1772-1-dnsmasq/

Misc

  • Participated in the monthly LTS/ELTS team meeting.
  • Debian LTS team BoF at DebConf 2026

Cheers,
Lukas

[0] https://www.freexian.com/lts/debian/#sponsors