During this month, I have worked on the following tasks for Debian LTS and ELTS.
Thanks to Freexian and sponsors for making this possible [0].
dnsmasq
- Investigate CVE-2026-2291, CVE-2026-4890, CVE-2026-4891, CVE-2026-4892,
CVE-2026-4893 and CVE-2026-5172 for ELTS - CVE-2026-5172 not-affected on buster & stretch, marked as such
extract_addresses() lacks the vulnerable generic-RR/rrblock path - CVE-2026-4890 and CVE-2026-4891 not-affected on stretch, marked as such
DNSSEC support was disabled in 2.76-5+deb9u5 - Cherry-pick and backport patches for the other 3-5 CVEs (from DLA-4625-1)
- Fix autopkgtests and adopt tests/environment to buster and stretch
- Getting the buster/stretch ELTS branches reviewed & fixed (thanks arnaudr!)
- Final testing/validation/installability/migration of the ELTS packages
- Published the corresponding ELA-1772-1 for buster/stretch:
https://www.freexian.com/lts/extended/updates/ela-1772-1-dnsmasq/
Misc
- Participated in the monthly LTS/ELTS team meeting.
- Debian LTS team BoF at DebConf 2026
Cheers,
Lukas
[0] https://www.freexian.com/lts/debian/#sponsors