dovecot (1:2.4.5+dfsg1-2) unstable; urgency=medium . * [8b432dd] lib: xxh64: fix byte ordering issue on big-endian systems (Closes: #1146449) * [45b5e14] Fix loong64 ftbfs (Closes: #1146490) dovecot (1:2.4.5+dfsg1-1) unstable; urgency=medium . * [e470328] New upstream version 2.4.5+dfsg1 (Closes: #1146018) - https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html - CVE-2026-27852 - DoS by sending mail with bad header. - CVE-2026-33263 - submission-login: Panic when mail_max_userip_connections is reached - CVE-2026-33604 - SMTP Smuggling via Missing Dot-Stuffing After Bare Carriage Return. - CVE-2026-33605 - managesieve-login: Pre-auth crash. - CVE-2026-33606 - dsync: Mail content can cause dsync protocol injection. - CVE-2026-33607 - Dovecot IMAP LIST match_sub() Exponential Backtracking - CPU Denial of Service. - CVE-2026-40013 - pigeonhole: Stack Buffer Underflow in Pigeonhole ManageSieve CHECKSCRIPT/PUTSCRIPT. - CVE-2026-40014 - Whenever a mail client issues a THREAD command on the affected mailbox, this can cause degradation or denial of service for IMAP. - CVE-2026-40015 - An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can intermittently cause an out-of-bounds read and crash the process. - CVE-2026-40017 - IMAP THREAD O(M³) CPU DoS via CRC32 Hash Collision in strmap - CVE-2026-40018 - MySQL multi-byte escaping wrong. - CVE-2026-40019 - v2.4.3 regression: managesieve-login pre-auth infinite loop. - CVE-2026-40203 - IMAP Compression Can Reveal Whether a Small Synced Email Body Matches Sender-Chosen Text. - CVE-2026-40204 - acl: lda_mailbox_autocreate can bypass acl restrictions. - CVE-2026-40205 - OAuth2 passdb scope enforcement bypass via OR semantics in remote validation path - CVE-2026-42007 - Sieve editheader RCE. An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. - CVE-2026-42008 - XCLIENT FORWARD= bare token not namespaced, allows nopassword injection via trusted proxy. - CVE-2026-42391 - imap: Pre-login memory/CPU growth with ID command. - CVE-2026-42392 - imap-urlauth leaks memory into user-visible error messages. - CVE-2026-42393 - doveadm_password or api key length can still be leaked with timing comparisons. - CVE-2026-42395 - Single NUL-Byte XCLIENT FORWARD Payload Crashes. A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following login attempt. - CVE-2026-52681 - Sieve resource usage tracking lost when active script changes. - CVE-2026-52687 - IMAP: COMPRESS ZSTD can cause excessive memory usage. - CVE-2026-73208 - auth: db-oauth2: aud claim used as fallback for missing scope claim. - CVE-2026-73209 - imap-login crash: Self-recursion on zero-output decompress chunks. * [0f045ed] refresh patches * [43cc0a0] d/copyright: reflect upstream's removal of src/lib-otp * [e781a92] update dovecot-mysql transitional package metadata grandorgue (3.17.3-1) unstable; urgency=medium . * New upstream version 3.17.3 * Add libcpptrace-dev to Build-Depends. Also do not try to use vendored cpptrace source. * Bump to debhelper compat level 14 libapache2-mod-auth-openidc (2.4.20.3-1) unstable; urgency=medium . * New upstream version 2.4.20.3 libapache2-mod-auth-openidc (2.4.20.2-3) unstable; urgency=medium . * fix riscv64 tests?! libapache2-mod-auth-openidc (2.4.20.2-2) unstable; urgency=medium . * Fix riscv64 tests libapache2-mod-auth-openidc (2.4.20.2-1) unstable; urgency=medium . [ Alexandre Detiste ] * fix dh_cruft glitch . [ Moritz Schlarb ] * New upstream version 2.4.20.2 libnginx-mod-js (1.0.1-1) unstable; urgency=medium . * New upstream version 1.0.1 * Drop upstream patch * Improve njs cli test a little. libnginx-mod-js (1.0.0-4) unstable; urgency=medium . * B-D libedit-dev. Closes: #1146139. metalog (20260902-1) unstable; urgency=medium . * New upstream release. * Update standards version to 4.7.4; no changes needed. pcre2 (10.48-2) unstable; urgency=high . * remove unnecessary libS logic from pcre2-config.in (closes: #1146381) pcre2 (10.48-1) unstable; urgency=high . * New upstream release . pcre2 (10.48~rc1-1) experimental; urgency=medium . * New upstream version (RC, for testing) . pcre2 (10.47-2) experimental; urgency=medium . * Undo symbol versioning at least for now (Closes: #1119027) . pcre2 (10.47-1) experimental; urgency=medium . * New upstream version (Closes: #902060) pcre2 (10.47-2) experimental; urgency=medium . * Undo symbol versioning at least for now (Closes: #1119027) pcre2 (10.47-1) experimental; urgency=medium . * New upstream version (Closes: #902060) rust-hamming-bitwise-fast (1.1.0-1) unstable; urgency=medium . * Package hamming-bitwise-fast 1.1.0 from crates.io using debcargo 2.8.4 rust-rootasrole (4.0.1-1) unstable; urgency=medium . * Package rootasrole 4.0.1 from crates.io using debcargo 2.8.3 rust-rootasrole (4.0.0+dfsg-1) unstable; urgency=medium . * Package rootasrole 4.0.0 from crates.io using debcargo 2.8.3 * Initial release (Closes: #1109792) scilab (2024.1.0+dfsg1-4) unstable; urgency=medium . * Building against libmatio/1.6 (Closes: #1146175) unrardll (0.1.7+ds1-6) unstable; urgency=medium . * Limit architectures that debusine builder works unrardll (0.1.7+ds1-5) unstable; urgency=medium . * Explicitly drop Python 3.13 support unrardll (0.1.7+ds1-4) unstable; urgency=medium . * Rebuild to drop Python 3.13 support wxwidgets3.2 (3.2.11+dfsg1-1) unstable; urgency=medium . * Exclude 3rdparty/pcre when repacking upstream tarball (Closes: #1146114) * New repack to exclude 3rdparty/pcre * Patch image sample to fix autopkgtests w/ GCC 16 (Closes: #1146456)