-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 16 Oct 2024 08:07:46 -0400 Source: golang-github-containers-buildah Architecture: source Version: 1.37.4+ds1-1 Distribution: unstable Urgency: medium Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org> Changed-By: Reinhard Tartler <siretart@tauware.de> Closes: 1084980 Changes: golang-github-containers-buildah (1.37.4+ds1-1) unstable; urgency=medium . * New upstream release, Closes: #1084980 Fixes: CVE-2024-9407, CVE-2024-9341: validate "bind-propagation" flag settings Fixes: https://issues.redhat.com/browse/RHEL-61147 Fixes: https://issues.redhat.com/browse/RHEL-61145 * Backport upstream patch for CVE-2024-9675 * debian/control: tighten dependencies on containers/common Checksums-Sha1: 2ef833821e768ae8d1a172ba562674b6a8997637 4105 golang-github-containers-buildah_1.37.4+ds1-1.dsc 33294850b8bd28c79241049497030f1a88890202 984988 golang-github-containers-buildah_1.37.4+ds1.orig.tar.xz ab05e9d9eef6b0d65bf7515fd24d2d5a4031a8ad 11108 golang-github-containers-buildah_1.37.4+ds1-1.debian.tar.xz Checksums-Sha256: 75181af27559c6931869599e261135fde028276ef66ed6db90718040c5d0c513 4105 golang-github-containers-buildah_1.37.4+ds1-1.dsc 998e51b09586debf271c675c2c05de6caf77937d3cc39b46d7b0e6e5ff5e095f 984988 golang-github-containers-buildah_1.37.4+ds1.orig.tar.xz 7428e3443fb19099d6f2ebb9e40bd66137d36639c338d5ee73ea580035984c10 11108 golang-github-containers-buildah_1.37.4+ds1-1.debian.tar.xz Files: 1ca0a066449a53d2b2cf242f41a97015 4105 devel optional golang-github-containers-buildah_1.37.4+ds1-1.dsc 73943cce3f583d8242dbddaa84403781 984988 devel optional golang-github-containers-buildah_1.37.4+ds1.orig.tar.xz 4429577d15fdf247de01523997a330fa 11108 devel optional golang-github-containers-buildah_1.37.4+ds1-1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQJIBAEBCgAyFiEEMN59F2OrlFLH4IJQSadpd5QoJssFAmcPrbMUHHNpcmV0YXJ0 QHRhdXdhcmUuZGUACgkQSadpd5QoJssHQxAAmdMxJkt5A1G3kDM2Km9EP5XUEQ0a KUbIsDnuInsQBhwXW6GAi43JW85nfM3F8Y3+oq+y+lrCKUbGmZoQonMYwPJWpALk OgFtoS6JK8n7wgpY/XjcwO4ltsQZFTorog9NSgIOboFNKKS+JQy/xaxwvenQjtso mFdSGFE2qeB8sOXFtpbglLhAFBzaUv26elt0/4lxXmwUry9RCaPxLoEgE2vnprdV +0oRSwAH/joOMSk+1vW+vO6yrQ+f7GPWEb5xlBcLMVI25OrIRUwLfvY0NOdM2uxQ tPJMTVgu3MgGFeCOxRHYN7vXrvj/bi4FVyW90J37bBPsDcJaxReLPjVFftL6DwT6 /Yi6FmskPVvIwG4UdAeJ9GIFNIPBcbJBz2Yl5BpS5FDK3vhloSYuI66HM0CQ9AhJ g0P5I3MQCdKWcsU94XQ33s7r5txxl8MBfwB/rrWTg1p6HCTZLzCwhV/nC/HWOJu3 iniqVBSHLfXUyVKEC10pH0smV8MrQ2Yl+keovR2Gfom2FxgRJRqJ0JJKzTBn+wJi 71sTLy3dEMo88u8aJLuMEfGwrHsGxh/CEDo7/sl0HkeyvtaTfsDVG+bUBiDkfk3i tbRaPzc7dN6HprbeIMZw8x4BrZyqXaJbO2qDSIqHAwlhm/dCaWhuExSVgKsZTHBA ozmvcp7WUey1aUk= =KRSU -----END PGP SIGNATURE-----