Version 3.1.5-1 of golang-github-pion-dtls-v3 is marked for autoremoval from testing on Sat 17 Oct 2026. It depends (transitively) on golang-github-rogpeppe-go-internal, affected by #1146612. You should try to prevent the removal by fixing these RC bugs.
CVE-2026-54908:
Pion DTLS is a Go implementation of Datagram Transport Layer Security. Versions prior to 3.1.4 are vulnerable to Remote Denial of Service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message. This issue has been fixed in version 3.1.4.
CVE-2026-54908:
Pion DTLS is a Go implementation of Datagram Transport Layer Security. Versions prior to 3.1.4 are vulnerable to Remote Denial of Service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message. This issue has been fixed in version 3.1.4.
Among the 1 debian patch
available in version 3.1.5-1 of the package,
we noticed the following issues:
1 patch
where the metadata indicates that the patch has not yet been forwarded
upstream. You should either forward the patch upstream or update the
metadata to document its real status.