There are 5 open security issues in buster.
commit 67164b70a9547b864c0253f28cc215dbc0777d21
Author: Sam Hartman <hartmans@debian.org>
Date: Mon Jun 8 09:48:34 2026 -0600
Upstream commit f5bbfa4 to use openssl facilities to verify certificates; needed to avoid discarding const qualifier from Openssl 4.0 patch
commit 451d03b4c426089d8d88378b5bbd998bcbf952f5
Author: Sam Hartman <hartmans@debian.org>
Date: Mon Jun 8 09:21:29 2026 -0600
Upstream patch for OpenSSL 4.0 compatibility, Closes: #1138466
commit 93070a96c5da3a84d066ed88916286f34634b7ae
Author: Sam Hartman <hartmans@debian.org>
Date: Mon Jun 8 07:23:25 2026 -0600
Remove lintian tag that ldap plugin is linked against libc6; no longer needed
commit 6f89ca77e5eaa5d26840c4a3110e25ad77453781
Author: Sam Hartman <hartmans@debian.org>
Date: Mon May 25 16:33:55 2026 -0600
Fix C23 use of strchr, Closes: #1128877
commit ed2f768c3cedeca6ee1cd6c900bf4cb57095b567
Merge: 8e1a790 b0b5c75
Author: Salvatore Bonaccorso <carnil@debian.org>
Date: Tue May 12 20:18:46 2026 +0200
Merge branch 'debian-1135317' into 'master'
Fix two NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356)
See merge request debian/krb5!13
Among the 12 debian patches available in version 1.22.1-2.1 of the package, we noticed the following issues: