<?xml version='1.0' encoding='UTF-8'?>
<updates>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1760712981</id>
    <title>Fix CVE(s): CVE-2025-24813</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: path Equivalence leads to Remote Code Execution and/or
     Information disclosure
     - debian/patches/CVE-2025-24813.patch: Enhance lifecycle of temporary files
       used by partial PUT
     - CVE-2025-24813</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: path Equivalence leads to Remote Code Execution and/or
     Information disclosure
     - debian/patches/CVE-2025-24813.patch: Enhance lifecycle of temporary files
       used by partial PUT
     - CVE-2025-24813</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-20 13:56:02 UTC" />
    <updated date="2025-10-20 13:56:02 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1760712981.html" id="CLSA-2025:1760712981" title="CLSA-2025:1760712981" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="all" name="libtomcat9-embed-java" version="9.0.31-1~deb10u12+tuxcare.els1">
          <filename>libtomcat9-embed-java_9.0.31-1~deb10u12+tuxcare.els1_all.deb</filename>
          <sum type="sha">cbd5aec9b164077d8ada2c0975b75356829b0a90</sum>
        </package>
        <package arch="all" name="libtomcat9-java" version="9.0.31-1~deb10u12+tuxcare.els1">
          <filename>libtomcat9-java_9.0.31-1~deb10u12+tuxcare.els1_all.deb</filename>
          <sum type="sha">d1c0ff69c3a2d6e7ba578277f0b8871fdbb13c0e</sum>
        </package>
        <package arch="all" name="tomcat9" version="9.0.31-1~deb10u12+tuxcare.els1">
          <filename>tomcat9_9.0.31-1~deb10u12+tuxcare.els1_all.deb</filename>
          <sum type="sha">87314267d62656d14d83f13111b07b3e6c1360a9</sum>
        </package>
        <package arch="all" name="tomcat9-admin" version="9.0.31-1~deb10u12+tuxcare.els1">
          <filename>tomcat9-admin_9.0.31-1~deb10u12+tuxcare.els1_all.deb</filename>
          <sum type="sha">a0e9ed1fba473efbfcd86f7aeed09bb4305d915a</sum>
        </package>
        <package arch="all" name="tomcat9-common" version="9.0.31-1~deb10u12+tuxcare.els1">
          <filename>tomcat9-common_9.0.31-1~deb10u12+tuxcare.els1_all.deb</filename>
          <sum type="sha">b1483dd1ef7232bdd0db94e429d306f322bf3351</sum>
        </package>
        <package arch="all" name="tomcat9-docs" version="9.0.31-1~deb10u12+tuxcare.els1">
          <filename>tomcat9-docs_9.0.31-1~deb10u12+tuxcare.els1_all.deb</filename>
          <sum type="sha">b9d2c0816fa6362ce688e6af9c58ae9e734418c5</sum>
        </package>
        <package arch="all" name="tomcat9-examples" version="9.0.31-1~deb10u12+tuxcare.els1">
          <filename>tomcat9-examples_9.0.31-1~deb10u12+tuxcare.els1_all.deb</filename>
          <sum type="sha">993f598a654edfa326b841c5153ee54dd5406329</sum>
        </package>
        <package arch="all" name="tomcat9-user" version="9.0.31-1~deb10u12+tuxcare.els1">
          <filename>tomcat9-user_9.0.31-1~deb10u12+tuxcare.els1_all.deb</filename>
          <sum type="sha">d916902fc70e7ad366a72db9899d3244e8af6854</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1760711358</id>
    <title>Fix CVE(s): CVE-2024-38474, CVE-2024-38475</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: mod_rewrite proxy handler substitution and prefix_stat
     vulnerabilities
     - debian/patches/CVE-2024-38474-38475-*.patch: tighten up prefix_stat and %3f
       handling, add better question mark tracking to avoid UnsafeAllow3F
     - CVE-2024-38474, CVE-2024-38475</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: mod_rewrite proxy handler substitution and prefix_stat
     vulnerabilities
     - debian/patches/CVE-2024-38474-38475-*.patch: tighten up prefix_stat and %3f
       handling, add better question mark tracking to avoid UnsafeAllow3F
     - CVE-2024-38474, CVE-2024-38475</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-20 14:02:40 UTC" />
    <updated date="2025-10-20 14:02:40 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1760711358.html" id="CLSA-2025:1760711358" title="CLSA-2025:1760711358" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="apache2" version="2.4.59-1~deb10u1+tuxcare.els2">
          <filename>apache2_2.4.59-1~deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">9c7a74a194ea840337212f7eb84fa4e05f2c80f7</sum>
        </package>
        <package arch="amd64" name="apache2-bin" version="2.4.59-1~deb10u1+tuxcare.els2">
          <filename>apache2-bin_2.4.59-1~deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">e84170b194839906fd30dd456ecc7839e160137b</sum>
        </package>
        <package arch="all" name="apache2-data" version="2.4.59-1~deb10u1+tuxcare.els2">
          <filename>apache2-data_2.4.59-1~deb10u1+tuxcare.els2_all.deb</filename>
          <sum type="sha">2f7a5595bb54c1849dd6d158d73000002ff51db5</sum>
        </package>
        <package arch="amd64" name="apache2-dev" version="2.4.59-1~deb10u1+tuxcare.els2">
          <filename>apache2-dev_2.4.59-1~deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">8359ab8a5ec9254275a3235f1212e6673e719e5b</sum>
        </package>
        <package arch="all" name="apache2-doc" version="2.4.59-1~deb10u1+tuxcare.els2">
          <filename>apache2-doc_2.4.59-1~deb10u1+tuxcare.els2_all.deb</filename>
          <sum type="sha">8cfcde608a7b65f3afe6abe2738ea2e59438c3a4</sum>
        </package>
        <package arch="amd64" name="apache2-ssl-dev" version="2.4.59-1~deb10u1+tuxcare.els2">
          <filename>apache2-ssl-dev_2.4.59-1~deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">9633ac21eecf085ade3dc9bd9e9e92292d9a95f9</sum>
        </package>
        <package arch="amd64" name="apache2-suexec-custom" version="2.4.59-1~deb10u1+tuxcare.els2">
          <filename>apache2-suexec-custom_2.4.59-1~deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">91195402df7d51c926d99677eec1c8bff9ad5014</sum>
        </package>
        <package arch="amd64" name="apache2-suexec-pristine" version="2.4.59-1~deb10u1+tuxcare.els2">
          <filename>apache2-suexec-pristine_2.4.59-1~deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">572c412ec85fa1131163bffc3424e08458fbf745</sum>
        </package>
        <package arch="amd64" name="apache2-utils" version="2.4.59-1~deb10u1+tuxcare.els2">
          <filename>apache2-utils_2.4.59-1~deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">c41bd92bcc8d261a7ae086bcc996ab16ca12b79a</sum>
        </package>
        <package arch="amd64" name="libapache2-mod-md" version="2.4.59-1~deb10u1+tuxcare.els2">
          <filename>libapache2-mod-md_2.4.59-1~deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">3f180ea79f44acfd5ad1dc7ac3c5bec7b76fc686</sum>
        </package>
        <package arch="amd64" name="libapache2-mod-proxy-uwsgi" version="2.4.59-1~deb10u1+tuxcare.els2">
          <filename>libapache2-mod-proxy-uwsgi_2.4.59-1~deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">9c10a74aaf1a7a86edf725d8176156382df6ff4d</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1760722427</id>
    <title>Fix CVE(s): CVE-2023-44487</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: The HTTP/2 protocol allows a denial of service
     because request cancellation can reset many streams quickly
     - debian/patches/CVE-2023-44487.patch: HTTP/2 - per-iteration
       stream handling limit.
     - CVE-2023-44487</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: The HTTP/2 protocol allows a denial of service
     because request cancellation can reset many streams quickly
     - debian/patches/CVE-2023-44487.patch: HTTP/2 - per-iteration
       stream handling limit.
     - CVE-2023-44487</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-20 14:41:05 UTC" />
    <updated date="2025-10-20 14:41:05 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1760722427.html" id="CLSA-2025:1760722427" title="CLSA-2025:1760722427" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libnginx-mod-http-auth-pam" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>libnginx-mod-http-auth-pam_1.14.2-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">0dcc3556afbe7601d3619ceac110e3e7f1301c23</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-cache-purge" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>libnginx-mod-http-cache-purge_1.14.2-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">c2baf90fe5d718a55678d21e4f51bec3cae4c990</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-dav-ext" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>libnginx-mod-http-dav-ext_1.14.2-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">a54f2c8bd495ad2ee6f9f4e6f444f6ba038a7b17</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-echo" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>libnginx-mod-http-echo_1.14.2-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">d7f351231005df843b39f654b00632faa89e0ead</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-fancyindex" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>libnginx-mod-http-fancyindex_1.14.2-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">ce9b0d6faf8704e10caf18b4c9ebd81bd4fdee1d</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-geoip" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>libnginx-mod-http-geoip_1.14.2-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">fb1a5bc5181df167170b43f4be34d8c3ea3f0f7f</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-headers-more-filter" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>libnginx-mod-http-headers-more-filter_1.14.2-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">99fcc513603ad569aea3d35a6f1b22c54096eebe</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-image-filter" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>libnginx-mod-http-image-filter_1.14.2-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">6f9e85498aeadd72a677fe65ab15f3f30e7d8f7d</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-lua" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>libnginx-mod-http-lua_1.14.2-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">efebb484d210724a88c112ff484518087e1ab317</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-ndk" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>libnginx-mod-http-ndk_1.14.2-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">cd0d3b172e64b419630dacf87036254e605f2dd2</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-perl" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>libnginx-mod-http-perl_1.14.2-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">b24476d97e9fcefd5d6cfd64d87f1f5c30c2800e</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-subs-filter" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>libnginx-mod-http-subs-filter_1.14.2-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">213355ecd5c4fd5eb9ff63e5b13a61e692b06a12</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-uploadprogress" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>libnginx-mod-http-uploadprogress_1.14.2-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">e7b62d84d52edd764ef3c178e0c9e784448e2935</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-upstream-fair" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>libnginx-mod-http-upstream-fair_1.14.2-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">432f848199acd2403895250fa9f4f26bb76d5f3a</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-xslt-filter" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>libnginx-mod-http-xslt-filter_1.14.2-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">612b10c491c4168d16628cb7bb5d67755fcd9357</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-mail" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>libnginx-mod-mail_1.14.2-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">003dcfbafa044580080dbe79c6484218f681dd40</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-nchan" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>libnginx-mod-nchan_1.14.2-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">72d3bcd8985f4583e813d36e61983394e1448e95</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-rtmp" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>libnginx-mod-rtmp_1.14.2-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">d412102bc8aa198335e79964fb72e600a8351b58</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-stream" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>libnginx-mod-stream_1.14.2-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">dc7226ce9470fcadcd06cdc70b91734ba605ebe5</sum>
        </package>
        <package arch="all" name="nginx" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>nginx_1.14.2-2+deb10u5+tuxcare.els1_all.deb</filename>
          <sum type="sha">042e1976a921c1cd59b53c1ed27803d04cc327bf</sum>
        </package>
        <package arch="all" name="nginx-common" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>nginx-common_1.14.2-2+deb10u5+tuxcare.els1_all.deb</filename>
          <sum type="sha">c9869a891544e0a6fae23f04ba3a626dc1010bb0</sum>
        </package>
        <package arch="all" name="nginx-doc" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>nginx-doc_1.14.2-2+deb10u5+tuxcare.els1_all.deb</filename>
          <sum type="sha">3442cb0e0c893f3db28f0bb642abf92204c66ff7</sum>
        </package>
        <package arch="amd64" name="nginx-extras" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>nginx-extras_1.14.2-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">aad6a81cc7a403a9dda5f8acf4644a1f5d4ee7e1</sum>
        </package>
        <package arch="amd64" name="nginx-full" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>nginx-full_1.14.2-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">3f34044bbe1a6deb21f92f4c86f6b6665b00f4a1</sum>
        </package>
        <package arch="amd64" name="nginx-light" version="1.14.2-2+deb10u5+tuxcare.els1">
          <filename>nginx-light_1.14.2-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">7caaddddb4dec76b75c44fb10bc336be9fa11299</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1760982550</id>
    <title>Fix CVE(s): CVE-2022-48174</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY_UPDATE: avoid segfault on ${0::0/0~09J}
     - debian/patches/CVE-2022-48174.patch: Fix shell segfault in malformed arithmetic
       expressions
     - CVE-2022-48174</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY_UPDATE: avoid segfault on ${0::0/0~09J}
     - debian/patches/CVE-2022-48174.patch: Fix shell segfault in malformed arithmetic
       expressions
     - CVE-2022-48174</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-20 17:49:15 UTC" />
    <updated date="2025-10-20 17:49:15 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1760982550.html" id="CLSA-2025:1760982550" title="CLSA-2025:1760982550" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="busybox" version="1:1.30.1-4+tuxcare.els1">
          <filename>busybox_1.30.1-4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">f80d6afde9c2ea020b595ba1558c5922535effb7</sum>
        </package>
        <package arch="amd64" name="busybox-static" version="1:1.30.1-4+tuxcare.els1">
          <filename>busybox-static_1.30.1-4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">7dc1cf3aa5d7ebb368d790fcc0ffa75790aea6e4</sum>
        </package>
        <package arch="all" name="busybox-syslogd" version="1:1.30.1-4+tuxcare.els1">
          <filename>busybox-syslogd_1.30.1-4+tuxcare.els1_all.deb</filename>
          <sum type="sha">3631b64bc688fb3a90ff3e8ec3ac091f1126f14f</sum>
        </package>
        <package arch="amd64" name="udhcpc" version="1:1.30.1-4+tuxcare.els1">
          <filename>udhcpc_1.30.1-4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">b859127a3bd83db5e61afe7e0be4952cdc1dbce3</sum>
        </package>
        <package arch="amd64" name="udhcpd" version="1:1.30.1-4+tuxcare.els1">
          <filename>udhcpd_1.30.1-4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">922610c336cee34df74765dd8f24c8514f9c3504</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761082098</id>
    <title>Fix CVE(s): CVE-2022-0547</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Authentication bypass in external authentication
     plug-ins with only partially correct credentials
     - debian/patches/CVE-2022-0547.patch: disallow multiple deferred
       authentication plug-ins
     - CVE-2022-0547
   * Update sample keys for testing
     - debian/sample-keys/*
     - debian/rules
     - debian/source/include-binaries</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Authentication bypass in external authentication
     plug-ins with only partially correct credentials
     - debian/patches/CVE-2022-0547.patch: disallow multiple deferred
       authentication plug-ins
     - CVE-2022-0547
   * Update sample keys for testing
     - debian/sample-keys/*
     - debian/rules
     - debian/source/include-binaries</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-21 21:28:25 UTC" />
    <updated date="2025-10-21 21:28:25 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761082098.html" id="CLSA-2025:1761082098" title="CLSA-2025:1761082098" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="openvpn" version="2.4.7-1+deb10u1+tuxcare.els1">
          <filename>openvpn_2.4.7-1+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">00ebbbe453fd52e9eb6e970c8150604a63957cfe</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761082274</id>
    <title>Fix of 5 CVEs</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: out-of-bound write
     - debian/patches/CVE-2024-11236: fix integer overflow causing in an out-of-bounds write
       ldap_escape()
     - CVE-2024-11236
   * SECURITY UPDATE: incorrect URL truncation
     - debian/patches/CVE-2025-1861: fix possible incorrect URL truncation and
       redirecting to a wrong location
     - CVE-2025-1217
     - CVE-2025-1734
     - CVE-2025-1861
   * SECURITY UPDATE: inadequate validation of user-supplied headers may lead to
     header misinterpretation
     - debian/patches/CVE-2025-1736.patch: Fix GHSA-hgf5-96fm-v528: Correct http
       user header CRLF check
     - CVE-2025-1736</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: out-of-bound write
     - debian/patches/CVE-2024-11236: fix integer overflow causing in an out-of-bounds write
       ldap_escape()
     - CVE-2024-11236
   * SECURITY UPDATE: incorrect URL truncation
     - debian/patches/CVE-2025-1861: fix possible incorrect URL truncation and
       redirecting to a wrong location
     - CVE-2025-1217
     - CVE-2025-1734
     - CVE-2025-1861
   * SECURITY UPDATE: inadequate validation of user-supplied headers may lead to
     header misinterpretation
     - debian/patches/CVE-2025-1736.patch: Fix GHSA-hgf5-96fm-v528: Correct http
       user header CRLF check
     - CVE-2025-1736</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-21 21:31:18 UTC" />
    <updated date="2025-10-21 21:31:18 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761082274.html" id="CLSA-2025:1761082274" title="CLSA-2025:1761082274" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libapache2-mod-php7.3" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>libapache2-mod-php7.3_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">124ff69f882ebb6487fa7763e4efae1881709e8d</sum>
        </package>
        <package arch="amd64" name="libphp7.3-embed" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>libphp7.3-embed_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">938b04e28d3ea9d509d7511dca90dd7599f10fb2</sum>
        </package>
        <package arch="all" name="php7.3" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3_7.3.31-1~deb10u7+tuxcare.els1_all.deb</filename>
          <sum type="sha">1d311b26ae25ae9c6c07a83174ab18d0644c343c</sum>
        </package>
        <package arch="amd64" name="php7.3-bcmath" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-bcmath_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">9784dd6965f50e10287a1cafdde7c92a58dc900e</sum>
        </package>
        <package arch="amd64" name="php7.3-bz2" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-bz2_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">a07db62d32252eeb475745016e6127244067c4c7</sum>
        </package>
        <package arch="amd64" name="php7.3-cgi" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-cgi_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">979bd77b6c599fdc4d8b23d97c71669876d02975</sum>
        </package>
        <package arch="amd64" name="php7.3-cli" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-cli_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">0c345eaee975420a0450e2cfb2c6a1d310370c05</sum>
        </package>
        <package arch="amd64" name="php7.3-common" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-common_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">4f6bd8911eef5bff6d16c63736adefa69c088396</sum>
        </package>
        <package arch="amd64" name="php7.3-curl" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-curl_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">dcc81d238f97ed521aa0798a13ee71f25951e419</sum>
        </package>
        <package arch="amd64" name="php7.3-dba" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-dba_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">3619878e37a0d197a23e32f64df800ff9bda4e41</sum>
        </package>
        <package arch="amd64" name="php7.3-dev" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-dev_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">26d58d2da6b248764e5e3b5e2694985a55a14c5a</sum>
        </package>
        <package arch="amd64" name="php7.3-enchant" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-enchant_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">591f55b03761fa8c381bee84bd6f6c53b5e70bd6</sum>
        </package>
        <package arch="amd64" name="php7.3-fpm" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-fpm_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">595c7bf8e8d9e61f81283d0e80cec75166fa283e</sum>
        </package>
        <package arch="amd64" name="php7.3-gd" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-gd_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">eb493a163534a15c6f2ad8e474ec1ad53668517f</sum>
        </package>
        <package arch="amd64" name="php7.3-gmp" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-gmp_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">8c5bd228b84f64c31038f2761b1c6e9925014ac0</sum>
        </package>
        <package arch="amd64" name="php7.3-imap" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-imap_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">6460d70f19d50c952240eb6b6ca257fa341cd3fe</sum>
        </package>
        <package arch="amd64" name="php7.3-interbase" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-interbase_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">afcc738fe1dbd5113437fb2e819b6879e1f3fa12</sum>
        </package>
        <package arch="amd64" name="php7.3-intl" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-intl_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">e01b78d9b0358535787ff365fe411310dd606472</sum>
        </package>
        <package arch="amd64" name="php7.3-json" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-json_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">381ae3e4513f496c689d123a286a475417e4bd52</sum>
        </package>
        <package arch="amd64" name="php7.3-ldap" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-ldap_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">813460e38c8cd6114a5384a36c43710569d04505</sum>
        </package>
        <package arch="amd64" name="php7.3-mbstring" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-mbstring_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">fa421e2c54394fc9a91d9a58f549dcea3f805a4b</sum>
        </package>
        <package arch="amd64" name="php7.3-mysql" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-mysql_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">fb4984854975032b697bf084fab5e94e8d236b53</sum>
        </package>
        <package arch="amd64" name="php7.3-odbc" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-odbc_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">799c53b8a4dc76d0a83058615ed91051db652b77</sum>
        </package>
        <package arch="amd64" name="php7.3-opcache" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-opcache_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">9117ba9c0202f82c2e6c6ddc58000aeec516b0f4</sum>
        </package>
        <package arch="amd64" name="php7.3-pgsql" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-pgsql_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">3249e83ff4325053d84766e1b9e6c83ba0295864</sum>
        </package>
        <package arch="amd64" name="php7.3-phpdbg" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-phpdbg_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">572569a770e6a51c9d54660f40a57f729d688bea</sum>
        </package>
        <package arch="amd64" name="php7.3-pspell" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-pspell_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">8590a3f6caf6434a2c13e2ea03e712093f23e5d2</sum>
        </package>
        <package arch="amd64" name="php7.3-readline" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-readline_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">2bb2a922fa5a4a26e3020ab89df4bb4a2112e597</sum>
        </package>
        <package arch="amd64" name="php7.3-recode" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-recode_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">8af6c07e34ad6cc3a7b65fef32018db3500b8b3f</sum>
        </package>
        <package arch="amd64" name="php7.3-snmp" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-snmp_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">7362ad8cfacfcfc734af7c5ab898f575d593f607</sum>
        </package>
        <package arch="amd64" name="php7.3-soap" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-soap_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">aa8d605e76c309c274fce1b65ef7608cecde283e</sum>
        </package>
        <package arch="amd64" name="php7.3-sqlite3" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-sqlite3_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">69f8f5dd4299a50b5403c9cdb72051d02386313a</sum>
        </package>
        <package arch="amd64" name="php7.3-sybase" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-sybase_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">391855bc7cfe3e987af5f0851e255de5ddfdb2c2</sum>
        </package>
        <package arch="amd64" name="php7.3-tidy" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-tidy_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">5fd47e0e05e3c6b823bf044875b2f3b0e1d1db57</sum>
        </package>
        <package arch="amd64" name="php7.3-xml" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-xml_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">c3d7462fe117de642fc22acf0bb8d2c7f19db473</sum>
        </package>
        <package arch="amd64" name="php7.3-xmlrpc" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-xmlrpc_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">650200bdc0a0778df15c6d23d04871af538a39f2</sum>
        </package>
        <package arch="all" name="php7.3-xsl" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-xsl_7.3.31-1~deb10u7+tuxcare.els1_all.deb</filename>
          <sum type="sha">5f0a7ebae86673da60ceffbae2e82eb0e9c3825a</sum>
        </package>
        <package arch="amd64" name="php7.3-zip" version="7.3.31-1~deb10u7+tuxcare.els1">
          <filename>php7.3-zip_7.3.31-1~deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">64ba6a4607bab6420736a5b8593cc0eb71c6405f</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761082525</id>
    <title>Fix CVE(s): CVE-2022-45141</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: AD DC can be forced to issue rc4-hmac Kerberos tickets
   - debian/patches/CVE-2022-45141.patch: fix session key selection algorithm
     for selecting the ticket in strongest-to-weakest order, thus allowing
     the target server to select better encryption
   - CVE-2022-45141</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: AD DC can be forced to issue rc4-hmac Kerberos tickets
   - debian/patches/CVE-2022-45141.patch: fix session key selection algorithm
     for selecting the ticket in strongest-to-weakest order, thus allowing
     the target server to select better encryption
   - CVE-2022-45141</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-21 21:35:29 UTC" />
    <updated date="2025-10-21 21:35:29 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761082525.html" id="CLSA-2025:1761082525" title="CLSA-2025:1761082525" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="ctdb" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els1">
          <filename>ctdb_4.9.5+dfsg-5+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">4ccab4982d9599a8ecf5718389319396c5a01e96</sum>
        </package>
        <package arch="amd64" name="libnss-winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els1">
          <filename>libnss-winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">c3ef500eb998ef581d8b03fa8f9c6770339d88fb</sum>
        </package>
        <package arch="amd64" name="libpam-winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els1">
          <filename>libpam-winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">37a3e027f90c561d39913604b3c8271611e3a739</sum>
        </package>
        <package arch="amd64" name="libsmbclient" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els1">
          <filename>libsmbclient_4.9.5+dfsg-5+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">7b279f8a03147ccbd0f6ff6cfb287c32a51f56b1</sum>
        </package>
        <package arch="amd64" name="libsmbclient-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els1">
          <filename>libsmbclient-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">4e81372cbbb57a9e25b9f4c7e7f2c4f43a0da19c</sum>
        </package>
        <package arch="amd64" name="libwbclient-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els1">
          <filename>libwbclient-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">d528766cbac88aee1cf94cfab923d8664464c6ab</sum>
        </package>
        <package arch="amd64" name="libwbclient0" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els1">
          <filename>libwbclient0_4.9.5+dfsg-5+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">b9773c13268057f4d5b2b64ca2398fc60c495c76</sum>
        </package>
        <package arch="amd64" name="python-samba" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els1">
          <filename>python-samba_4.9.5+dfsg-5+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">91e2546cf2c2da38eb1e491cde034f7f1530305d</sum>
        </package>
        <package arch="amd64" name="registry-tools" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els1">
          <filename>registry-tools_4.9.5+dfsg-5+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">792e409275d08c28ae619d06e5b29f29aeb23219</sum>
        </package>
        <package arch="amd64" name="samba" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els1">
          <filename>samba_4.9.5+dfsg-5+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">a0f008095dd3a9cdfbc3786b3535b3f64c49d3af</sum>
        </package>
        <package arch="all" name="samba-common" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els1">
          <filename>samba-common_4.9.5+dfsg-5+deb10u5+tuxcare.els1_all.deb</filename>
          <sum type="sha">e7784053f78821dca2a10ddd686f1b3123a69c0e</sum>
        </package>
        <package arch="amd64" name="samba-common-bin" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els1">
          <filename>samba-common-bin_4.9.5+dfsg-5+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">dd462f838f6659d903ed8590f3c6f28722f659f3</sum>
        </package>
        <package arch="amd64" name="samba-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els1">
          <filename>samba-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">9689a808ae608fdaebba3f6f06e9a6a8d59a0147</sum>
        </package>
        <package arch="amd64" name="samba-dsdb-modules" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els1">
          <filename>samba-dsdb-modules_4.9.5+dfsg-5+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">cb1bdd39f782e3534646cd26499d020eb2a5d39b</sum>
        </package>
        <package arch="amd64" name="samba-libs" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els1">
          <filename>samba-libs_4.9.5+dfsg-5+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">2b2147eb3107687998c6851823f8a7c3b697dabe</sum>
        </package>
        <package arch="amd64" name="samba-testsuite" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els1">
          <filename>samba-testsuite_4.9.5+dfsg-5+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">3b407416460521ec48cc2fb7ad39d3f4c77071a0</sum>
        </package>
        <package arch="amd64" name="samba-vfs-modules" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els1">
          <filename>samba-vfs-modules_4.9.5+dfsg-5+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">bf940f6e18cadd3d47a186695261726a90b8244b</sum>
        </package>
        <package arch="amd64" name="smbclient" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els1">
          <filename>smbclient_4.9.5+dfsg-5+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">ee39fe8a5a140d6d78c6712c5e383b588b29ac47</sum>
        </package>
        <package arch="amd64" name="winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els1">
          <filename>winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">2643ce335c80b28420a250e8152d89a147fafa1e</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761141568</id>
    <title>Fix CVE(s): CVE-2021-46174, CVE-2022-44840</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: heap-based buffer overflow in function bfd_getl32 in
     objdump
     - debian/patches/CVE-2021-46174.patch: Don't read past end of section
       when concatentating stab strings in
       read_section_stabs_debugging_info() in rddbg.c
     - CVE-2021-46174
   * SECURITY UPDATE: heap buffer overflow in find_section_in_set() in
     readelf
     - debian/patches/CVE-2022-44840.patch: Scan the pool directly
     - CVE-2022-44840</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: heap-based buffer overflow in function bfd_getl32 in
     objdump
     - debian/patches/CVE-2021-46174.patch: Don't read past end of section
       when concatentating stab strings in
       read_section_stabs_debugging_info() in rddbg.c
     - CVE-2021-46174
   * SECURITY UPDATE: heap buffer overflow in find_section_in_set() in
     readelf
     - debian/patches/CVE-2022-44840.patch: Scan the pool directly
     - CVE-2022-44840</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-22 13:59:35 UTC" />
    <updated date="2025-10-22 13:59:35 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761141568.html" id="CLSA-2025:1761141568" title="CLSA-2025:1761141568" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="binutils" version="2.31.1-16+tuxcare.els1">
          <filename>binutils_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">0f424607a13e19be1f97cd27d1ec31f5bd6319d7</sum>
        </package>
        <package arch="amd64" name="binutils-aarch64-linux-gnu" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-aarch64-linux-gnu_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">b9c6429dbd971e936c175061803ea0516282f3de</sum>
        </package>
        <package arch="amd64" name="binutils-alpha-linux-gnu" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-alpha-linux-gnu_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">5eb545b330dd702645a126c69026338bf44106a1</sum>
        </package>
        <package arch="amd64" name="binutils-arm-linux-gnueabi" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-arm-linux-gnueabi_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">a686c445ec6f4aadad5205fd3cedf890d35515d8</sum>
        </package>
        <package arch="amd64" name="binutils-arm-linux-gnueabihf" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-arm-linux-gnueabihf_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">62fac3d5149d8571e9b067bb99eb04f7075147c6</sum>
        </package>
        <package arch="amd64" name="binutils-common" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-common_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">a6e2918f445c5214fbf06c9e26caa0b1c916f251</sum>
        </package>
        <package arch="amd64" name="binutils-dev" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-dev_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">40c5e2eef0e9758c9f4b0ddb9a901dc442b9e1d8</sum>
        </package>
        <package arch="all" name="binutils-doc" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-doc_2.31.1-16+tuxcare.els1_all.deb</filename>
          <sum type="sha">f5c05979436561bd8ad03c5b08141b9be7486119</sum>
        </package>
        <package arch="all" name="binutils-for-build" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-for-build_2.31.1-16+tuxcare.els1_all.deb</filename>
          <sum type="sha">6b060a148e6d395775ee006a9c20179c516f5fca</sum>
        </package>
        <package arch="amd64" name="binutils-for-host" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-for-host_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">0d4c005b392b31f4f1b13839b77e1f23b4fe5df2</sum>
        </package>
        <package arch="amd64" name="binutils-hppa-linux-gnu" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-hppa-linux-gnu_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">afe8dde4d083cc2ff4e0563e249ed2f07b118f62</sum>
        </package>
        <package arch="amd64" name="binutils-hppa64-linux-gnu" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-hppa64-linux-gnu_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">76141f2f3fb5da7701679dae5facdd2654080c24</sum>
        </package>
        <package arch="amd64" name="binutils-i686-gnu" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-i686-gnu_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">5108d1cd505516f2739001585d94fef717f9b505</sum>
        </package>
        <package arch="amd64" name="binutils-i686-kfreebsd-gnu" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-i686-kfreebsd-gnu_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">a9047c7768a456f4823eae4275760ebd817bc620</sum>
        </package>
        <package arch="amd64" name="binutils-i686-linux-gnu" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-i686-linux-gnu_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">0d60ebdd10175eaf63ca190ed2558d58d842cc2d</sum>
        </package>
        <package arch="amd64" name="binutils-ia64-linux-gnu" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-ia64-linux-gnu_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">154bfab9424e71a795d2b4d9d876f424e6eed990</sum>
        </package>
        <package arch="amd64" name="binutils-m68k-linux-gnu" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-m68k-linux-gnu_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">1eb66a363b4c368250e6c0c0ab38b71cfda37b7a</sum>
        </package>
        <package arch="amd64" name="binutils-mips-linux-gnu" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-mips-linux-gnu_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">5d9fe95168eccbea3a5d9745dc00dde08da4c478</sum>
        </package>
        <package arch="amd64" name="binutils-mips64el-linux-gnuabi64" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-mips64el-linux-gnuabi64_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">c3f7c16be5d54e65c66b6f686f1ddb249a2d98c4</sum>
        </package>
        <package arch="amd64" name="binutils-mipsel-linux-gnu" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-mipsel-linux-gnu_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">088b545b95748adc98a3d99b71206d4b763921d5</sum>
        </package>
        <package arch="amd64" name="binutils-multiarch" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-multiarch_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">708c845fa4bc9ba76b96842be4249fe4e2600af6</sum>
        </package>
        <package arch="amd64" name="binutils-multiarch-dev" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-multiarch-dev_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">a1ce5a9b555763a24ce9cb307b0d5951b93bad0f</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc-linux-gnu" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-powerpc-linux-gnu_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">365242c2b9a05e0d2613152ce3a94a9f54f54e5c</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc-linux-gnuspe" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-powerpc-linux-gnuspe_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">3e9194222a805c0bf59b69dac0f3a9002a67bf9a</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc64-linux-gnu" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-powerpc64-linux-gnu_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">c08abfc65c6cd91fe57ee89a4fdc142a0e52ffc4</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc64le-linux-gnu" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-powerpc64le-linux-gnu_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">cd931e038afef67c1027afecfff81c64cf5d801e</sum>
        </package>
        <package arch="amd64" name="binutils-riscv64-linux-gnu" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-riscv64-linux-gnu_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">2a5730ac400fa7941c0fca594b99d651eec766b8</sum>
        </package>
        <package arch="amd64" name="binutils-s390x-linux-gnu" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-s390x-linux-gnu_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">1ae34654db857a262ef96a6028343473646be963</sum>
        </package>
        <package arch="amd64" name="binutils-sh4-linux-gnu" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-sh4-linux-gnu_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">c8881e3690be0565a6d063028f14491a3f4c71c0</sum>
        </package>
        <package arch="all" name="binutils-source" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-source_2.31.1-16+tuxcare.els1_all.deb</filename>
          <sum type="sha">3df691d0e97273ba84fdd585b7faaa865f58f67e</sum>
        </package>
        <package arch="amd64" name="binutils-sparc64-linux-gnu" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-sparc64-linux-gnu_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">eb7008c93370a70e8b27d16697548880089838f3</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-kfreebsd-gnu" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-x86-64-kfreebsd-gnu_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">6dd57aec86555137e540d19b7b407e46e4b5d068</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-linux-gnu" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-x86-64-linux-gnu_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">22761d64c400f819f065d2334d6f125036f6c529</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-linux-gnux32" version="2.31.1-16+tuxcare.els1">
          <filename>binutils-x86-64-linux-gnux32_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">49991512dad7517b855fe9604838ed4a77953be5</sum>
        </package>
        <package arch="amd64" name="libbinutils" version="2.31.1-16+tuxcare.els1">
          <filename>libbinutils_2.31.1-16+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">dfb6cc3503772ea9cc81fb88e7177d9f87796ca5</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761261543</id>
    <title>Fix CVE(s): CVE-2024-56171</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: use-after-free vulnerability in XML schema processing
     - debian/patches/CVE-2024-56171.patch: Fix use-after-free after
       xmlSchemaItemListAdd in xmlSchemaIDCFillNodeTables and
       xmlSchemaBubbleIDCNodeTables
     - CVE-2024-56171</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: use-after-free vulnerability in XML schema processing
     - debian/patches/CVE-2024-56171.patch: Fix use-after-free after
       xmlSchemaItemListAdd in xmlSchemaIDCFillNodeTables and
       xmlSchemaBubbleIDCNodeTables
     - CVE-2024-56171</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-23 23:19:07 UTC" />
    <updated date="2025-10-23 23:19:07 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761261543.html" id="CLSA-2025:1761261543" title="CLSA-2025:1761261543" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libxml2" version="2.9.4+dfsg1-7+deb10u6+tuxcare.els1">
          <filename>libxml2_2.9.4+dfsg1-7+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">d856ee784d0e5418691329eaca7a2e2b0a334d73</sum>
        </package>
        <package arch="amd64" name="libxml2-dev" version="2.9.4+dfsg1-7+deb10u6+tuxcare.els1">
          <filename>libxml2-dev_2.9.4+dfsg1-7+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">18d58e5e54bebd72c636fdaa056c2410ddcc5059</sum>
        </package>
        <package arch="all" name="libxml2-doc" version="2.9.4+dfsg1-7+deb10u6+tuxcare.els1">
          <filename>libxml2-doc_2.9.4+dfsg1-7+deb10u6+tuxcare.els1_all.deb</filename>
          <sum type="sha">00f206446fc264b7db59d3b50242bce22cfb4caa</sum>
        </package>
        <package arch="amd64" name="libxml2-utils" version="2.9.4+dfsg1-7+deb10u6+tuxcare.els1">
          <filename>libxml2-utils_2.9.4+dfsg1-7+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">ffb0174c1f81bf11ff3e19f0402a7fbf7083e8fe</sum>
        </package>
        <package arch="amd64" name="python-libxml2" version="2.9.4+dfsg1-7+deb10u6+tuxcare.els1">
          <filename>python-libxml2_2.9.4+dfsg1-7+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">217028bfa7b7991c2691ec349fe239bb80dfb7ef</sum>
        </package>
        <package arch="amd64" name="python3-libxml2" version="2.9.4+dfsg1-7+deb10u6+tuxcare.els1">
          <filename>python3-libxml2_2.9.4+dfsg1-7+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">8204e644d1863c3ed236b633278d43c2dc9e3d57</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1760649409</id>
    <title>Fix CVE(s): CVE-2025-6965</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: excessive aggregate terms potentially leading to memory
     corruption
     - debian/patches/CVE-2025-6965.patch: fix a potential memory corruption if the number
       of aggregate terms in a query exceeds the maximum number of columns
     - CVE-2025-6965</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: excessive aggregate terms potentially leading to memory
     corruption
     - debian/patches/CVE-2025-6965.patch: fix a potential memory corruption if the number
       of aggregate terms in a query exceeds the maximum number of columns
     - CVE-2025-6965</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-24 15:08:14 UTC" />
    <updated date="2025-10-24 15:08:14 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1760649409.html" id="CLSA-2025:1760649409" title="CLSA-2025:1760649409" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="lemon" version="3.31.1-4ubuntu0.7+tuxcare.els1">
          <filename>lemon_3.31.1-4ubuntu0.7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">e7ef9078ae0f9875540c3f96aa099d16d5a4243d</sum>
        </package>
        <package arch="amd64" name="libsqlite3-0" version="3.31.1-4ubuntu0.7+tuxcare.els1">
          <filename>libsqlite3-0_3.31.1-4ubuntu0.7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">7926aec247b7c064ff7dae0d2f5ebc8a4e3afc08</sum>
        </package>
        <package arch="amd64" name="libsqlite3-dev" version="3.31.1-4ubuntu0.7+tuxcare.els1">
          <filename>libsqlite3-dev_3.31.1-4ubuntu0.7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">8686e24186dbf9972a664a403f256e7a21a28cd5</sum>
        </package>
        <package arch="amd64" name="libsqlite3-tcl" version="3.31.1-4ubuntu0.7+tuxcare.els1">
          <filename>libsqlite3-tcl_3.31.1-4ubuntu0.7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">0d895f5786bddd55ceb2dede32fd2764be00d709</sum>
        </package>
        <package arch="amd64" name="sqlite3" version="3.31.1-4ubuntu0.7+tuxcare.els1">
          <filename>sqlite3_3.31.1-4ubuntu0.7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">b19c579edb6025d355ee12f27929eda8182be16e</sum>
        </package>
        <package arch="all" name="sqlite3-doc" version="3.31.1-4ubuntu0.7+tuxcare.els1">
          <filename>sqlite3-doc_3.31.1-4ubuntu0.7+tuxcare.els1_all.deb</filename>
          <sum type="sha">a132efc62705e0eb683956feae88211ac3675931</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761323691</id>
    <title>Fix CVE(s): CVE-2025-0840</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: stack-based buffer overflow in disassemble_bytes function
     - debian/patches/CVE-2025-0840.patch: Fix stack-buffer-overflow by
       restricting size of insn_width buffer
     - CVE-2025-0840</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: stack-based buffer overflow in disassemble_bytes function
     - debian/patches/CVE-2025-0840.patch: Fix stack-buffer-overflow by
       restricting size of insn_width buffer
     - CVE-2025-0840</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-24 16:34:59 UTC" />
    <updated date="2025-10-24 16:34:59 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761323691.html" id="CLSA-2025:1761323691" title="CLSA-2025:1761323691" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="binutils" version="2.31.1-16+tuxcare.els2">
          <filename>binutils_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">10d61e45d8ce9d5a604c7a2fb66acfb202b646a4</sum>
        </package>
        <package arch="amd64" name="binutils-aarch64-linux-gnu" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-aarch64-linux-gnu_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">a2f9df0ac31bf4fd0f1438260713099bc67c16cd</sum>
        </package>
        <package arch="amd64" name="binutils-alpha-linux-gnu" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-alpha-linux-gnu_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">9b2953d555cd1c2c3bf93659cd3178789212c1e8</sum>
        </package>
        <package arch="amd64" name="binutils-arm-linux-gnueabi" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-arm-linux-gnueabi_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">9e18343881aa6f6a2f8e65ca4f869237fa975bff</sum>
        </package>
        <package arch="amd64" name="binutils-arm-linux-gnueabihf" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-arm-linux-gnueabihf_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">509cca3ea3d3afba537fded1f1d51d8e757e425b</sum>
        </package>
        <package arch="amd64" name="binutils-common" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-common_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">e4cb4c14c914a72afc7d9735c636d215de01fc5a</sum>
        </package>
        <package arch="amd64" name="binutils-dev" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-dev_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">c28d5780b68962ac7cbbc83a1901406e42191a11</sum>
        </package>
        <package arch="all" name="binutils-doc" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-doc_2.31.1-16+tuxcare.els2_all.deb</filename>
          <sum type="sha">5dce8da58cfc10efe1e8eb1e372ea90aae05e6e1</sum>
        </package>
        <package arch="all" name="binutils-for-build" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-for-build_2.31.1-16+tuxcare.els2_all.deb</filename>
          <sum type="sha">82090105f21bd0bd9926ffbd2ac02d96778171f1</sum>
        </package>
        <package arch="amd64" name="binutils-for-host" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-for-host_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">f1c7478350a18d8a04ef93302d8c3e8aad084836</sum>
        </package>
        <package arch="amd64" name="binutils-hppa-linux-gnu" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-hppa-linux-gnu_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">c04eef795892e0edfbb47eb21e0237dae8952abc</sum>
        </package>
        <package arch="amd64" name="binutils-hppa64-linux-gnu" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-hppa64-linux-gnu_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">3d6214a97b4797f714e2159ea9e1880a48701325</sum>
        </package>
        <package arch="amd64" name="binutils-i686-gnu" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-i686-gnu_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">cd1f87ce4f1a18e14894ce7ed10d90718649ad9a</sum>
        </package>
        <package arch="amd64" name="binutils-i686-kfreebsd-gnu" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-i686-kfreebsd-gnu_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">a68d38e65de4755d39bb7c3b96a14dda9d6e0598</sum>
        </package>
        <package arch="amd64" name="binutils-i686-linux-gnu" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-i686-linux-gnu_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">2081b6e7dc47f34243f1a8afa16a2cbb064737b4</sum>
        </package>
        <package arch="amd64" name="binutils-ia64-linux-gnu" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-ia64-linux-gnu_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">55745a353c8618df893ff22f37769d73df264597</sum>
        </package>
        <package arch="amd64" name="binutils-m68k-linux-gnu" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-m68k-linux-gnu_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">d84b19862bfa94fd08602690016e2f6ea2d7586c</sum>
        </package>
        <package arch="amd64" name="binutils-mips-linux-gnu" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-mips-linux-gnu_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">b011b4b7a347c2211fae2ca4945bb58f103b5979</sum>
        </package>
        <package arch="amd64" name="binutils-mips64el-linux-gnuabi64" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-mips64el-linux-gnuabi64_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">ebfd3e756aa2a93a13317dfa5f6a1dcb4cf08b08</sum>
        </package>
        <package arch="amd64" name="binutils-mipsel-linux-gnu" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-mipsel-linux-gnu_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">4054ad107553ec30ab9507fbc8c9e1f400175119</sum>
        </package>
        <package arch="amd64" name="binutils-multiarch" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-multiarch_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">4a704bb65efd46388862a6d524711b7fa652216a</sum>
        </package>
        <package arch="amd64" name="binutils-multiarch-dev" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-multiarch-dev_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">596fc7acffc0b2e786b8482ed3092f0b933a679a</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc-linux-gnu" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-powerpc-linux-gnu_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">1d55ea307f67316e81382b03a16aa4192b1e560b</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc-linux-gnuspe" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-powerpc-linux-gnuspe_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">dbc2c6090426fb2e2581b0cb05b4605188f35ca9</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc64-linux-gnu" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-powerpc64-linux-gnu_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">5571ca6c0c8ad2ce890eb19550e99acbd24aa121</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc64le-linux-gnu" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-powerpc64le-linux-gnu_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">94cb107ee64e3dc34204a9f4c29bc2ab4f0ffd48</sum>
        </package>
        <package arch="amd64" name="binutils-riscv64-linux-gnu" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-riscv64-linux-gnu_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">dd2759ccbf7cd1fea810233c764c707859b32467</sum>
        </package>
        <package arch="amd64" name="binutils-s390x-linux-gnu" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-s390x-linux-gnu_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">be7511b4fb84c8eb916f269e2dc814f491eea6dd</sum>
        </package>
        <package arch="amd64" name="binutils-sh4-linux-gnu" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-sh4-linux-gnu_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">2175769114d40f7209815feaaa6386a9f7bfcf39</sum>
        </package>
        <package arch="all" name="binutils-source" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-source_2.31.1-16+tuxcare.els2_all.deb</filename>
          <sum type="sha">95ae0d96f4ed410735f826fd658041312a6ed759</sum>
        </package>
        <package arch="amd64" name="binutils-sparc64-linux-gnu" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-sparc64-linux-gnu_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">a514e9aae2f987cb11c8f57bd34977775dc563d0</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-kfreebsd-gnu" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-x86-64-kfreebsd-gnu_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">8c5608078e32d3ef0c783a5dc48701523e716404</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-linux-gnu" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-x86-64-linux-gnu_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">3dc035b71503dbeac506bc6ecf287ba487f4fa1b</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-linux-gnux32" version="2.31.1-16+tuxcare.els2">
          <filename>binutils-x86-64-linux-gnux32_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">41b91301ee1417ce3a56309d7827151604ba4b49</sum>
        </package>
        <package arch="amd64" name="libbinutils" version="2.31.1-16+tuxcare.els2">
          <filename>libbinutils_2.31.1-16+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">138684001179f12c447ba61deda6cc8b337a962d</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761323893</id>
    <title>Fix CVE(s): CVE-2023-31484</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: missing TLS certificate verification
     - debian/patches/fixes/CVE-2023-31484.patch: enable SSL/TLS cert checking
       in .../CPAN/HTTP/Client.pm
     - CVE-2023-31484</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: missing TLS certificate verification
     - debian/patches/fixes/CVE-2023-31484.patch: enable SSL/TLS cert checking
       in .../CPAN/HTTP/Client.pm
     - CVE-2023-31484</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-24 16:38:23 UTC" />
    <updated date="2025-10-24 16:38:23 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761323893.html" id="CLSA-2025:1761323893" title="CLSA-2025:1761323893" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libperl-dev" version="5.28.1-6+deb10u1+tuxcare.els1">
          <filename>libperl-dev_5.28.1-6+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">a6249129e36bc6f39594991ec07da4c5ec98e962</sum>
        </package>
        <package arch="amd64" name="libperl5.28" version="5.28.1-6+deb10u1+tuxcare.els1">
          <filename>libperl5.28_5.28.1-6+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">e0a40390d42e2ea9f3bdb7f63e03899ee07ebe00</sum>
        </package>
        <package arch="amd64" name="perl" version="5.28.1-6+deb10u1+tuxcare.els1">
          <filename>perl_5.28.1-6+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">fff0018a92c3bcabd01ad70325d347179c2f51d2</sum>
        </package>
        <package arch="amd64" name="perl-base" version="5.28.1-6+deb10u1+tuxcare.els1">
          <filename>perl-base_5.28.1-6+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">d64e800da2525d19bf018d723f10d725bb1c4091</sum>
        </package>
        <package arch="amd64" name="perl-debug" version="5.28.1-6+deb10u1+tuxcare.els1">
          <filename>perl-debug_5.28.1-6+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">e4d81dff64bd849fc78e3b54c984af8c2627bbc6</sum>
        </package>
        <package arch="all" name="perl-doc" version="5.28.1-6+deb10u1+tuxcare.els1">
          <filename>perl-doc_5.28.1-6+deb10u1+tuxcare.els1_all.deb</filename>
          <sum type="sha">ab90013c6c641b879085bc80719d8701e5d4f4d4</sum>
        </package>
        <package arch="all" name="perl-modules-5.28" version="5.28.1-6+deb10u1+tuxcare.els1">
          <filename>perl-modules-5.28_5.28.1-6+deb10u1+tuxcare.els1_all.deb</filename>
          <sum type="sha">845f464545febba5adf05946cb6f9ac604fd6847</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761325294</id>
    <title>Fix CVE(s): CVE-2021-23240, CVE-2023-42465, CVE-2025-32462</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: privilege escalation via symlinks
   - debian/patches/CVE-2021-23240.patch: fix opportunity for local
     unprivileged user to gain file ownership via symlinks.
   * SECURITY UPDATE: unauthorized commands execution on unintended hosts
   - debian/patches/CVE-2025-32462.patch: restrict user from setting remote
     host for command unless listing privileges
   - CVE-2025-32462
   * SECURITY UPDATE: row hammer attack
   - debian/patches/CVE-2023-42465.patch: make return values resist to
     single bit flips
   - CVE-2023-42465</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: privilege escalation via symlinks
   - debian/patches/CVE-2021-23240.patch: fix opportunity for local
     unprivileged user to gain file ownership via symlinks.
   * SECURITY UPDATE: unauthorized commands execution on unintended hosts
   - debian/patches/CVE-2025-32462.patch: restrict user from setting remote
     host for command unless listing privileges
   - CVE-2025-32462
   * SECURITY UPDATE: row hammer attack
   - debian/patches/CVE-2023-42465.patch: make return values resist to
     single bit flips
   - CVE-2023-42465</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-24 17:01:38 UTC" />
    <updated date="2025-10-24 17:01:38 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761325294.html" id="CLSA-2025:1761325294" title="CLSA-2025:1761325294" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="sudo" version="1.8.27-1+deb10u6+tuxcare.els1">
          <filename>sudo_1.8.27-1+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">ca25ece51abdcfd50763004df146b24b28ecf303</sum>
        </package>
        <package arch="amd64" name="sudo-ldap" version="1.8.27-1+deb10u6+tuxcare.els1">
          <filename>sudo-ldap_1.8.27-1+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">1f5aea49b4a70b516390debe596e7ba4f1153682</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761326171</id>
    <title>Fix CVE(s): CVE-2019-18276</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: privilege escalation vulnerability in privileged mode
     - debian/patches/CVE-2019-18276.patch: fix setuid/setgid handling
       when bash is running in privileged mode, use setresuid/setresgid
       over setuid/setgid when available
     - CVE-2019-18276</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: privilege escalation vulnerability in privileged mode
     - debian/patches/CVE-2019-18276.patch: fix setuid/setgid handling
       when bash is running in privileged mode, use setresuid/setresgid
       over setuid/setgid when available
     - CVE-2019-18276</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-24 17:16:15 UTC" />
    <updated date="2025-10-24 17:16:15 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761326171.html" id="CLSA-2025:1761326171" title="CLSA-2025:1761326171" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="bash" version="5.0-4+tuxcare.els1">
          <filename>bash_5.0-4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">04afc0d6dd679af3f9d23177f3a0ac92eccaff24</sum>
        </package>
        <package arch="amd64" name="bash-builtins" version="5.0-4+tuxcare.els1">
          <filename>bash-builtins_5.0-4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">d1eb3f548e5b0930a54571f75c2f90afa15202f5</sum>
        </package>
        <package arch="all" name="bash-doc" version="5.0-4+tuxcare.els1">
          <filename>bash-doc_5.0-4+tuxcare.els1_all.deb</filename>
          <sum type="sha">3a09b35a485f8f3c6de1a1c31874e0f650ce89b4</sum>
        </package>
        <package arch="amd64" name="bash-static" version="5.0-4+tuxcare.els1">
          <filename>bash-static_5.0-4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">29641db28dc6d03d6520ab31d44bef645edff7d4</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761575970</id>
    <title>Fix of 6 CVEs</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: potential Denial of Service via TLS connection
     - debian/patches/CVE-2020-14058.patch: Fix sending of unknown validation
       errors to cert validator
     - CVE-2020-14058
   * SECURITY UPDATE: improper Validation of Specified Index leads to Denial of
     Service via TLS Handshake vulnerability
     - debian/patches/CVE-2023-46724.patch: Fix validation of certificates with
       CN=* due to Buffer UnderRead in SSL CN Parsing issue (#1523)
     - CVE-2023-46724
   * SECURITY UPDATE: denial of Service vulnerability in HTTP Chunked decoder due
     to uncontrolled recursion bug
     - debian/patches/CVE-2024-25111.patch: Fix infinite recursion when parsing
       HTTP chunks, prevent progress in call chain by stopping HttpStateData
       recursion
     - CVE-2024-25111
   * SECURITY UPDATE: denial of Service vulnerability in the NTLM authentication
     credentials parser due to incorrect input validation
     - debian/patches/CVE-2020-8517.patch: Fix incorrect input validation
       allowing writing outside of buffer and leading to denial of service
     - CVE-2020-8517
   * SECURITY UPDATE: denial of Service vulnerability against HTTP header parsing
     due to a Collapse of Data into Unsafe Value
     - debian/patches/CVE-2024-25617.patch: Improve handling of expanding HTTP
       header values to prevent DoS
     - CVE-2024-25617
   * SECURITY UPDATE: denial of Service vulnerability by a trusted server
     - debian/rules: Disable ESI due to unfixed multiple
       issues in ESI causing DoS by a trusted server
     - debian/control: Remove dependencies used by ESI
     - CVE-2024-45802</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: potential Denial of Service via TLS connection
     - debian/patches/CVE-2020-14058.patch: Fix sending of unknown validation
       errors to cert validator
     - CVE-2020-14058
   * SECURITY UPDATE: improper Validation of Specified Index leads to Denial of
     Service via TLS Handshake vulnerability
     - debian/patches/CVE-2023-46724.patch: Fix validation of certificates with
       CN=* due to Buffer UnderRead in SSL CN Parsing issue (#1523)
     - CVE-2023-46724
   * SECURITY UPDATE: denial of Service vulnerability in HTTP Chunked decoder due
     to uncontrolled recursion bug
     - debian/patches/CVE-2024-25111.patch: Fix infinite recursion when parsing
       HTTP chunks, prevent progress in call chain by stopping HttpStateData
       recursion
     - CVE-2024-25111
   * SECURITY UPDATE: denial of Service vulnerability in the NTLM authentication
     credentials parser due to incorrect input validation
     - debian/patches/CVE-2020-8517.patch: Fix incorrect input validation
       allowing writing outside of buffer and leading to denial of service
     - CVE-2020-8517
   * SECURITY UPDATE: denial of Service vulnerability against HTTP header parsing
     due to a Collapse of Data into Unsafe Value
     - debian/patches/CVE-2024-25617.patch: Improve handling of expanding HTTP
       header values to prevent DoS
     - CVE-2024-25617
   * SECURITY UPDATE: denial of Service vulnerability by a trusted server
     - debian/rules: Disable ESI due to unfixed multiple
       issues in ESI causing DoS by a trusted server
     - debian/control: Remove dependencies used by ESI
     - CVE-2024-45802</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-27 14:39:39 UTC" />
    <updated date="2025-10-27 14:39:39 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761575970.html" id="CLSA-2025:1761575970" title="CLSA-2025:1761575970" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="squid" version="4.6-1+deb10u10+tuxcare.els1">
          <filename>squid_4.6-1+deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">f6ab2fab6e59af569e63d5523611884b7bbe8138</sum>
        </package>
        <package arch="amd64" name="squid-cgi" version="4.6-1+deb10u10+tuxcare.els1">
          <filename>squid-cgi_4.6-1+deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">4c594136f4f4c32a86dbf8dd5fa1b433df895857</sum>
        </package>
        <package arch="all" name="squid-common" version="4.6-1+deb10u10+tuxcare.els1">
          <filename>squid-common_4.6-1+deb10u10+tuxcare.els1_all.deb</filename>
          <sum type="sha">cb9e61c1b50a63a0bbcce6e89f05e59d7e3b6b47</sum>
        </package>
        <package arch="amd64" name="squid-purge" version="4.6-1+deb10u10+tuxcare.els1">
          <filename>squid-purge_4.6-1+deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">66170871d1df3093aa97b4a3ad3375197f64f773</sum>
        </package>
        <package arch="all" name="squid3" version="4.6-1+deb10u10+tuxcare.els1">
          <filename>squid3_4.6-1+deb10u10+tuxcare.els1_all.deb</filename>
          <sum type="sha">f18f61dc50e834ae0e2194a0b67626153e48fc83</sum>
        </package>
        <package arch="amd64" name="squidclient" version="4.6-1+deb10u10+tuxcare.els1">
          <filename>squidclient_4.6-1+deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">27a1964f3383cd999d943c851e49774ca4829fcd</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761576180</id>
    <title>Fix CVE(s): CVE-2025-31651</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Bypassing of some rewrite rules by a specially
     crafted request
     - debian/patches/CVE-2025-31651.patch: better handling of URLs
     - CVE-2025-31651</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Bypassing of some rewrite rules by a specially
     crafted request
     - debian/patches/CVE-2025-31651.patch: better handling of URLs
     - CVE-2025-31651</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-27 14:43:04 UTC" />
    <updated date="2025-10-27 14:43:04 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761576180.html" id="CLSA-2025:1761576180" title="CLSA-2025:1761576180" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="all" name="libtomcat9-embed-java" version="9.0.31-1~deb10u12+tuxcare.els3">
          <filename>libtomcat9-embed-java_9.0.31-1~deb10u12+tuxcare.els3_all.deb</filename>
          <sum type="sha">f11444681888fcd100cff2db2f6753a2fa0bc7f5</sum>
        </package>
        <package arch="all" name="libtomcat9-java" version="9.0.31-1~deb10u12+tuxcare.els3">
          <filename>libtomcat9-java_9.0.31-1~deb10u12+tuxcare.els3_all.deb</filename>
          <sum type="sha">2c6bbd92af923c26715fc1b241c63d21e0e8e6ad</sum>
        </package>
        <package arch="all" name="tomcat9" version="9.0.31-1~deb10u12+tuxcare.els3">
          <filename>tomcat9_9.0.31-1~deb10u12+tuxcare.els3_all.deb</filename>
          <sum type="sha">b5e935bd2fcd169c9c1f0e312df4a3e038091709</sum>
        </package>
        <package arch="all" name="tomcat9-admin" version="9.0.31-1~deb10u12+tuxcare.els3">
          <filename>tomcat9-admin_9.0.31-1~deb10u12+tuxcare.els3_all.deb</filename>
          <sum type="sha">4653d95a291c4cce814891605a3488c1ef9eb28a</sum>
        </package>
        <package arch="all" name="tomcat9-common" version="9.0.31-1~deb10u12+tuxcare.els3">
          <filename>tomcat9-common_9.0.31-1~deb10u12+tuxcare.els3_all.deb</filename>
          <sum type="sha">3dc7a0bbeb37f515ab6ec145447aa8ab3c4edcd3</sum>
        </package>
        <package arch="all" name="tomcat9-docs" version="9.0.31-1~deb10u12+tuxcare.els3">
          <filename>tomcat9-docs_9.0.31-1~deb10u12+tuxcare.els3_all.deb</filename>
          <sum type="sha">8cae880463599441799cf82e173b0d62d95eaa49</sum>
        </package>
        <package arch="all" name="tomcat9-examples" version="9.0.31-1~deb10u12+tuxcare.els3">
          <filename>tomcat9-examples_9.0.31-1~deb10u12+tuxcare.els3_all.deb</filename>
          <sum type="sha">9031c7a0592ba5fa946aba5d8b648353321c49e8</sum>
        </package>
        <package arch="all" name="tomcat9-user" version="9.0.31-1~deb10u12+tuxcare.els3">
          <filename>tomcat9-user_9.0.31-1~deb10u12+tuxcare.els3_all.deb</filename>
          <sum type="sha">1fdd665af3fdaf54b1f6339a9e05273f8fb30c2c</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761576318</id>
    <title>Fix CVE(s): CVE-2022-3520</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Heap-based Buffer Overflow in visual mode
     - debian/patches/CVE-2022-3520.patch: check that the column does not
       become negative
     - CVE-2022-3520</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Heap-based Buffer Overflow in visual mode
     - debian/patches/CVE-2022-3520.patch: check that the column does not
       become negative
     - CVE-2022-3520</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-27 14:45:22 UTC" />
    <updated date="2025-10-27 14:45:22 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761576318.html" id="CLSA-2025:1761576318" title="CLSA-2025:1761576318" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="vim" version="2:8.1.0875-5+deb10u6+tuxcare.els2">
          <filename>vim_8.1.0875-5+deb10u6+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">a652abe70d57c7a0d8eb12f0a0482181dba761b5</sum>
        </package>
        <package arch="amd64" name="vim-athena" version="2:8.1.0875-5+deb10u6+tuxcare.els2">
          <filename>vim-athena_8.1.0875-5+deb10u6+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">5161201d4a472d3cb28309352d4d781054b7a839</sum>
        </package>
        <package arch="all" name="vim-common" version="2:8.1.0875-5+deb10u6+tuxcare.els2">
          <filename>vim-common_8.1.0875-5+deb10u6+tuxcare.els2_all.deb</filename>
          <sum type="sha">661ddcd2de95d674d114c3783ce2330da8f0f276</sum>
        </package>
        <package arch="all" name="vim-doc" version="2:8.1.0875-5+deb10u6+tuxcare.els2">
          <filename>vim-doc_8.1.0875-5+deb10u6+tuxcare.els2_all.deb</filename>
          <sum type="sha">db26acd259cef15d92dbfe1a85dc0b7e1d3fac85</sum>
        </package>
        <package arch="amd64" name="vim-gtk" version="2:8.1.0875-5+deb10u6+tuxcare.els2">
          <filename>vim-gtk_8.1.0875-5+deb10u6+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">f5c64adfecd25e3df2e877df3ee93cdfe706f30b</sum>
        </package>
        <package arch="amd64" name="vim-gtk3" version="2:8.1.0875-5+deb10u6+tuxcare.els2">
          <filename>vim-gtk3_8.1.0875-5+deb10u6+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">5c9f0c3a0caf414bbf9c9aadd18d2906acbf6d5e</sum>
        </package>
        <package arch="all" name="vim-gui-common" version="2:8.1.0875-5+deb10u6+tuxcare.els2">
          <filename>vim-gui-common_8.1.0875-5+deb10u6+tuxcare.els2_all.deb</filename>
          <sum type="sha">863d94168ad4fb46c4a20d1c0d4dbfa892f7777a</sum>
        </package>
        <package arch="amd64" name="vim-nox" version="2:8.1.0875-5+deb10u6+tuxcare.els2">
          <filename>vim-nox_8.1.0875-5+deb10u6+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">acf01bf56ff18fe3b93fc9707db97a81a2328834</sum>
        </package>
        <package arch="all" name="vim-runtime" version="2:8.1.0875-5+deb10u6+tuxcare.els2">
          <filename>vim-runtime_8.1.0875-5+deb10u6+tuxcare.els2_all.deb</filename>
          <sum type="sha">d2f532d57ff49053bb1bc21475ca1deb04ea7915</sum>
        </package>
        <package arch="amd64" name="vim-tiny" version="2:8.1.0875-5+deb10u6+tuxcare.els2">
          <filename>vim-tiny_8.1.0875-5+deb10u6+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">d5e630002939479f2b0ce1f63cc1b0cb066da7ef</sum>
        </package>
        <package arch="amd64" name="xxd" version="2:8.1.0875-5+deb10u6+tuxcare.els2">
          <filename>xxd_8.1.0875-5+deb10u6+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">13a91d3734ef322e167cb57280af8164e72bb879</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761577285</id>
    <title>Fix of 5 CVEs</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: out-of-bounds access
     - debian/patches/CVE-2017-9118.patch: fix out of bounds access in php_pcre_replace_impl
     - CVE-2017-9118
   * SECURITY UPDATE: improper validation of HTTP_REDIRECT_STATUS variable in CGI
     binary
     - debian/patches/CVE-2024-8927.patch: fix Apache server name check; remove
       references to redirect.so and Netscape; check configuration override first
     - CVE-2024-8927
   * SECURITY UPDATE: buffer overread vulnerability
     - debian/patches/CVE-2024-11233.patch: move bound check upwards to fix
       single byte overread with convert.quoted-printable-decode filter
     - CVE-2024-11233
   * SECURITY UPDATE: URI is not properly sanitized
     - debian/patches/CVE-2024-11234.patch: when using streams with configured
       proxy and "request_fulluri" option, the URI is not properly sanitized which
       can lead to HTTP request smuggling and allow the attacker to use the proxy to
       perform arbitrary HTTP requests originating from the server, thus potentially
       gaining access to resources not normally available to the external user
     - CVE-2024-11234
   * SECURITY UPDATE: incomplete check in escaping functions
     - debian/patches/CVE-2025-1735.patch: pgsql and pdo_pgsql escaping functions do
       not check if the underlying quoting functions returned errors. This could cause
       crashes if Postgres server rejects the string as invalid.
     - CVE-2025-1735</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: out-of-bounds access
     - debian/patches/CVE-2017-9118.patch: fix out of bounds access in php_pcre_replace_impl
     - CVE-2017-9118
   * SECURITY UPDATE: improper validation of HTTP_REDIRECT_STATUS variable in CGI
     binary
     - debian/patches/CVE-2024-8927.patch: fix Apache server name check; remove
       references to redirect.so and Netscape; check configuration override first
     - CVE-2024-8927
   * SECURITY UPDATE: buffer overread vulnerability
     - debian/patches/CVE-2024-11233.patch: move bound check upwards to fix
       single byte overread with convert.quoted-printable-decode filter
     - CVE-2024-11233
   * SECURITY UPDATE: URI is not properly sanitized
     - debian/patches/CVE-2024-11234.patch: when using streams with configured
       proxy and "request_fulluri" option, the URI is not properly sanitized which
       can lead to HTTP request smuggling and allow the attacker to use the proxy to
       perform arbitrary HTTP requests originating from the server, thus potentially
       gaining access to resources not normally available to the external user
     - CVE-2024-11234
   * SECURITY UPDATE: incomplete check in escaping functions
     - debian/patches/CVE-2025-1735.patch: pgsql and pdo_pgsql escaping functions do
       not check if the underlying quoting functions returned errors. This could cause
       crashes if Postgres server rejects the string as invalid.
     - CVE-2025-1735</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-27 15:01:32 UTC" />
    <updated date="2025-10-27 15:01:32 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761577285.html" id="CLSA-2025:1761577285" title="CLSA-2025:1761577285" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libapache2-mod-php7.3" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>libapache2-mod-php7.3_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">14af307772a82ccbdf768b811122fdc03cbd8b35</sum>
        </package>
        <package arch="amd64" name="libphp7.3-embed" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>libphp7.3-embed_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">66b09f9e0541beb8b54be0281b71b4757994a2a9</sum>
        </package>
        <package arch="all" name="php7.3" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3_7.3.31-1~deb10u7+tuxcare.els2_all.deb</filename>
          <sum type="sha">5474a5bf1c7d13d02b4bb34c701cc33824118ced</sum>
        </package>
        <package arch="amd64" name="php7.3-bcmath" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-bcmath_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">c0395b7c7d5d8332e194d05e43a35beda0576664</sum>
        </package>
        <package arch="amd64" name="php7.3-bz2" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-bz2_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">804323c55677cae40653d513ce48537d6917ec9e</sum>
        </package>
        <package arch="amd64" name="php7.3-cgi" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-cgi_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">428ee37b6a5585e3d1e6fa8642a6f5c480aa6306</sum>
        </package>
        <package arch="amd64" name="php7.3-cli" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-cli_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">cdaf217f13881232c59efe8442d01659572251de</sum>
        </package>
        <package arch="amd64" name="php7.3-common" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-common_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">005e70f76a41b8af6c56d802d4a39921e61aaa8c</sum>
        </package>
        <package arch="amd64" name="php7.3-curl" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-curl_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">44255e68e38ed0fd7ddc4691da086880ee05ad16</sum>
        </package>
        <package arch="amd64" name="php7.3-dba" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-dba_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">34e4f4097bd1bfb822a96c2097609208c9b55220</sum>
        </package>
        <package arch="amd64" name="php7.3-dev" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-dev_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">089300ada7f230e1907881fdf0d03ce5434b460b</sum>
        </package>
        <package arch="amd64" name="php7.3-enchant" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-enchant_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">99c0f92d54e07ad6a7726b8fc23e04cfc77225dd</sum>
        </package>
        <package arch="amd64" name="php7.3-fpm" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-fpm_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">d3f729d0f9cbac8c30b58508a6c76400e4461b98</sum>
        </package>
        <package arch="amd64" name="php7.3-gd" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-gd_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">36793ed98efe3766e4cd9b34b8243fb24b77db4d</sum>
        </package>
        <package arch="amd64" name="php7.3-gmp" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-gmp_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">e0d6f713334fd8aecc423d5f16dc4865c8ec0543</sum>
        </package>
        <package arch="amd64" name="php7.3-imap" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-imap_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">3ebb93b5d79541c84be9b6b759eeedd02e5360ca</sum>
        </package>
        <package arch="amd64" name="php7.3-interbase" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-interbase_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">4143f3ff430310df20cc2cef846c4646b1edcdf3</sum>
        </package>
        <package arch="amd64" name="php7.3-intl" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-intl_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">9b52ebac15c76e944db1c46a7854eec9fd4c9be4</sum>
        </package>
        <package arch="amd64" name="php7.3-json" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-json_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">fe401b391a511f0dd3fa899d31aea1b4d2447d7f</sum>
        </package>
        <package arch="amd64" name="php7.3-ldap" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-ldap_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">f3c42537a0614dbd8eda708594f2f47504f9b5c7</sum>
        </package>
        <package arch="amd64" name="php7.3-mbstring" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-mbstring_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">fb6d408012bb7f0488b7b7a8e89c304c9145a6e7</sum>
        </package>
        <package arch="amd64" name="php7.3-mysql" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-mysql_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">8cb26b1e237dafc245bd7895be82990ebe90820f</sum>
        </package>
        <package arch="amd64" name="php7.3-odbc" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-odbc_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">81ee827acb397f9de5452727ac3635a1fd8e44d2</sum>
        </package>
        <package arch="amd64" name="php7.3-opcache" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-opcache_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">b651ede498c0c8befca2895cce888f9e5c7ea954</sum>
        </package>
        <package arch="amd64" name="php7.3-pgsql" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-pgsql_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">5502f8eb3e17930d6f8cad2273465bf429092a73</sum>
        </package>
        <package arch="amd64" name="php7.3-phpdbg" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-phpdbg_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">3ffbb7f692ae8e817f5e8f3b0fd461ec9dd628f0</sum>
        </package>
        <package arch="amd64" name="php7.3-pspell" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-pspell_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">1fd64c13cef814dee86466cd636acdc86ec631d6</sum>
        </package>
        <package arch="amd64" name="php7.3-readline" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-readline_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">8e75cff8205e89f7896a7767d30e6a688b440b92</sum>
        </package>
        <package arch="amd64" name="php7.3-recode" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-recode_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">bbea46766369f38af79093493b42c5dcb293e3c6</sum>
        </package>
        <package arch="amd64" name="php7.3-snmp" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-snmp_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">519cf311ce183a8fc92d4b9ee598807b50ce94ea</sum>
        </package>
        <package arch="amd64" name="php7.3-soap" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-soap_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">311390e242d53c5bcc51f5ff63954ced42f602ea</sum>
        </package>
        <package arch="amd64" name="php7.3-sqlite3" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-sqlite3_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">0619a1142ef2915973d3742a3872c20d04537b32</sum>
        </package>
        <package arch="amd64" name="php7.3-sybase" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-sybase_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">c48a286e241ae38ffc81683e0befd7f894d1103b</sum>
        </package>
        <package arch="amd64" name="php7.3-tidy" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-tidy_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">6efd294c9e6d48ee2d864e2066c4ef08858f0aa4</sum>
        </package>
        <package arch="amd64" name="php7.3-xml" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-xml_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">0b41c6c0afe376f44f046ebb20c0fa99f5c8bf82</sum>
        </package>
        <package arch="amd64" name="php7.3-xmlrpc" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-xmlrpc_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">75f0420d185015f46111db3c408b876a946eb25d</sum>
        </package>
        <package arch="all" name="php7.3-xsl" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-xsl_7.3.31-1~deb10u7+tuxcare.els2_all.deb</filename>
          <sum type="sha">c5d68f8bc5db631cd6c9023446e6b9a3fcbfbe3f</sum>
        </package>
        <package arch="amd64" name="php7.3-zip" version="7.3.31-1~deb10u7+tuxcare.els2">
          <filename>php7.3-zip_7.3.31-1~deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">56d97ff12b7dbee23927329ad2ad8b4bab4c69df</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761577745</id>
    <title>Fix CVE(s): CVE-2020-35342</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: uninitialized-heap vulnerability in tic4x_print_cond
     function
     - debian/patches/CVE-2020-35342.patch: Initialize all elements of the
       condtable array to fix uninitialized heap memory issue in tic4x_print_cond
       function
     - CVE-2020-35342</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: uninitialized-heap vulnerability in tic4x_print_cond
     function
     - debian/patches/CVE-2020-35342.patch: Initialize all elements of the
       condtable array to fix uninitialized heap memory issue in tic4x_print_cond
       function
     - CVE-2020-35342</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-27 15:09:12 UTC" />
    <updated date="2025-10-27 15:09:12 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761577745.html" id="CLSA-2025:1761577745" title="CLSA-2025:1761577745" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="binutils" version="2.31.1-16+tuxcare.els4">
          <filename>binutils_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">ddc8c8b30158d4d31d43b5b244809b404a5ebd7c</sum>
        </package>
        <package arch="amd64" name="binutils-aarch64-linux-gnu" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-aarch64-linux-gnu_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">491037e9ef6df03a90b728b2a2780fa769d0f840</sum>
        </package>
        <package arch="amd64" name="binutils-alpha-linux-gnu" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-alpha-linux-gnu_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">08ef744838b05b327b579f80a01c1915695e46bc</sum>
        </package>
        <package arch="amd64" name="binutils-arm-linux-gnueabi" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-arm-linux-gnueabi_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">0d19fbfcffdee22e02bddb40922845fc15d4dc91</sum>
        </package>
        <package arch="amd64" name="binutils-arm-linux-gnueabihf" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-arm-linux-gnueabihf_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">564d88d28d811f6a60eeb08dcfca6163df2fa251</sum>
        </package>
        <package arch="amd64" name="binutils-common" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-common_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">e28eff71e1f9a22bdecd4bc7f5c2265e28829716</sum>
        </package>
        <package arch="amd64" name="binutils-dev" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-dev_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">be5f6f5876edeaee6f12f560f2e831f0a2bfe120</sum>
        </package>
        <package arch="all" name="binutils-doc" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-doc_2.31.1-16+tuxcare.els4_all.deb</filename>
          <sum type="sha">3d2ef2d57cdb3b18eb446e110b8d8876376ab2a7</sum>
        </package>
        <package arch="all" name="binutils-for-build" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-for-build_2.31.1-16+tuxcare.els4_all.deb</filename>
          <sum type="sha">1b0d10a33ec8218fbfc3b64dd5250b0760a6ec5c</sum>
        </package>
        <package arch="amd64" name="binutils-for-host" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-for-host_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">7d0ed91177b8b3141474f0a57cf335ad595e4969</sum>
        </package>
        <package arch="amd64" name="binutils-hppa-linux-gnu" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-hppa-linux-gnu_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">5037c979e376459df7cefed261e1a845ede473e4</sum>
        </package>
        <package arch="amd64" name="binutils-hppa64-linux-gnu" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-hppa64-linux-gnu_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">8567f7f46aae2cef8a247b53d42d367e795cccfb</sum>
        </package>
        <package arch="amd64" name="binutils-i686-gnu" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-i686-gnu_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">04c5d37c7020c44a490b02d4a068407cdf09f3cf</sum>
        </package>
        <package arch="amd64" name="binutils-i686-kfreebsd-gnu" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-i686-kfreebsd-gnu_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">662804df901c5966e7cee566b9d63bb215ec29d5</sum>
        </package>
        <package arch="amd64" name="binutils-i686-linux-gnu" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-i686-linux-gnu_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">c14f3684102668b1b235a0714c112a127ac81900</sum>
        </package>
        <package arch="amd64" name="binutils-ia64-linux-gnu" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-ia64-linux-gnu_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">5124ea2bf214a3ab54e2aabfb5fac4b2caac44f9</sum>
        </package>
        <package arch="amd64" name="binutils-m68k-linux-gnu" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-m68k-linux-gnu_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">ad1463a35af5cf6a49c53eae68e4baff7a9272bf</sum>
        </package>
        <package arch="amd64" name="binutils-mips-linux-gnu" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-mips-linux-gnu_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">cd31ad87bebdf046250be99a7ac41dd4dc21f7da</sum>
        </package>
        <package arch="amd64" name="binutils-mips64el-linux-gnuabi64" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-mips64el-linux-gnuabi64_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">d3e1b4e6cf8a65ea8fa8679ef9323ee874f02a0d</sum>
        </package>
        <package arch="amd64" name="binutils-mipsel-linux-gnu" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-mipsel-linux-gnu_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">f1b63f3d5c0e5f96d7b2e132df482e1d95818888</sum>
        </package>
        <package arch="amd64" name="binutils-multiarch" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-multiarch_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">518f880ecf95a2704f573be46418707ed6fbf331</sum>
        </package>
        <package arch="amd64" name="binutils-multiarch-dev" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-multiarch-dev_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">40bcaa0dafc18cfc0ced9319ccd06b666357c13f</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc-linux-gnu" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-powerpc-linux-gnu_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">abfafbf7048d428446afa063758b997b6fde6bba</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc-linux-gnuspe" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-powerpc-linux-gnuspe_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">ab276c2f54075d0038abbb1578c6b52e249d7573</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc64-linux-gnu" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-powerpc64-linux-gnu_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">24a8b6c7c3077e12996255dadd624882dd9f19b4</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc64le-linux-gnu" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-powerpc64le-linux-gnu_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">91b7c7b7a8813919ab50418444c7c3adc881f9d9</sum>
        </package>
        <package arch="amd64" name="binutils-riscv64-linux-gnu" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-riscv64-linux-gnu_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">03d845a992ec1aab4eb29922cd27ea2980d4ca67</sum>
        </package>
        <package arch="amd64" name="binutils-s390x-linux-gnu" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-s390x-linux-gnu_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">60fbceb19e37dbe378c517fe125d0d37ca08f344</sum>
        </package>
        <package arch="amd64" name="binutils-sh4-linux-gnu" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-sh4-linux-gnu_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">1104975ef2a829285b3529dfe1f90a8dfd15c964</sum>
        </package>
        <package arch="all" name="binutils-source" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-source_2.31.1-16+tuxcare.els4_all.deb</filename>
          <sum type="sha">8f2fcc4118568494ca4521c663924d77c2e45e74</sum>
        </package>
        <package arch="amd64" name="binutils-sparc64-linux-gnu" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-sparc64-linux-gnu_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">00198adb02a218ca276f70ae429807767a6f25cb</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-kfreebsd-gnu" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-x86-64-kfreebsd-gnu_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">ac4a169b2f4f82c9f922cef39a6a24ebcc10f519</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-linux-gnu" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-x86-64-linux-gnu_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">e1fb362a6cbe5e55e72ba0fc5c628e5b1524b3b1</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-linux-gnux32" version="2.31.1-16+tuxcare.els4">
          <filename>binutils-x86-64-linux-gnux32_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">17b862cad4dcdf83b1d5a45975add76172e10eb0</sum>
        </package>
        <package arch="amd64" name="libbinutils" version="2.31.1-16+tuxcare.els4">
          <filename>libbinutils_2.31.1-16+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">feac8ca92eb10919a95b6fb54ddfbbaa62fbc58e</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761673667</id>
    <title>Fix CVE(s): CVE-2019-20044</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: insecure privilege dropping vulnerability
     - debian/patches/CVE-2019-20044-*.patch: improve error handling in
       setopt command, add OpenSSH-based setresuid/setresgid wrappers,
       simplify and secure privilege dropping logic, add comprehensive
       tests for PRIVILEGED option
     - CVE-2019-20044</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: insecure privilege dropping vulnerability
     - debian/patches/CVE-2019-20044-*.patch: improve error handling in
       setopt command, add OpenSSH-based setresuid/setresgid wrappers,
       simplify and secure privilege dropping logic, add comprehensive
       tests for PRIVILEGED option
     - CVE-2019-20044</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-28 17:47:51 UTC" />
    <updated date="2025-10-28 17:47:51 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761673667.html" id="CLSA-2025:1761673667" title="CLSA-2025:1761673667" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="zsh" version="5.7.1-1+deb10u1+tuxcare.els1">
          <filename>zsh_5.7.1-1+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">bc7022c352b4dfeeaaab2f40872b2c6f57f2a381</sum>
        </package>
        <package arch="all" name="zsh-common" version="5.7.1-1+deb10u1+tuxcare.els1">
          <filename>zsh-common_5.7.1-1+deb10u1+tuxcare.els1_all.deb</filename>
          <sum type="sha">4f20c7a66dd2fde2f36fa38bc9adc03ede4533c6</sum>
        </package>
        <package arch="amd64" name="zsh-dev" version="5.7.1-1+deb10u1+tuxcare.els1">
          <filename>zsh-dev_5.7.1-1+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">27c6bffacec3093ff27abaece2a20c0e486c5bf3</sum>
        </package>
        <package arch="all" name="zsh-doc" version="5.7.1-1+deb10u1+tuxcare.els1">
          <filename>zsh-doc_5.7.1-1+deb10u1+tuxcare.els1_all.deb</filename>
          <sum type="sha">128f0a8beeecacb229aca8c806a481754e2738b6</sum>
        </package>
        <package arch="amd64" name="zsh-static" version="5.7.1-1+deb10u1+tuxcare.els1">
          <filename>zsh-static_5.7.1-1+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">d29d9b3c9968d3c0ac03c21af5c27851a9411f21</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761744879</id>
    <title>Fix CVE(s): CVE-2019-9923</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: NULL pointer dereference
     - debian/patches/CVE-2019-9923.patch: fix a NULL pointer dereference when
       parsing certain archives that have malformed extended headers in
       pax_decode_header() in sparse.c
     - CVE-2019-9923</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: NULL pointer dereference
     - debian/patches/CVE-2019-9923.patch: fix a NULL pointer dereference when
       parsing certain archives that have malformed extended headers in
       pax_decode_header() in sparse.c
     - CVE-2019-9923</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-29 13:34:44 UTC" />
    <updated date="2025-10-29 13:34:44 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761744879.html" id="CLSA-2025:1761744879" title="CLSA-2025:1761744879" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="tar" version="1.30+dfsg-6+deb10u1+tuxcare.els1">
          <filename>tar_1.30+dfsg-6+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">b7ba2b0d3b0300aa921970ed440aa538e7815ca7</sum>
        </package>
        <package arch="amd64" name="tar-scripts" version="1.30+dfsg-6+deb10u1+tuxcare.els1">
          <filename>tar-scripts_1.30+dfsg-6+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">5969dae34a60a03db86fdc96a06356a563a7e607</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761744996</id>
    <title>Fix CVE(s): CVE-2022-1927, CVE-2022-2042, CVE-2022-2581, CVE-2022-2849</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Buffer Over-read because of invalid cursor position
     after "0;" range
     - debian/patches/CVE-2022-1927.patch: check the cursor position when
       it was set by ";" in the range
     - CVE-2022-1927
   * SECURITY UPDATE: Use After Free in spell command
     - debian/patches/CVE-2022-2042.patch: initialize "attr", check for
       empty line early
     - CVE-2022-2042
   * SECURITY UPDATE: Out-of-bounds Read when regex pattern starts with
     illegal byte
     - debian/patches/CVE-2022-2581.patch: do not match a character with an
       illegal byte
     - CVE-2022-2581
   * SECURITY UPDATE: Heap-based Buffer Overflow with for loop over NULL
     string
     - debian/patches/CVE-2022-2849.patch: make sure mb_ptr2len()
       consistently returns zero for NUL
     - CVE-2022-2849</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Buffer Over-read because of invalid cursor position
     after "0;" range
     - debian/patches/CVE-2022-1927.patch: check the cursor position when
       it was set by ";" in the range
     - CVE-2022-1927
   * SECURITY UPDATE: Use After Free in spell command
     - debian/patches/CVE-2022-2042.patch: initialize "attr", check for
       empty line early
     - CVE-2022-2042
   * SECURITY UPDATE: Out-of-bounds Read when regex pattern starts with
     illegal byte
     - debian/patches/CVE-2022-2581.patch: do not match a character with an
       illegal byte
     - CVE-2022-2581
   * SECURITY UPDATE: Heap-based Buffer Overflow with for loop over NULL
     string
     - debian/patches/CVE-2022-2849.patch: make sure mb_ptr2len()
       consistently returns zero for NUL
     - CVE-2022-2849</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-29 13:36:40 UTC" />
    <updated date="2025-10-29 13:36:40 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761744996.html" id="CLSA-2025:1761744996" title="CLSA-2025:1761744996" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="vim" version="2:8.1.0875-5+deb10u6+tuxcare.els3">
          <filename>vim_8.1.0875-5+deb10u6+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">31c38873b108f950becafc12b1445c83acb950b0</sum>
        </package>
        <package arch="amd64" name="vim-athena" version="2:8.1.0875-5+deb10u6+tuxcare.els3">
          <filename>vim-athena_8.1.0875-5+deb10u6+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">209509ab565e940b5edabf7c2c31a65852430ba6</sum>
        </package>
        <package arch="all" name="vim-common" version="2:8.1.0875-5+deb10u6+tuxcare.els3">
          <filename>vim-common_8.1.0875-5+deb10u6+tuxcare.els3_all.deb</filename>
          <sum type="sha">7e679dc72ecbc8f9446961bd78ab903176109243</sum>
        </package>
        <package arch="all" name="vim-doc" version="2:8.1.0875-5+deb10u6+tuxcare.els3">
          <filename>vim-doc_8.1.0875-5+deb10u6+tuxcare.els3_all.deb</filename>
          <sum type="sha">5673ccb08f6bbddf9d5aac7f08cbc7a8960fabe6</sum>
        </package>
        <package arch="amd64" name="vim-gtk" version="2:8.1.0875-5+deb10u6+tuxcare.els3">
          <filename>vim-gtk_8.1.0875-5+deb10u6+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">f282d4b4f85446a192259dd1c3a291bd1f86eb5e</sum>
        </package>
        <package arch="amd64" name="vim-gtk3" version="2:8.1.0875-5+deb10u6+tuxcare.els3">
          <filename>vim-gtk3_8.1.0875-5+deb10u6+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">2366cc31225102957182adbf61d8b5e01d42ffe8</sum>
        </package>
        <package arch="all" name="vim-gui-common" version="2:8.1.0875-5+deb10u6+tuxcare.els3">
          <filename>vim-gui-common_8.1.0875-5+deb10u6+tuxcare.els3_all.deb</filename>
          <sum type="sha">7c5d19ea742e6b5a90059e1d02532bea7528fc0b</sum>
        </package>
        <package arch="amd64" name="vim-nox" version="2:8.1.0875-5+deb10u6+tuxcare.els3">
          <filename>vim-nox_8.1.0875-5+deb10u6+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">e8bcb7161d4ff2943b579b2ec2a71093c57a4c41</sum>
        </package>
        <package arch="all" name="vim-runtime" version="2:8.1.0875-5+deb10u6+tuxcare.els3">
          <filename>vim-runtime_8.1.0875-5+deb10u6+tuxcare.els3_all.deb</filename>
          <sum type="sha">8bc1b361f38240005fe614b542ed89cc77711fe0</sum>
        </package>
        <package arch="amd64" name="vim-tiny" version="2:8.1.0875-5+deb10u6+tuxcare.els3">
          <filename>vim-tiny_8.1.0875-5+deb10u6+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">3a6d73f74307172e07c8c979a3088c88aa10e7da</sum>
        </package>
        <package arch="amd64" name="xxd" version="2:8.1.0875-5+deb10u6+tuxcare.els3">
          <filename>xxd_8.1.0875-5+deb10u6+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">ed57cadac2e131f0705a883632dd757939fc3a85</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761747106</id>
    <title>Fix CVE(s): CVE-2024-38477</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: null pointer dereference in mod_proxy
     - debian/patches/CVE-2024-38477.patch: validate hostname in
       modules/proxy/proxy_util.c. Restart from the original URL
       on reconnect in modules/http2/mod_proxy_http2.c.
     - CVE-2024-38477</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: null pointer dereference in mod_proxy
     - debian/patches/CVE-2024-38477.patch: validate hostname in
       modules/proxy/proxy_util.c. Restart from the original URL
       on reconnect in modules/http2/mod_proxy_http2.c.
     - CVE-2024-38477</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-29 14:11:50 UTC" />
    <updated date="2025-10-29 14:11:50 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761747106.html" id="CLSA-2025:1761747106" title="CLSA-2025:1761747106" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="apache2" version="2.4.59-1~deb10u1+tuxcare.els3">
          <filename>apache2_2.4.59-1~deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">d83e4564fc823504bdeba508d2019eaeba290fb3</sum>
        </package>
        <package arch="amd64" name="apache2-bin" version="2.4.59-1~deb10u1+tuxcare.els3">
          <filename>apache2-bin_2.4.59-1~deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">246e02afdd5946df6c2fe12d53051eb5e4a15342</sum>
        </package>
        <package arch="all" name="apache2-data" version="2.4.59-1~deb10u1+tuxcare.els3">
          <filename>apache2-data_2.4.59-1~deb10u1+tuxcare.els3_all.deb</filename>
          <sum type="sha">3ee2d1d74a9695141e75e9545066f859a7a54342</sum>
        </package>
        <package arch="amd64" name="apache2-dev" version="2.4.59-1~deb10u1+tuxcare.els3">
          <filename>apache2-dev_2.4.59-1~deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">dd87ce92ea3d426433c572e334b4ec6386ea2b9c</sum>
        </package>
        <package arch="all" name="apache2-doc" version="2.4.59-1~deb10u1+tuxcare.els3">
          <filename>apache2-doc_2.4.59-1~deb10u1+tuxcare.els3_all.deb</filename>
          <sum type="sha">78c4eab1978adec52c7852492151c2637df0050c</sum>
        </package>
        <package arch="amd64" name="apache2-ssl-dev" version="2.4.59-1~deb10u1+tuxcare.els3">
          <filename>apache2-ssl-dev_2.4.59-1~deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">cf1694d0862bc5edfb5de855bbe4f6da573ec7a4</sum>
        </package>
        <package arch="amd64" name="apache2-suexec-custom" version="2.4.59-1~deb10u1+tuxcare.els3">
          <filename>apache2-suexec-custom_2.4.59-1~deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">51d40dc91bc5335bafbff5da74cbd57426aeeba8</sum>
        </package>
        <package arch="amd64" name="apache2-suexec-pristine" version="2.4.59-1~deb10u1+tuxcare.els3">
          <filename>apache2-suexec-pristine_2.4.59-1~deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">541d091b57ed8de95aa8ae8f7c43ec603119d01b</sum>
        </package>
        <package arch="amd64" name="apache2-utils" version="2.4.59-1~deb10u1+tuxcare.els3">
          <filename>apache2-utils_2.4.59-1~deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">f6b89ecf4f9be6078c80ae87062a762c2fa054cf</sum>
        </package>
        <package arch="amd64" name="libapache2-mod-md" version="2.4.59-1~deb10u1+tuxcare.els3">
          <filename>libapache2-mod-md_2.4.59-1~deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">5507831b6565f403131645702831a2c8186b4389</sum>
        </package>
        <package arch="amd64" name="libapache2-mod-proxy-uwsgi" version="2.4.59-1~deb10u1+tuxcare.els3">
          <filename>libapache2-mod-proxy-uwsgi_2.4.59-1~deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">55fddff6effef7bb7dc3b3b8845f8ba2fe0501e8</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761844758</id>
    <title>Fix CVE(s): CVE-2024-1013</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: out-of-bounds stack write flaw in 64-bit architectures
     - debian/patches/CVE-2024-1013.patch: Fix incompatible pointer-to-integer
       types causing out-of-bounds stack writes on 64-bit architectures
     - CVE-2024-1013</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: out-of-bounds stack write flaw in 64-bit architectures
     - debian/patches/CVE-2024-1013.patch: Fix incompatible pointer-to-integer
       types causing out-of-bounds stack writes on 64-bit architectures
     - CVE-2024-1013</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-30 17:19:22 UTC" />
    <updated date="2025-10-30 17:19:22 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761844758.html" id="CLSA-2025:1761844758" title="CLSA-2025:1761844758" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libodbc1" version="2.3.6-0.1+tuxcare.els1">
          <filename>libodbc1_2.3.6-0.1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">68c1064f9a63341da089509dd47234e80f52ffc3</sum>
        </package>
        <package arch="amd64" name="odbcinst" version="2.3.6-0.1+tuxcare.els1">
          <filename>odbcinst_2.3.6-0.1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">08040910fcc60e9ff77afdff8aa76fddb2124783</sum>
        </package>
        <package arch="amd64" name="odbcinst1debian2" version="2.3.6-0.1+tuxcare.els1">
          <filename>odbcinst1debian2_2.3.6-0.1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">79b6231f08cca2a94bc2b504c82ab64c6f6ef83d</sum>
        </package>
        <package arch="amd64" name="unixodbc" version="2.3.6-0.1+tuxcare.els1">
          <filename>unixodbc_2.3.6-0.1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">85dbd3a4d78a8406301fc6dae693c9e5809f91dc</sum>
        </package>
        <package arch="amd64" name="unixodbc-dev" version="2.3.6-0.1+tuxcare.els1">
          <filename>unixodbc-dev_2.3.6-0.1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">9379243fe64165c9a4bff107b98f365ac0a5d9f7</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761847256</id>
    <title>Fix CVE(s): CVE-2022-47673, CVE-2023-25584</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: multiple vulnerabilities in vms-alpha.c parse_module
     - debian/patches/CVE-2022-47673_CVE-2023-25584-*.patch: fix null pointer
       dereference in parse_module by adding return value checking for
       bfd_zalloc calls, fix potential out of bounds memory access
       in DST record parsing loop
     - CVE-2022-47673, CVE-2023-25584</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: multiple vulnerabilities in vms-alpha.c parse_module
     - debian/patches/CVE-2022-47673_CVE-2023-25584-*.patch: fix null pointer
       dereference in parse_module by adding return value checking for
       bfd_zalloc calls, fix potential out of bounds memory access
       in DST record parsing loop
     - CVE-2022-47673, CVE-2023-25584</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-30 18:00:59 UTC" />
    <updated date="2025-10-30 18:00:59 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761847256.html" id="CLSA-2025:1761847256" title="CLSA-2025:1761847256" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="binutils" version="2.31.1-16+tuxcare.els5">
          <filename>binutils_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">f6a73cd95969afae0d3d21e417e22a96e2d69e77</sum>
        </package>
        <package arch="amd64" name="binutils-aarch64-linux-gnu" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-aarch64-linux-gnu_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">cb465f93dca7328cdc651274691c170980f44ec7</sum>
        </package>
        <package arch="amd64" name="binutils-alpha-linux-gnu" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-alpha-linux-gnu_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">b4ea31ac5805feddac60f224631189ca33ef70e8</sum>
        </package>
        <package arch="amd64" name="binutils-arm-linux-gnueabi" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-arm-linux-gnueabi_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">ea0592912a676156f289b85576f0f47c8949facd</sum>
        </package>
        <package arch="amd64" name="binutils-arm-linux-gnueabihf" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-arm-linux-gnueabihf_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">4c7f1376ceda4d6c5ebc57d8122a77c8d4a211a3</sum>
        </package>
        <package arch="amd64" name="binutils-common" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-common_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">c29c7b004bbf03408aed92bfaf02aa7b6a55ac37</sum>
        </package>
        <package arch="amd64" name="binutils-dev" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-dev_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">d0f0ba274c7d00f388709a42d449b658f9dbfe06</sum>
        </package>
        <package arch="all" name="binutils-doc" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-doc_2.31.1-16+tuxcare.els5_all.deb</filename>
          <sum type="sha">35f8a7acb254ffd4281b2bcc3c9d6531171de473</sum>
        </package>
        <package arch="all" name="binutils-for-build" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-for-build_2.31.1-16+tuxcare.els5_all.deb</filename>
          <sum type="sha">85797276219a5909e3c9c4ed12ca7d76f952466c</sum>
        </package>
        <package arch="amd64" name="binutils-for-host" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-for-host_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">38a72144c8bfce5ef82988bc052bfae91d363e35</sum>
        </package>
        <package arch="amd64" name="binutils-hppa-linux-gnu" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-hppa-linux-gnu_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">8c52e352894141eaf9e7826783e8ae2458e2bfb1</sum>
        </package>
        <package arch="amd64" name="binutils-hppa64-linux-gnu" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-hppa64-linux-gnu_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">9cd633f16f82c4296761ed4e64736c018094b96a</sum>
        </package>
        <package arch="amd64" name="binutils-i686-gnu" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-i686-gnu_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">faf4091383692c402e10ad9763bee8345ea7e02b</sum>
        </package>
        <package arch="amd64" name="binutils-i686-kfreebsd-gnu" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-i686-kfreebsd-gnu_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">bcbec67a4818ae8c1d0d3c35199401037c454ebe</sum>
        </package>
        <package arch="amd64" name="binutils-i686-linux-gnu" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-i686-linux-gnu_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">45bf44c04a2611b9fe0340a49da6e9c318673cf0</sum>
        </package>
        <package arch="amd64" name="binutils-ia64-linux-gnu" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-ia64-linux-gnu_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">f45b20b188baa4f27d9b0edcd9b643882758eb60</sum>
        </package>
        <package arch="amd64" name="binutils-m68k-linux-gnu" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-m68k-linux-gnu_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">267242036edeca80b8a519ece047fc9beaa42ff8</sum>
        </package>
        <package arch="amd64" name="binutils-mips-linux-gnu" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-mips-linux-gnu_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">b52544e1b754ea46b6325e19d0eec4f61cfb1062</sum>
        </package>
        <package arch="amd64" name="binutils-mips64el-linux-gnuabi64" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-mips64el-linux-gnuabi64_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">099f2cbafd8435b3fbc13f5aee53df2b522b2e76</sum>
        </package>
        <package arch="amd64" name="binutils-mipsel-linux-gnu" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-mipsel-linux-gnu_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">3c0d152fd8b8bfb4af75d5ac2d960447273e40cd</sum>
        </package>
        <package arch="amd64" name="binutils-multiarch" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-multiarch_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">3c6a1bb94cedd5518a8ffbd08a90056bf2dcc59e</sum>
        </package>
        <package arch="amd64" name="binutils-multiarch-dev" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-multiarch-dev_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">68c7cd21b21763e37df33a764803dc0e3ce99db6</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc-linux-gnu" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-powerpc-linux-gnu_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">13238e8dc607c400f8a69a17512537ef31502a78</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc-linux-gnuspe" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-powerpc-linux-gnuspe_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">29ab1431b01ffd146cf6d353ebebcad42bb293a1</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc64-linux-gnu" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-powerpc64-linux-gnu_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">b010db497eae77080203c95f4b21bb8f9035af1a</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc64le-linux-gnu" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-powerpc64le-linux-gnu_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">d50b97480a08a74dab9736aa3f7f69de767ea654</sum>
        </package>
        <package arch="amd64" name="binutils-riscv64-linux-gnu" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-riscv64-linux-gnu_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">5d58fee744cf5fcac4bc5a107a5c75e99098fde1</sum>
        </package>
        <package arch="amd64" name="binutils-s390x-linux-gnu" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-s390x-linux-gnu_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">9278c512f96f6fe4fc2f8d149898a3d4721df8d5</sum>
        </package>
        <package arch="amd64" name="binutils-sh4-linux-gnu" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-sh4-linux-gnu_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">3f8d0823bd803e4e33284297fbdebbdfa820bc22</sum>
        </package>
        <package arch="all" name="binutils-source" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-source_2.31.1-16+tuxcare.els5_all.deb</filename>
          <sum type="sha">b164eb7fdae81539f7c9db116c5d8786c324d0e3</sum>
        </package>
        <package arch="amd64" name="binutils-sparc64-linux-gnu" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-sparc64-linux-gnu_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">b31a4f389a7a8b6aa0bf739ed236d9de848b1289</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-kfreebsd-gnu" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-x86-64-kfreebsd-gnu_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">90b62d116e6030ff83fa569b78a58781d90bf8db</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-linux-gnu" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-x86-64-linux-gnu_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">37fb946ec45e13443439dc3fa6f560951ede5d78</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-linux-gnux32" version="2.31.1-16+tuxcare.els5">
          <filename>binutils-x86-64-linux-gnux32_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">f7aa47c6b617e83d0880979839f6367b32fc98ea</sum>
        </package>
        <package arch="amd64" name="libbinutils" version="2.31.1-16+tuxcare.els5">
          <filename>libbinutils_2.31.1-16+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">3a0694b14e5bda7dc90505d38febc0ca98f31749</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761844638</id>
    <title>Fix CVE(s): CVE-2023-49288, CVE-2023-5824</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: excessive cached HTTP response header size causing worker
     process stall or crash
     - debian/patches/CVE-2023-5824.patch: Refactor serialized HTTP response header
       handling to prevent cache flow
     - CVE-2023-5824
   * SECURITY UPDATE: Use-After-Free in the HTTP Collapsed Forwarding Feature
     - debian/patches/CVE-2023-5824.patch: Removed Use-After-Free during refactor
       serialized HTTP response header
     - CVE-2023-49288</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: excessive cached HTTP response header size causing worker
     process stall or crash
     - debian/patches/CVE-2023-5824.patch: Refactor serialized HTTP response header
       handling to prevent cache flow
     - CVE-2023-5824
   * SECURITY UPDATE: Use-After-Free in the HTTP Collapsed Forwarding Feature
     - debian/patches/CVE-2023-5824.patch: Removed Use-After-Free during refactor
       serialized HTTP response header
     - CVE-2023-49288</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-30 18:04:01 UTC" />
    <updated date="2025-10-30 18:04:01 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761844638.html" id="CLSA-2025:1761844638" title="CLSA-2025:1761844638" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="squid" version="4.6-1+deb10u10+tuxcare.els2">
          <filename>squid_4.6-1+deb10u10+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">61389a7d8d90e0c2aa552e6af168563d306e8180</sum>
        </package>
        <package arch="amd64" name="squid-cgi" version="4.6-1+deb10u10+tuxcare.els2">
          <filename>squid-cgi_4.6-1+deb10u10+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">049bf2f62618327e6af0aafdcd85d199ecaa6530</sum>
        </package>
        <package arch="all" name="squid-common" version="4.6-1+deb10u10+tuxcare.els2">
          <filename>squid-common_4.6-1+deb10u10+tuxcare.els2_all.deb</filename>
          <sum type="sha">77a0b018cd96d82672259c29fcb1ee9991d408e7</sum>
        </package>
        <package arch="amd64" name="squid-purge" version="4.6-1+deb10u10+tuxcare.els2">
          <filename>squid-purge_4.6-1+deb10u10+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">9b7eb9d08a392679a227e4585c489e4486660f06</sum>
        </package>
        <package arch="all" name="squid3" version="4.6-1+deb10u10+tuxcare.els2">
          <filename>squid3_4.6-1+deb10u10+tuxcare.els2_all.deb</filename>
          <sum type="sha">969e9b17da22c7ad343e60467ae66c757241d70f</sum>
        </package>
        <package arch="amd64" name="squidclient" version="4.6-1+deb10u10+tuxcare.els2">
          <filename>squidclient_4.6-1+deb10u10+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">a026e9e0418d7c87ca49311681d3508ce5c5977e</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761845210</id>
    <title>Fix CVE(s): CVE-2022-1733, CVE-2022-1796, CVE-2022-1886, CVE-2022-3016</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Heap-based Buffer Overflow
   - debian/patches/CVE-2022-1733.patch: Check for NUL to prevent
     reading past end of the line when C-indenting
   - CVE-2022-1733
   * SECURITY UPDATE: Use After Free
   - debian/patches/CVE-2022-1796.patch: Fix accessing freed memory when line
     is flushed by making a copy of the search pattern
   - CVE-2022-1796
   * SECURITY UPDATE: Heap-based Buffer Overflow
   - debian/patches/CVE-2022-1886.patch: Check the length is more than zero
     to fix access before start of text with a put command
   - CVE-2022-1886
   * SECURITY UPDATE: Use After Free
   - debian/patches/CVE-2022-3016.patch: Return QF_ABORT when location
     list changed in autocmd
   - CVE-2022-3016</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Heap-based Buffer Overflow
   - debian/patches/CVE-2022-1733.patch: Check for NUL to prevent
     reading past end of the line when C-indenting
   - CVE-2022-1733
   * SECURITY UPDATE: Use After Free
   - debian/patches/CVE-2022-1796.patch: Fix accessing freed memory when line
     is flushed by making a copy of the search pattern
   - CVE-2022-1796
   * SECURITY UPDATE: Heap-based Buffer Overflow
   - debian/patches/CVE-2022-1886.patch: Check the length is more than zero
     to fix access before start of text with a put command
   - CVE-2022-1886
   * SECURITY UPDATE: Use After Free
   - debian/patches/CVE-2022-3016.patch: Return QF_ABORT when location
     list changed in autocmd
   - CVE-2022-3016</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-30 18:06:08 UTC" />
    <updated date="2025-10-30 18:06:08 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761845210.html" id="CLSA-2025:1761845210" title="CLSA-2025:1761845210" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="vim" version="2:8.1.0875-5+deb10u6+tuxcare.els5">
          <filename>vim_8.1.0875-5+deb10u6+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">c10968f2f1b7dabe40eedbf0de59161e805a4e73</sum>
        </package>
        <package arch="amd64" name="vim-athena" version="2:8.1.0875-5+deb10u6+tuxcare.els5">
          <filename>vim-athena_8.1.0875-5+deb10u6+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">fce7d20bf450c4140acb7d9944b3afa45d17f817</sum>
        </package>
        <package arch="all" name="vim-common" version="2:8.1.0875-5+deb10u6+tuxcare.els5">
          <filename>vim-common_8.1.0875-5+deb10u6+tuxcare.els5_all.deb</filename>
          <sum type="sha">4f4f9ea66a32349a2639c07c1816f371fee1a441</sum>
        </package>
        <package arch="all" name="vim-doc" version="2:8.1.0875-5+deb10u6+tuxcare.els5">
          <filename>vim-doc_8.1.0875-5+deb10u6+tuxcare.els5_all.deb</filename>
          <sum type="sha">352378dd7bad30e6b01f32a44960d3fc53dc5f48</sum>
        </package>
        <package arch="amd64" name="vim-gtk" version="2:8.1.0875-5+deb10u6+tuxcare.els5">
          <filename>vim-gtk_8.1.0875-5+deb10u6+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">8157c9b930756f562a98b786bfc228399b14833b</sum>
        </package>
        <package arch="amd64" name="vim-gtk3" version="2:8.1.0875-5+deb10u6+tuxcare.els5">
          <filename>vim-gtk3_8.1.0875-5+deb10u6+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">3d1549ce192466a9518e1bbd7a1a8433614bd6f1</sum>
        </package>
        <package arch="all" name="vim-gui-common" version="2:8.1.0875-5+deb10u6+tuxcare.els5">
          <filename>vim-gui-common_8.1.0875-5+deb10u6+tuxcare.els5_all.deb</filename>
          <sum type="sha">35c0896361ce9ebbfbf6c1ca92df5c5bb96a1d94</sum>
        </package>
        <package arch="amd64" name="vim-nox" version="2:8.1.0875-5+deb10u6+tuxcare.els5">
          <filename>vim-nox_8.1.0875-5+deb10u6+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">6004aaca43fbf2fa55a0b926b2dfc41f17e4ebba</sum>
        </package>
        <package arch="all" name="vim-runtime" version="2:8.1.0875-5+deb10u6+tuxcare.els5">
          <filename>vim-runtime_8.1.0875-5+deb10u6+tuxcare.els5_all.deb</filename>
          <sum type="sha">33f48e14361be0127e4da02495fa93e358228a2e</sum>
        </package>
        <package arch="amd64" name="vim-tiny" version="2:8.1.0875-5+deb10u6+tuxcare.els5">
          <filename>vim-tiny_8.1.0875-5+deb10u6+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">472b9e20221f48ac388524440a684e63f5315d39</sum>
        </package>
        <package arch="amd64" name="xxd" version="2:8.1.0875-5+deb10u6+tuxcare.els5">
          <filename>xxd_8.1.0875-5+deb10u6+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">b511091b79ac5f02d54230f9f24ec7c4ccd58405</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761844489</id>
    <title>Fix of 9 CVEs</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: multiple vulnerabilities in AWK implementation
     - debian/patches/CVE-2021-423xx-awk.patch: fix issues with argument parsing,
       delete statement validation, length() parsing, post-increment/decrement on
       literals, expression handling, regex splitting, use-after-realloc, and
       maxfields underflow
     - CVE-2021-42378
     - CVE-2021-42379
     - CVE-2021-42380
     - CVE-2021-42381
     - CVE-2021-42382
     - CVE-2021-42384
     - CVE-2021-42385
     - CVE-2021-42386</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: multiple vulnerabilities in AWK implementation
     - debian/patches/CVE-2021-423xx-awk.patch: fix issues with argument parsing,
       delete statement validation, length() parsing, post-increment/decrement on
       literals, expression handling, regex splitting, use-after-realloc, and
       maxfields underflow
     - CVE-2021-42378
     - CVE-2021-42379
     - CVE-2021-42380
     - CVE-2021-42381
     - CVE-2021-42382
     - CVE-2021-42384
     - CVE-2021-42385
     - CVE-2021-42386</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-30 18:32:32 UTC" />
    <updated date="2025-10-30 18:32:32 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761844489.html" id="CLSA-2025:1761844489" title="CLSA-2025:1761844489" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="busybox" version="1:1.30.1-4+tuxcare.els2">
          <filename>busybox_1.30.1-4+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">cebd3f054c0eefa7aa908fde674142980f2da377</sum>
        </package>
        <package arch="amd64" name="busybox-static" version="1:1.30.1-4+tuxcare.els2">
          <filename>busybox-static_1.30.1-4+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">d3df845c8cd0685742c848387e6fad0bcda2222b</sum>
        </package>
        <package arch="all" name="busybox-syslogd" version="1:1.30.1-4+tuxcare.els2">
          <filename>busybox-syslogd_1.30.1-4+tuxcare.els2_all.deb</filename>
          <sum type="sha">ccea7d3441d296c28e5e2caf1e53cd24d0f1f5f0</sum>
        </package>
        <package arch="amd64" name="udhcpc" version="1:1.30.1-4+tuxcare.els2">
          <filename>udhcpc_1.30.1-4+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">d74ad862be831bd7aa7210d6fccd7dce0b26e69e</sum>
        </package>
        <package arch="amd64" name="udhcpd" version="1:1.30.1-4+tuxcare.els2">
          <filename>udhcpd_1.30.1-4+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">03720af70c72cc3b8c85c353864aade307bf5375</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761849390</id>
    <title>Fix CVE(s): CVE-2022-47695</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: denial of service via bfd_mach_o_get_synthetic_symtab in
     match-o.c
     - debian/patches/CVE-2022-47695.patch: Fix segmentation fault in
       compare_symbols function by excluding section and synthetic symbols before
       checking symbol flags
     - CVE-2022-47695</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: denial of service via bfd_mach_o_get_synthetic_symtab in
     match-o.c
     - debian/patches/CVE-2022-47695.patch: Fix segmentation fault in
       compare_symbols function by excluding section and synthetic symbols before
       checking symbol flags
     - CVE-2022-47695</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-30 18:36:34 UTC" />
    <updated date="2025-10-30 18:36:34 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761849390.html" id="CLSA-2025:1761849390" title="CLSA-2025:1761849390" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="binutils" version="2.31.1-16+tuxcare.els6">
          <filename>binutils_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">81fef4985e1339852dff6d4c1d64d569f90b3a35</sum>
        </package>
        <package arch="amd64" name="binutils-aarch64-linux-gnu" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-aarch64-linux-gnu_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">e22bc4757b5643576a5808396da1b7a09894580f</sum>
        </package>
        <package arch="amd64" name="binutils-alpha-linux-gnu" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-alpha-linux-gnu_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">05af9333fdfe16e7df7f787cb43a0f3bfda5cfd5</sum>
        </package>
        <package arch="amd64" name="binutils-arm-linux-gnueabi" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-arm-linux-gnueabi_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">1ad5ec7f0e7b766a5df59bc0a0ab122c11ca322d</sum>
        </package>
        <package arch="amd64" name="binutils-arm-linux-gnueabihf" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-arm-linux-gnueabihf_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">ecf958e265665ec0050e6c315b70d53d62a495e2</sum>
        </package>
        <package arch="amd64" name="binutils-common" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-common_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">244f8bbf948a8874b42e6a6f5273395bf2e2e98b</sum>
        </package>
        <package arch="amd64" name="binutils-dev" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-dev_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">4d43fef93dec7a48d233079c71cb98d71a376e39</sum>
        </package>
        <package arch="all" name="binutils-doc" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-doc_2.31.1-16+tuxcare.els6_all.deb</filename>
          <sum type="sha">b33cbb433ec3a30384c7a5b14dc54d17ab9d295f</sum>
        </package>
        <package arch="all" name="binutils-for-build" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-for-build_2.31.1-16+tuxcare.els6_all.deb</filename>
          <sum type="sha">9479180e2beb43d81149435322b0966701ab2ee1</sum>
        </package>
        <package arch="amd64" name="binutils-for-host" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-for-host_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">dc3d678c93ea5d4cc37cd55f194cb3167d1763b2</sum>
        </package>
        <package arch="amd64" name="binutils-hppa-linux-gnu" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-hppa-linux-gnu_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">1b8109c7499996c9a1e15911eca3e19a7299ddc5</sum>
        </package>
        <package arch="amd64" name="binutils-hppa64-linux-gnu" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-hppa64-linux-gnu_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">b24bb7b733caeb9a0d79f26812489c8b535e69e5</sum>
        </package>
        <package arch="amd64" name="binutils-i686-gnu" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-i686-gnu_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">8c6e1deeadd3c465578cc7d70493cd80554c4b1c</sum>
        </package>
        <package arch="amd64" name="binutils-i686-kfreebsd-gnu" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-i686-kfreebsd-gnu_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">82981d14c140f61be95591f19885dc49c44ec669</sum>
        </package>
        <package arch="amd64" name="binutils-i686-linux-gnu" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-i686-linux-gnu_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">1bd97cd31ce13db8203f132baaf1bd7813c94041</sum>
        </package>
        <package arch="amd64" name="binutils-ia64-linux-gnu" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-ia64-linux-gnu_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">a4dbf8916d1997d86b2661877aac084765bc5a3c</sum>
        </package>
        <package arch="amd64" name="binutils-m68k-linux-gnu" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-m68k-linux-gnu_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">a8553cdcd04db374d60243b90a88249f46b6b8a9</sum>
        </package>
        <package arch="amd64" name="binutils-mips-linux-gnu" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-mips-linux-gnu_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">77f8b55d1bd5529d16c7914dec2ba6bdfffc39cc</sum>
        </package>
        <package arch="amd64" name="binutils-mips64el-linux-gnuabi64" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-mips64el-linux-gnuabi64_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">30eb011f8fe888787a61500a2839a852b58f1426</sum>
        </package>
        <package arch="amd64" name="binutils-mipsel-linux-gnu" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-mipsel-linux-gnu_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">6616d8d5db38e234b5628bbb405fae25478db2da</sum>
        </package>
        <package arch="amd64" name="binutils-multiarch" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-multiarch_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">59b3824d81e31e5d82b7c795ffd57c4dca4dcfef</sum>
        </package>
        <package arch="amd64" name="binutils-multiarch-dev" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-multiarch-dev_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">d26495e405a4833663ac5f46f42252bfebed279e</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc-linux-gnu" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-powerpc-linux-gnu_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">46f82fac2d08297d61779d35458c561f44c58219</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc-linux-gnuspe" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-powerpc-linux-gnuspe_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">515b1672d94a5b8157e684d1082ec6154ec094e1</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc64-linux-gnu" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-powerpc64-linux-gnu_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">7736c9ac19ba21054328822c5617fdd6af4ca5e0</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc64le-linux-gnu" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-powerpc64le-linux-gnu_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">aad9d99966e2d24faec85d67a61be06e05bf8277</sum>
        </package>
        <package arch="amd64" name="binutils-riscv64-linux-gnu" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-riscv64-linux-gnu_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">72a95f5593680866979dcd7301feb9aaa709f4a6</sum>
        </package>
        <package arch="amd64" name="binutils-s390x-linux-gnu" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-s390x-linux-gnu_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">4587c40292cd1ead917ec7d37ad7f71a0f2fb703</sum>
        </package>
        <package arch="amd64" name="binutils-sh4-linux-gnu" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-sh4-linux-gnu_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">016c9c7e8704899e0a367f1e2b2c37752f313fa4</sum>
        </package>
        <package arch="all" name="binutils-source" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-source_2.31.1-16+tuxcare.els6_all.deb</filename>
          <sum type="sha">422b4d545228adba535b5dda73582c84880fd13f</sum>
        </package>
        <package arch="amd64" name="binutils-sparc64-linux-gnu" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-sparc64-linux-gnu_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">7d42d22df72fc8325ca9d8103b6ff7b04938245b</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-kfreebsd-gnu" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-x86-64-kfreebsd-gnu_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">ef01587dd37f50f8e4133f6a9cf4a63302ff51fc</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-linux-gnu" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-x86-64-linux-gnu_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">b653b4a4b718e171b4c87faa6a848755549b10d2</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-linux-gnux32" version="2.31.1-16+tuxcare.els6">
          <filename>binutils-x86-64-linux-gnux32_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">39ef8f2e272ddc12b85e6b47b4680d3d8ff8d1c3</sum>
        </package>
        <package arch="amd64" name="libbinutils" version="2.31.1-16+tuxcare.els6">
          <filename>libbinutils_2.31.1-16+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">04a6045e34dd23366ee4ad6fa91a613bf6e85a70</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761901881</id>
    <title>Fix CVE(s): CVE-2023-5764</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: template injection allows code injection through specially
     crafted files
     - debian/patches/CVE-2023-5764.patch: avoid evaluate unsafe conditions
     - debian/patches/CVE-2023-5764-ext-tests.patch: addional tests
     - CVE-2023-5764</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: template injection allows code injection through specially
     crafted files
     - debian/patches/CVE-2023-5764.patch: avoid evaluate unsafe conditions
     - debian/patches/CVE-2023-5764-ext-tests.patch: addional tests
     - CVE-2023-5764</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-31 09:11:29 UTC" />
    <updated date="2025-10-31 09:11:29 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761901881.html" id="CLSA-2025:1761901881" title="CLSA-2025:1761901881" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="all" name="ansible" version="2.7.7+dfsg-1+deb10u2+tuxcare.els1">
          <filename>ansible_2.7.7+dfsg-1+deb10u2+tuxcare.els1_all.deb</filename>
          <sum type="sha">ed3906d28cc0ff2d21aaf707016fdc6f500160ab</sum>
        </package>
        <package arch="all" name="ansible-doc" version="2.7.7+dfsg-1+deb10u2+tuxcare.els1">
          <filename>ansible-doc_2.7.7+dfsg-1+deb10u2+tuxcare.els1_all.deb</filename>
          <sum type="sha">092601992ad0beb626940886c6642d9254b548c3</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761902260</id>
    <title>Fix CVE(s): CVE-2024-45490</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Improper restriction of XML External Entity Reference
     - debian/patches/CVE-2024-45490.patch: Reject negative len for
       XML_ParseBuffer
     - CVE-2024-45490</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Improper restriction of XML External Entity Reference
     - debian/patches/CVE-2024-45490.patch: Reject negative len for
       XML_ParseBuffer
     - CVE-2024-45490</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-31 09:17:47 UTC" />
    <updated date="2025-10-31 09:17:47 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761902260.html" id="CLSA-2025:1761902260" title="CLSA-2025:1761902260" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="expat" version="2.2.6-2+deb10u7+tuxcare.els1">
          <filename>expat_2.2.6-2+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">4f6f361b7ef530ded217effc9418772f66d6de06</sum>
        </package>
        <package arch="amd64" name="libexpat1" version="2.2.6-2+deb10u7+tuxcare.els1">
          <filename>libexpat1_2.2.6-2+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">d976efa3d746078b0d9c9267cb1eb11c9caccbb8</sum>
        </package>
        <package arch="amd64" name="libexpat1-dev" version="2.2.6-2+deb10u7+tuxcare.els1">
          <filename>libexpat1-dev_2.2.6-2+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">ec4c268c4b883b1ed4a1f5b5005a134ca79ec346</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1762180511</id>
    <title>Fix CVE(s): CVE-2025-1000876</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix integer overflow in libbfd
     - debian/patches/CVE-2025-1000876.patch: Add overflow checks to prevent
       potential memory allocation issues from integer overflow
     - CVE-2025-1000876</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix integer overflow in libbfd
     - debian/patches/CVE-2025-1000876.patch: Add overflow checks to prevent
       potential memory allocation issues from integer overflow
     - CVE-2025-1000876</summary>
    <pushcount>0</pushcount>
    <issued date="2025-11-03 14:35:20 UTC" />
    <updated date="2025-11-03 14:35:20 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1762180511.html" id="CLSA-2025:1762180511" title="CLSA-2025:1762180511" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="binutils" version="2.31.1-16+tuxcare.els8">
          <filename>binutils_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">194fc09b28e2899d08730e4f8723a4a7d12e0515</sum>
        </package>
        <package arch="amd64" name="binutils-aarch64-linux-gnu" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-aarch64-linux-gnu_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">b74b68b7bc81d147eafcd3b099024b1757a8e15a</sum>
        </package>
        <package arch="amd64" name="binutils-alpha-linux-gnu" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-alpha-linux-gnu_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">f8993fddb93bb041b61a29b9cbe90b4b7e022ba5</sum>
        </package>
        <package arch="amd64" name="binutils-arm-linux-gnueabi" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-arm-linux-gnueabi_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">7041a4ed7d27a4ebb492c27eda2083df0563b7e5</sum>
        </package>
        <package arch="amd64" name="binutils-arm-linux-gnueabihf" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-arm-linux-gnueabihf_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">749c75345985dffdc9ae52278e0f06c22eb9e08c</sum>
        </package>
        <package arch="amd64" name="binutils-common" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-common_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">192fc34978512b09d494ed733f9f84aeca98f629</sum>
        </package>
        <package arch="amd64" name="binutils-dev" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-dev_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">cdb6cd2b1fc822892942ed48d4ea40d69a9db8be</sum>
        </package>
        <package arch="all" name="binutils-doc" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-doc_2.31.1-16+tuxcare.els8_all.deb</filename>
          <sum type="sha">953e1eef26fd5499f84a4752d1e890f732ed2e82</sum>
        </package>
        <package arch="all" name="binutils-for-build" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-for-build_2.31.1-16+tuxcare.els8_all.deb</filename>
          <sum type="sha">2ac928c5ca5a94f9b94349c82e6d206057cc9c05</sum>
        </package>
        <package arch="amd64" name="binutils-for-host" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-for-host_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">fe634b6949ed63b93e493fc207c3d3174b5c56ec</sum>
        </package>
        <package arch="amd64" name="binutils-hppa-linux-gnu" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-hppa-linux-gnu_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">adfa57fb15541330967a5dd9a8d6dc11d472a3cc</sum>
        </package>
        <package arch="amd64" name="binutils-hppa64-linux-gnu" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-hppa64-linux-gnu_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">a87be92fa1a10c1a1d619dbfe812c43dcd75d221</sum>
        </package>
        <package arch="amd64" name="binutils-i686-gnu" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-i686-gnu_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">7a29def849471b3c98d10463134a7cec56161489</sum>
        </package>
        <package arch="amd64" name="binutils-i686-kfreebsd-gnu" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-i686-kfreebsd-gnu_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">42f6ca0557d30476627f8cec674dd2f5deefe28c</sum>
        </package>
        <package arch="amd64" name="binutils-i686-linux-gnu" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-i686-linux-gnu_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">4b3b56a98634a7d8e81bb091c856d2821bc657a4</sum>
        </package>
        <package arch="amd64" name="binutils-ia64-linux-gnu" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-ia64-linux-gnu_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">e9ef0be2f6fd0279306a5401530ea860099bf920</sum>
        </package>
        <package arch="amd64" name="binutils-m68k-linux-gnu" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-m68k-linux-gnu_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">c81461c89a135cd709c7e856e9d6cd207b63833c</sum>
        </package>
        <package arch="amd64" name="binutils-mips-linux-gnu" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-mips-linux-gnu_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">45c3146b2f19acc006cf4e6607ea6811d35c55ff</sum>
        </package>
        <package arch="amd64" name="binutils-mips64el-linux-gnuabi64" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-mips64el-linux-gnuabi64_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">ab30f7c19112763763f0cebd495a4b36d8b3b7da</sum>
        </package>
        <package arch="amd64" name="binutils-mipsel-linux-gnu" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-mipsel-linux-gnu_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">6137dd21f224baad879017f21f7a8fe8b2f00fa4</sum>
        </package>
        <package arch="amd64" name="binutils-multiarch" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-multiarch_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">da1187cff1abc1c3e31658646f6818144b982215</sum>
        </package>
        <package arch="amd64" name="binutils-multiarch-dev" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-multiarch-dev_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">850fc9a03e287361cfa2c94f2dd85b2011cbfdd7</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc-linux-gnu" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-powerpc-linux-gnu_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">5e27874d05511b9ccbe163145e943d37674644d2</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc-linux-gnuspe" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-powerpc-linux-gnuspe_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">26b623ae1b670779024de0a409a8c10a1e25dc09</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc64-linux-gnu" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-powerpc64-linux-gnu_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">d9eb75f90f92ab2414ab62bcdaf504e0b27662b1</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc64le-linux-gnu" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-powerpc64le-linux-gnu_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">9ac0c4f5ea00e381b4c80fc09841a33fdc2737d5</sum>
        </package>
        <package arch="amd64" name="binutils-riscv64-linux-gnu" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-riscv64-linux-gnu_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">3f6a56f95a602c38d694b2f35909e639d0d862e5</sum>
        </package>
        <package arch="amd64" name="binutils-s390x-linux-gnu" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-s390x-linux-gnu_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">a27c3b84439c67181982d85d7df2dd34a32c9804</sum>
        </package>
        <package arch="amd64" name="binutils-sh4-linux-gnu" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-sh4-linux-gnu_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">93956fd4c0bdba537f63c259c84a106146a0433f</sum>
        </package>
        <package arch="all" name="binutils-source" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-source_2.31.1-16+tuxcare.els8_all.deb</filename>
          <sum type="sha">0d85854d10469c07d6f8ef7e6d315503d1b20ea7</sum>
        </package>
        <package arch="amd64" name="binutils-sparc64-linux-gnu" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-sparc64-linux-gnu_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">c59b7f7dfe5824658b96b01839e9abe32ff46b3c</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-kfreebsd-gnu" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-x86-64-kfreebsd-gnu_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">d7b7fb350d86128189f5f3fa93b753403d8874dd</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-linux-gnu" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-x86-64-linux-gnu_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">24a176b9c5a825aec2cc4c1dc4cfc465a58ca45f</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-linux-gnux32" version="2.31.1-16+tuxcare.els8">
          <filename>binutils-x86-64-linux-gnux32_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">006c24eae852ee3e544191321d7531f3fc5209f2</sum>
        </package>
        <package arch="amd64" name="libbinutils" version="2.31.1-16+tuxcare.els8">
          <filename>libbinutils_2.31.1-16+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">7cfc63e202f603480477c5a5a1c06bb1d6595130</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1762180717</id>
    <title>Fix CVE(s): CVE-2022-2343, CVE-2022-2522</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Reading past end of completion with a long line and
     'infercase' set
     - debian/patches/CVE-2022-2343.patch: Allocate the string if needed
     - CVE-2022-2343
   * SECURITY UPDATE: Accessing uninitialized memory when completing long
     line
     - debian/patches/CVE-2022-2522.patch: Terminate string with NUL.
     - CVE-2022-2522</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Reading past end of completion with a long line and
     'infercase' set
     - debian/patches/CVE-2022-2343.patch: Allocate the string if needed
     - CVE-2022-2343
   * SECURITY UPDATE: Accessing uninitialized memory when completing long
     line
     - debian/patches/CVE-2022-2522.patch: Terminate string with NUL.
     - CVE-2022-2522</summary>
    <pushcount>0</pushcount>
    <issued date="2025-11-03 14:38:41 UTC" />
    <updated date="2025-11-03 14:38:41 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1762180717.html" id="CLSA-2025:1762180717" title="CLSA-2025:1762180717" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="vim" version="2:8.1.0875-5+deb10u6+tuxcare.els9">
          <filename>vim_8.1.0875-5+deb10u6+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">62805de622d7b4c9352a43b6f9da0ac255fea2fc</sum>
        </package>
        <package arch="amd64" name="vim-athena" version="2:8.1.0875-5+deb10u6+tuxcare.els9">
          <filename>vim-athena_8.1.0875-5+deb10u6+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">a14386745aa39e945d5e2545d65a6ed1c99e8f56</sum>
        </package>
        <package arch="all" name="vim-common" version="2:8.1.0875-5+deb10u6+tuxcare.els9">
          <filename>vim-common_8.1.0875-5+deb10u6+tuxcare.els9_all.deb</filename>
          <sum type="sha">e044e65afef89ba2637fbf8d354122d14a7d59cc</sum>
        </package>
        <package arch="all" name="vim-doc" version="2:8.1.0875-5+deb10u6+tuxcare.els9">
          <filename>vim-doc_8.1.0875-5+deb10u6+tuxcare.els9_all.deb</filename>
          <sum type="sha">68f7997aa45e2b5ffe3e452be8f9c5bcaad02418</sum>
        </package>
        <package arch="amd64" name="vim-gtk" version="2:8.1.0875-5+deb10u6+tuxcare.els9">
          <filename>vim-gtk_8.1.0875-5+deb10u6+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">11c97cf73683a403dff8cf26941b1e8e964036cb</sum>
        </package>
        <package arch="amd64" name="vim-gtk3" version="2:8.1.0875-5+deb10u6+tuxcare.els9">
          <filename>vim-gtk3_8.1.0875-5+deb10u6+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">f95c642d5c5b2a23391eec611ea9d54270053965</sum>
        </package>
        <package arch="all" name="vim-gui-common" version="2:8.1.0875-5+deb10u6+tuxcare.els9">
          <filename>vim-gui-common_8.1.0875-5+deb10u6+tuxcare.els9_all.deb</filename>
          <sum type="sha">a912ad97629bcbd85bf430a52b2523d0898120e3</sum>
        </package>
        <package arch="amd64" name="vim-nox" version="2:8.1.0875-5+deb10u6+tuxcare.els9">
          <filename>vim-nox_8.1.0875-5+deb10u6+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">2569ae6adea94b40812f2b139c2fbfdebf90c30d</sum>
        </package>
        <package arch="all" name="vim-runtime" version="2:8.1.0875-5+deb10u6+tuxcare.els9">
          <filename>vim-runtime_8.1.0875-5+deb10u6+tuxcare.els9_all.deb</filename>
          <sum type="sha">10a72e9ae4c9d190e7312e1db69e07ff77386ee1</sum>
        </package>
        <package arch="amd64" name="vim-tiny" version="2:8.1.0875-5+deb10u6+tuxcare.els9">
          <filename>vim-tiny_8.1.0875-5+deb10u6+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">b26a807cf8a772d2b861090fc73d482ab2b546d9</sum>
        </package>
        <package arch="amd64" name="xxd" version="2:8.1.0875-5+deb10u6+tuxcare.els9">
          <filename>xxd_8.1.0875-5+deb10u6+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">b4c8c4c0ab9c4805b9d12cb2adb824d740be6ac3</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1762269073</id>
    <title>Fix CVE(s): CVE-2018-1000500, CVE-2022-28391, CVE-2023-39810</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: missing SSL certificate validation vulnerability in wget
     - debian/patches/CVE-2018-1000500-1.patch: implement TLS verification with
       CENABLE_FEATURE_WGET_OPENSSL
     - debian/patches/CVE 2018-1000500-2.patch: fix openssl options for cert verification
     - CVE-2018-1000500
   * SECURITY UPDATE: escape sequence injection attack
     - debian/patches/CVE-2022-28391-1.patch: sockaddr2str: ensure only printable
       characters are returned for the hostname part
     - debian/patches/CVE-2022-28391-2.patch: nslookup: sanitize all printed strings
     - CVE-2022-28391
   * SECURITY UPDATE: directory traversal vulnerability in CPIO command
     - debian/patches/CVE-2023-39810.patch: archival: disallow path traversals
     - debian/config/pkg/*: regenerate to add the new FEATURE_PATH_TRAVERSAL_PROTECTION
       option
     - CVE-2023-39810</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: missing SSL certificate validation vulnerability in wget
     - debian/patches/CVE-2018-1000500-1.patch: implement TLS verification with
       CENABLE_FEATURE_WGET_OPENSSL
     - debian/patches/CVE 2018-1000500-2.patch: fix openssl options for cert verification
     - CVE-2018-1000500
   * SECURITY UPDATE: escape sequence injection attack
     - debian/patches/CVE-2022-28391-1.patch: sockaddr2str: ensure only printable
       characters are returned for the hostname part
     - debian/patches/CVE-2022-28391-2.patch: nslookup: sanitize all printed strings
     - CVE-2022-28391
   * SECURITY UPDATE: directory traversal vulnerability in CPIO command
     - debian/patches/CVE-2023-39810.patch: archival: disallow path traversals
     - debian/config/pkg/*: regenerate to add the new FEATURE_PATH_TRAVERSAL_PROTECTION
       option
     - CVE-2023-39810</summary>
    <pushcount>0</pushcount>
    <issued date="2025-11-04 15:11:26 UTC" />
    <updated date="2025-11-04 15:11:26 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1762269073.html" id="CLSA-2025:1762269073" title="CLSA-2025:1762269073" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="busybox" version="1:1.30.1-4+tuxcare.els3">
          <filename>busybox_1.30.1-4+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">21a2ce52c43b99e8c54e0664eb281f404b686d96</sum>
        </package>
        <package arch="amd64" name="busybox-static" version="1:1.30.1-4+tuxcare.els3">
          <filename>busybox-static_1.30.1-4+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">78dd776d8c94616d646705a43d2bd66a54fdb77b</sum>
        </package>
        <package arch="all" name="busybox-syslogd" version="1:1.30.1-4+tuxcare.els3">
          <filename>busybox-syslogd_1.30.1-4+tuxcare.els3_all.deb</filename>
          <sum type="sha">b285d1fcf1db417003615ff4b836ff3175a3202a</sum>
        </package>
        <package arch="amd64" name="udhcpc" version="1:1.30.1-4+tuxcare.els3">
          <filename>udhcpc_1.30.1-4+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">5fb6ffe2b094e54743bbcec262c10cbd0b469dc5</sum>
        </package>
        <package arch="amd64" name="udhcpd" version="1:1.30.1-4+tuxcare.els3">
          <filename>udhcpd_1.30.1-4+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">ebc00a2736308db32cd17044925db8a5a6a0158d</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1762337525</id>
    <title>Fix CVE(s): CVE-2022-42898</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: integer overflow in PAC parsing
     - debian/patches/CVE-2022-42898.patch: catch overflows that result from
       adding PAC_INFO_BUFFER_SIZE
     - CVE-2022-42898</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: integer overflow in PAC parsing
     - debian/patches/CVE-2022-42898.patch: catch overflows that result from
       adding PAC_INFO_BUFFER_SIZE
     - CVE-2022-42898</summary>
    <pushcount>0</pushcount>
    <issued date="2025-11-05 10:12:12 UTC" />
    <updated date="2025-11-05 10:12:12 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1762337525.html" id="CLSA-2025:1762337525" title="CLSA-2025:1762337525" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="ctdb" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els2">
          <filename>ctdb_4.9.5+dfsg-5+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">4453572161441016e2a8bbacc0082401b32f8702</sum>
        </package>
        <package arch="amd64" name="libnss-winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els2">
          <filename>libnss-winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">d86eea85d6446fbd950633c1c3fa0a0c2d93235f</sum>
        </package>
        <package arch="amd64" name="libpam-winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els2">
          <filename>libpam-winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">e096089cb491b2bc0a1eaf84afa1741732ffa648</sum>
        </package>
        <package arch="amd64" name="libsmbclient" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els2">
          <filename>libsmbclient_4.9.5+dfsg-5+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">18303382c58f16113dfbdc155e2db0305f165d2d</sum>
        </package>
        <package arch="amd64" name="libsmbclient-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els2">
          <filename>libsmbclient-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">ce852c1c1ea2c872a54692505abd12cc4afac753</sum>
        </package>
        <package arch="amd64" name="libwbclient-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els2">
          <filename>libwbclient-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">6867308481add7d79f1dc7a0bcd21e4a8b63c9af</sum>
        </package>
        <package arch="amd64" name="libwbclient0" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els2">
          <filename>libwbclient0_4.9.5+dfsg-5+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">d9199c8884e368ebd662ae1e7857e14c33b74365</sum>
        </package>
        <package arch="amd64" name="python-samba" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els2">
          <filename>python-samba_4.9.5+dfsg-5+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">ea59e1fd8e98793a8ccb61a474ab02d23de543f6</sum>
        </package>
        <package arch="amd64" name="registry-tools" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els2">
          <filename>registry-tools_4.9.5+dfsg-5+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">ba39e96d60cff7ab473d88c3fa3f0d18a5e5f548</sum>
        </package>
        <package arch="amd64" name="samba" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els2">
          <filename>samba_4.9.5+dfsg-5+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">1b5fde8d3599450da37f0a6622fa7f47278409ad</sum>
        </package>
        <package arch="all" name="samba-common" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els2">
          <filename>samba-common_4.9.5+dfsg-5+deb10u5+tuxcare.els2_all.deb</filename>
          <sum type="sha">2c95bd35994858b1f834ccae21bf5c9a20741e49</sum>
        </package>
        <package arch="amd64" name="samba-common-bin" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els2">
          <filename>samba-common-bin_4.9.5+dfsg-5+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">4366dfc6846b83a9b8614d07d7389405cf4739cf</sum>
        </package>
        <package arch="amd64" name="samba-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els2">
          <filename>samba-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">bc6ea9f0528b2e36e5bd7b8f475fe69aff5f5809</sum>
        </package>
        <package arch="amd64" name="samba-dsdb-modules" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els2">
          <filename>samba-dsdb-modules_4.9.5+dfsg-5+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">f30778b4c3cba818987450d8dc97db9d08a77e21</sum>
        </package>
        <package arch="amd64" name="samba-libs" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els2">
          <filename>samba-libs_4.9.5+dfsg-5+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">d0295bd0704ea501401315c81795abb51cfbf473</sum>
        </package>
        <package arch="amd64" name="samba-testsuite" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els2">
          <filename>samba-testsuite_4.9.5+dfsg-5+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">ffe1be51b2e54d94d13eca42093147d1f6c6fcec</sum>
        </package>
        <package arch="amd64" name="samba-vfs-modules" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els2">
          <filename>samba-vfs-modules_4.9.5+dfsg-5+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">146c11e4012b9a6e658c868aac5d7a9af79c5b5a</sum>
        </package>
        <package arch="amd64" name="smbclient" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els2">
          <filename>smbclient_4.9.5+dfsg-5+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">5d84167242d4bb8607d07753ac515a3e94cb9555</sum>
        </package>
        <package arch="amd64" name="winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els2">
          <filename>winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">ba85647bc79d83bbb3b82c131a511e819fbb2b5b</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1762419767</id>
    <title>Fix CVE(s): CVE-2022-3296</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Stack-based Buffer Overflow with unexpected :finally
     - debian/patches/CVE-2022-3296.patch: check CSF_TRY can be found
     - CVE-2022-3296
   * Fix Test_terminal_noblock()
     - debian/patches/fix-flaky-terminal-noblock-test.patch</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Stack-based Buffer Overflow with unexpected :finally
     - debian/patches/CVE-2022-3296.patch: check CSF_TRY can be found
     - CVE-2022-3296
   * Fix Test_terminal_noblock()
     - debian/patches/fix-flaky-terminal-noblock-test.patch</summary>
    <pushcount>0</pushcount>
    <issued date="2025-11-06 09:02:59 UTC" />
    <updated date="2025-11-06 09:02:59 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1762419767.html" id="CLSA-2025:1762419767" title="CLSA-2025:1762419767" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="vim" version="2:8.1.0875-5+deb10u6+tuxcare.els13">
          <filename>vim_8.1.0875-5+deb10u6+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">10eb34ce7f351d5aac2dbbf06a921bb1848d4910</sum>
        </package>
        <package arch="amd64" name="vim-athena" version="2:8.1.0875-5+deb10u6+tuxcare.els13">
          <filename>vim-athena_8.1.0875-5+deb10u6+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">10d5ccd5d68d66698bca8d1052de3f1ebb5a560e</sum>
        </package>
        <package arch="all" name="vim-common" version="2:8.1.0875-5+deb10u6+tuxcare.els13">
          <filename>vim-common_8.1.0875-5+deb10u6+tuxcare.els13_all.deb</filename>
          <sum type="sha">3fd197a254d075b1c9fc72b5ad73b8d22461d1be</sum>
        </package>
        <package arch="all" name="vim-doc" version="2:8.1.0875-5+deb10u6+tuxcare.els13">
          <filename>vim-doc_8.1.0875-5+deb10u6+tuxcare.els13_all.deb</filename>
          <sum type="sha">77f0fd717e4eafa9a73106be0bfbf46b7ec6ed2e</sum>
        </package>
        <package arch="amd64" name="vim-gtk" version="2:8.1.0875-5+deb10u6+tuxcare.els13">
          <filename>vim-gtk_8.1.0875-5+deb10u6+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">e15a4ab0927719375830788b5d8cd283ce63e9c2</sum>
        </package>
        <package arch="amd64" name="vim-gtk3" version="2:8.1.0875-5+deb10u6+tuxcare.els13">
          <filename>vim-gtk3_8.1.0875-5+deb10u6+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">e37a962e12f753ffe69ecaed3d0a7ef1cbdc17e1</sum>
        </package>
        <package arch="all" name="vim-gui-common" version="2:8.1.0875-5+deb10u6+tuxcare.els13">
          <filename>vim-gui-common_8.1.0875-5+deb10u6+tuxcare.els13_all.deb</filename>
          <sum type="sha">eddeebc73b8291025f03f1f35c2881f3db843d54</sum>
        </package>
        <package arch="amd64" name="vim-nox" version="2:8.1.0875-5+deb10u6+tuxcare.els13">
          <filename>vim-nox_8.1.0875-5+deb10u6+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">fc3f7d1e9172861fd169a7c93fbdcd9f11985dc5</sum>
        </package>
        <package arch="all" name="vim-runtime" version="2:8.1.0875-5+deb10u6+tuxcare.els13">
          <filename>vim-runtime_8.1.0875-5+deb10u6+tuxcare.els13_all.deb</filename>
          <sum type="sha">66b7c359f80af685a915a4d4be8ccc8baea5cf57</sum>
        </package>
        <package arch="amd64" name="vim-tiny" version="2:8.1.0875-5+deb10u6+tuxcare.els13">
          <filename>vim-tiny_8.1.0875-5+deb10u6+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">29f1f403a35cbe6c8a3208220df23691c1c17e4c</sum>
        </package>
        <package arch="amd64" name="xxd" version="2:8.1.0875-5+deb10u6+tuxcare.els13">
          <filename>xxd_8.1.0875-5+deb10u6+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">1a88c9784d6422970d449497f5d1ece3c64e7f0f</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1762449077</id>
    <title>Fix CVE(s): CVE-2023-30630</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Overwrite a local file
     - debian/patches/CVE-2023-30630.patch: Prevent --dump-bin from overwriting
       local files to address privilege escalation vulnerability
     - CVE-2023-30630</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Overwrite a local file
     - debian/patches/CVE-2023-30630.patch: Prevent --dump-bin from overwriting
       local files to address privilege escalation vulnerability
     - CVE-2023-30630</summary>
    <pushcount>0</pushcount>
    <issued date="2025-11-06 17:11:23 UTC" />
    <updated date="2025-11-06 17:11:23 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1762449077.html" id="CLSA-2025:1762449077" title="CLSA-2025:1762449077" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="dmidecode" version="3.2-1+tuxcare.els1">
          <filename>dmidecode_3.2-1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">84898ae8ad5cca40c6603b6dea05ece6fb159aa8</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1762537520</id>
    <title>Fix CVE(s): CVE-2023-4408</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: The DNS message parsing code in `named` includes a section
     whose computational complexity is overly high
     - debian/patches/CVE-2023-4408.patch: refactoring parsing code
     - debian/patches/CVE-2023-4408-1.patch: fix DNSSEC test suite
     - debian/libdns1100.symbols: some function declarations were removed
       according to the CVE-2023-4408.patch
     - CVE-2023-4408
   * Add patch for enabling automated testing</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: The DNS message parsing code in `named` includes a section
     whose computational complexity is overly high
     - debian/patches/CVE-2023-4408.patch: refactoring parsing code
     - debian/patches/CVE-2023-4408-1.patch: fix DNSSEC test suite
     - debian/libdns1100.symbols: some function declarations were removed
       according to the CVE-2023-4408.patch
     - CVE-2023-4408
   * Add patch for enabling automated testing</summary>
    <pushcount>0</pushcount>
    <issued date="2025-11-07 17:45:24 UTC" />
    <updated date="2025-11-07 17:45:24 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1762537520.html" id="CLSA-2025:1762537520" title="CLSA-2025:1762537520" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="bind9" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1">
          <filename>bind9_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">0fd9141e9737206a7c1b8d87cf5073689656a188</sum>
        </package>
        <package arch="all" name="bind9-doc" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1">
          <filename>bind9-doc_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_all.deb</filename>
          <sum type="sha">af56ebc5040a4ae3a47b03c807860b7a589b47b3</sum>
        </package>
        <package arch="amd64" name="bind9-host" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1">
          <filename>bind9-host_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">50368ab48b0b59e4694660800f659cb7eab73738</sum>
        </package>
        <package arch="amd64" name="bind9utils" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1">
          <filename>bind9utils_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">7bc79d1fc034beeb3067a3806477608e2bb02444</sum>
        </package>
        <package arch="amd64" name="dnsutils" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1">
          <filename>dnsutils_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">6e70bc56bb3498227b755355bdddfb69f1f434d2</sum>
        </package>
        <package arch="amd64" name="libbind-dev" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1">
          <filename>libbind-dev_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">ec9dcd4fbe8d54a2cf0365f787e0e5ce8f05076e</sum>
        </package>
        <package arch="amd64" name="libbind-export-dev" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1">
          <filename>libbind-export-dev_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">475974d613e6b06e66e5a6cfe6fcf98af1e8b131</sum>
        </package>
        <package arch="amd64" name="libbind9-161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1">
          <filename>libbind9-161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">bbf3ea3db0223365eaa081b98aee811ef1b7b027</sum>
        </package>
        <package arch="amd64" name="libdns-export1104" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1">
          <filename>libdns-export1104_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">93cbd0ae2e86bc1a76950258113f0e4569ddcc0f</sum>
        </package>
        <package arch="amd64" name="libdns1104" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1">
          <filename>libdns1104_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">9fddcfc2a2c819267b9969d57dc72ece39c1af23</sum>
        </package>
        <package arch="amd64" name="libirs-export161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1">
          <filename>libirs-export161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">010cb6a17e0ef9fd90b8d47478494bc9b5ea06d5</sum>
        </package>
        <package arch="amd64" name="libirs161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1">
          <filename>libirs161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">0be55119f9518a796006b85bcc33cf92163b3a4e</sum>
        </package>
        <package arch="amd64" name="libisc-export1100" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1">
          <filename>libisc-export1100_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">a7e705bfe2ce17dcb5d8c65f48d3816f1b9db776</sum>
        </package>
        <package arch="amd64" name="libisc1100" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1">
          <filename>libisc1100_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">73f6e4ce54a8221546c316b421fd37de01ff1e74</sum>
        </package>
        <package arch="amd64" name="libisccc-export161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1">
          <filename>libisccc-export161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">7d24cd52442f96d1309e8e05edcbe92e444f6329</sum>
        </package>
        <package arch="amd64" name="libisccc161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1">
          <filename>libisccc161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">12cfa649cb759463999260a62275c7b1830acac8</sum>
        </package>
        <package arch="amd64" name="libisccfg-export163" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1">
          <filename>libisccfg-export163_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">9fb29a110d2120fd43a040f5a9ef6464dfbae393</sum>
        </package>
        <package arch="amd64" name="libisccfg163" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1">
          <filename>libisccfg163_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">c57846214c7b4bfdb4383600cfdb5d46c6af9c91</sum>
        </package>
        <package arch="amd64" name="liblwres161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1">
          <filename>liblwres161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">c95edae68ad9943e13ffce917323e9c6b343778c</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1762540530</id>
    <title>Fix CVE(s): CVE-2020-10745, CVE-2022-42898</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: DNS string buffer overflow
     - debian/patches/CVE-2020-10745.patch: add input validation to prevent
       buffer overflows when handling DNS/NBT names with consecutive dots or
       exceeding RFC 1035 255-byte limit. The fix enforces proper bounds
       checking and component length validation in ndr_push_dns_string() and
       ndr_push_nbt_string() functions.
     - CVE-2020-10745
   * SECURITY UPDATE: panic in krb5_pac_parse()
     - debian/patches/0001-Additional-fix-for-CVE-2022-42898.patch: check
       pointer for NULL
     - CVE-2022-42898</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: DNS string buffer overflow
     - debian/patches/CVE-2020-10745.patch: add input validation to prevent
       buffer overflows when handling DNS/NBT names with consecutive dots or
       exceeding RFC 1035 255-byte limit. The fix enforces proper bounds
       checking and component length validation in ndr_push_dns_string() and
       ndr_push_nbt_string() functions.
     - CVE-2020-10745
   * SECURITY UPDATE: panic in krb5_pac_parse()
     - debian/patches/0001-Additional-fix-for-CVE-2022-42898.patch: check
       pointer for NULL
     - CVE-2022-42898</summary>
    <pushcount>0</pushcount>
    <issued date="2025-11-07 18:35:34 UTC" />
    <updated date="2025-11-07 18:35:34 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1762540530.html" id="CLSA-2025:1762540530" title="CLSA-2025:1762540530" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="ctdb" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els3">
          <filename>ctdb_4.9.5+dfsg-5+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">f001bbada8e562a9f31c30d05aedbc08485925ee</sum>
        </package>
        <package arch="amd64" name="libnss-winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els3">
          <filename>libnss-winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">d74f0fc9845738de2f6a2f55399ac87af0007702</sum>
        </package>
        <package arch="amd64" name="libpam-winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els3">
          <filename>libpam-winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">d9d604a40086b8669961e18a63ef4b74381916cb</sum>
        </package>
        <package arch="amd64" name="libsmbclient" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els3">
          <filename>libsmbclient_4.9.5+dfsg-5+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">dec2413c88583f98fc9918474acff01971b6da53</sum>
        </package>
        <package arch="amd64" name="libsmbclient-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els3">
          <filename>libsmbclient-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">b43bed8471d854be1b2c1395614a55d66ea81bed</sum>
        </package>
        <package arch="amd64" name="libwbclient-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els3">
          <filename>libwbclient-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">1e537e856113fc669787e7e28bbe07eab140c01a</sum>
        </package>
        <package arch="amd64" name="libwbclient0" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els3">
          <filename>libwbclient0_4.9.5+dfsg-5+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">80144999aae3acd623cc00d83eda40382eaa7317</sum>
        </package>
        <package arch="amd64" name="python-samba" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els3">
          <filename>python-samba_4.9.5+dfsg-5+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">21dec970918be44289365a24432748c520d1f716</sum>
        </package>
        <package arch="amd64" name="registry-tools" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els3">
          <filename>registry-tools_4.9.5+dfsg-5+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">6674d7c2fd64e0aabdea27cc118f61b217d88675</sum>
        </package>
        <package arch="amd64" name="samba" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els3">
          <filename>samba_4.9.5+dfsg-5+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">0bf868b5a8ec1d76af30866eff72f7c7911c8502</sum>
        </package>
        <package arch="all" name="samba-common" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els3">
          <filename>samba-common_4.9.5+dfsg-5+deb10u5+tuxcare.els3_all.deb</filename>
          <sum type="sha">5b50ee71ea66f73ce8a59278379188e80e0ac445</sum>
        </package>
        <package arch="amd64" name="samba-common-bin" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els3">
          <filename>samba-common-bin_4.9.5+dfsg-5+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">3f4e9a98da7ebc7ff77863076ee22b599b1cf2a3</sum>
        </package>
        <package arch="amd64" name="samba-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els3">
          <filename>samba-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">e4240310db8b52f3549b4b5516a174a2908f5b6b</sum>
        </package>
        <package arch="amd64" name="samba-dsdb-modules" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els3">
          <filename>samba-dsdb-modules_4.9.5+dfsg-5+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">4bd5e1c6466a229bd91e449b2fcf2947b46645de</sum>
        </package>
        <package arch="amd64" name="samba-libs" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els3">
          <filename>samba-libs_4.9.5+dfsg-5+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">710a7d1915b71226db35dcf6737b5a98ce4bf9aa</sum>
        </package>
        <package arch="amd64" name="samba-testsuite" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els3">
          <filename>samba-testsuite_4.9.5+dfsg-5+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">4c9b0fc2ec1242074236a3439af745ddca8c0b66</sum>
        </package>
        <package arch="amd64" name="samba-vfs-modules" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els3">
          <filename>samba-vfs-modules_4.9.5+dfsg-5+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">05b5741e720d8b9145533dca59590fa7af2db05c</sum>
        </package>
        <package arch="amd64" name="smbclient" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els3">
          <filename>smbclient_4.9.5+dfsg-5+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">3906ab3dae182ab8a225b4a9b0d59d904040136c</sum>
        </package>
        <package arch="amd64" name="winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els3">
          <filename>winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">ddb36176f218cd3a7d3a313187a71ced6e269a21</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1762783856</id>
    <title>Fix CVE(s): CVE-2024-38428</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: mishandling of semicolons in userinfo
     - debian/patches/CVE-2024-38428.patch: properly re-implement userinfo
       parsing in src/url.c.
     - CVE-2024-38428</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: mishandling of semicolons in userinfo
     - debian/patches/CVE-2024-38428.patch: properly re-implement userinfo
       parsing in src/url.c.
     - CVE-2024-38428</summary>
    <pushcount>0</pushcount>
    <issued date="2025-11-10 14:11:01 UTC" />
    <updated date="2025-11-10 14:11:01 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1762783856.html" id="CLSA-2025:1762783856" title="CLSA-2025:1762783856" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="wget" version="1.20.1-1.1+tuxcare.els1">
          <filename>wget_1.20.1-1.1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">9813bfb854b2b9da2cbf66b5b85589d4852dc9f2</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1762800667</id>
    <title>Fix CVE(s): CVE-2021-44038</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Unsafe chown/chmod operations in .service files
     - debian/patches/CVE-2021-44038.patch: remove chown/chmod commands
       from the .service files
     - CVE-2021-44038</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Unsafe chown/chmod operations in .service files
     - debian/patches/CVE-2021-44038.patch: remove chown/chmod commands
       from the .service files
     - CVE-2021-44038</summary>
    <pushcount>0</pushcount>
    <issued date="2025-11-10 18:51:12 UTC" />
    <updated date="2025-11-10 18:51:12 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1762800667.html" id="CLSA-2025:1762800667" title="CLSA-2025:1762800667" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="quagga" version="1.2.4-3+tuxcare.els1">
          <filename>quagga_1.2.4-3+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">9dc8b0e03de5ca6abfcddca7a32db3995c1e51ab</sum>
        </package>
        <package arch="amd64" name="quagga-bgpd" version="1.2.4-3+tuxcare.els1">
          <filename>quagga-bgpd_1.2.4-3+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">4bba6e0587a689acd01aa1bb1ce4f8f843a748e6</sum>
        </package>
        <package arch="amd64" name="quagga-core" version="1.2.4-3+tuxcare.els1">
          <filename>quagga-core_1.2.4-3+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">90ecf8e3738329953b5845e7458759c62b2ed48f</sum>
        </package>
        <package arch="all" name="quagga-doc" version="1.2.4-3+tuxcare.els1">
          <filename>quagga-doc_1.2.4-3+tuxcare.els1_all.deb</filename>
          <sum type="sha">050c2250e0c7c004943b44ba8b4a6ba81328ce5f</sum>
        </package>
        <package arch="amd64" name="quagga-isisd" version="1.2.4-3+tuxcare.els1">
          <filename>quagga-isisd_1.2.4-3+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">348f7885b459beb6cd83bd613bc02191f82303e5</sum>
        </package>
        <package arch="amd64" name="quagga-ospf6d" version="1.2.4-3+tuxcare.els1">
          <filename>quagga-ospf6d_1.2.4-3+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">ef25e6387e2ec5f5f9d474191c7f8d147bb9e200</sum>
        </package>
        <package arch="amd64" name="quagga-ospfd" version="1.2.4-3+tuxcare.els1">
          <filename>quagga-ospfd_1.2.4-3+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">18db80b07e774a685b0ebb62614f6d80b4ab8993</sum>
        </package>
        <package arch="amd64" name="quagga-pimd" version="1.2.4-3+tuxcare.els1">
          <filename>quagga-pimd_1.2.4-3+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">56f9fb070c7b563546ffee1402f86030aa8d5200</sum>
        </package>
        <package arch="amd64" name="quagga-ripd" version="1.2.4-3+tuxcare.els1">
          <filename>quagga-ripd_1.2.4-3+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">d5731ac74341a33c159e1e34f0cc9feef91cf2e5</sum>
        </package>
        <package arch="amd64" name="quagga-ripngd" version="1.2.4-3+tuxcare.els1">
          <filename>quagga-ripngd_1.2.4-3+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">f3bca9015989f63cdafac41bbe75c4d5c40a7970</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1763023946</id>
    <title>Fix CVE(s): CVE-2020-35457</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Integer Overflow in g_option_group_add_entries
     - debian/patches/CVE-2020-35457.patch: goption: add a precondition to
       avoid GOptionEntry list overflow
     - CVE-2020-35457</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Integer Overflow in g_option_group_add_entries
     - debian/patches/CVE-2020-35457.patch: goption: add a precondition to
       avoid GOptionEntry list overflow
     - CVE-2020-35457</summary>
    <pushcount>0</pushcount>
    <issued date="2025-11-13 08:52:30 UTC" />
    <updated date="2025-11-13 08:52:30 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1763023946.html" id="CLSA-2025:1763023946" title="CLSA-2025:1763023946" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libglib2.0-0" version="2.58.3-2+deb10u6+tuxcare.els1">
          <filename>libglib2.0-0_2.58.3-2+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">191d6bf021f10fefb96ff51711ea6c93d6039d9b</sum>
        </package>
        <package arch="amd64" name="libglib2.0-bin" version="2.58.3-2+deb10u6+tuxcare.els1">
          <filename>libglib2.0-bin_2.58.3-2+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">01546448e3206df1d123d8a5fba9d39846a1ea56</sum>
        </package>
        <package arch="all" name="libglib2.0-data" version="2.58.3-2+deb10u6+tuxcare.els1">
          <filename>libglib2.0-data_2.58.3-2+deb10u6+tuxcare.els1_all.deb</filename>
          <sum type="sha">1e5a3f815d76164de7d391e14f2168117f987d8f</sum>
        </package>
        <package arch="amd64" name="libglib2.0-dev" version="2.58.3-2+deb10u6+tuxcare.els1">
          <filename>libglib2.0-dev_2.58.3-2+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">07e4cf8af6a0a65bfd288c7fc0b645846af94b06</sum>
        </package>
        <package arch="amd64" name="libglib2.0-dev-bin" version="2.58.3-2+deb10u6+tuxcare.els1">
          <filename>libglib2.0-dev-bin_2.58.3-2+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">7d435571d2b6d71bc0ecbbb87a1c82231c9995e7</sum>
        </package>
        <package arch="all" name="libglib2.0-doc" version="2.58.3-2+deb10u6+tuxcare.els1">
          <filename>libglib2.0-doc_2.58.3-2+deb10u6+tuxcare.els1_all.deb</filename>
          <sum type="sha">dfb22b7c53a9867a4a7202773ec9f554d385da3b</sum>
        </package>
        <package arch="amd64" name="libglib2.0-tests" version="2.58.3-2+deb10u6+tuxcare.els1">
          <filename>libglib2.0-tests_2.58.3-2+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">ec045ed241b8c0c683c523160be5e13384dab31c</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1763136711</id>
    <title>Fix CVE(s): CVE-2022-29154, CVE-2024-12087, CVE-2024-12088</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: malicious remote servers to write arbitrary files inside
     the directories of connecting peers:
     - debian/patches/els/0001-CVE-2022-29154.patch: fix insufficient validation of file
       names.
     - CVE-2022-29154.
   * SECURITY UPDATE: path traversal vulnerability.
     - debian/patches/els/0002-CVE-2024-12087.patch: refuse a duplicate dirlist and
       range check dir_ndx before use
     - CVE-2024-12087
   * SECURITY UPDATE: rsync client fails to properly verify if a symbolic link
     destination sent from the server contains another symbolic link within it:
     - debian/patches/els/0003-CVE-2024-12088.patch: make --safe-links stricter.
     - CVE-2024-12088.</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: malicious remote servers to write arbitrary files inside
     the directories of connecting peers:
     - debian/patches/els/0001-CVE-2022-29154.patch: fix insufficient validation of file
       names.
     - CVE-2022-29154.
   * SECURITY UPDATE: path traversal vulnerability.
     - debian/patches/els/0002-CVE-2024-12087.patch: refuse a duplicate dirlist and
       range check dir_ndx before use
     - CVE-2024-12087
   * SECURITY UPDATE: rsync client fails to properly verify if a symbolic link
     destination sent from the server contains another symbolic link within it:
     - debian/patches/els/0003-CVE-2024-12088.patch: make --safe-links stricter.
     - CVE-2024-12088.</summary>
    <pushcount>0</pushcount>
    <issued date="2025-11-14 16:11:55 UTC" />
    <updated date="2025-11-14 16:11:55 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1763136711.html" id="CLSA-2025:1763136711" title="CLSA-2025:1763136711" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="rsync" version="3.1.3-6+tuxcare.els1">
          <filename>rsync_3.1.3-6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">ee57d5f92e35c90e1ea8c1bca846f2b20be67419</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1763418591</id>
    <title>Fix CVE(s): CVE-2019-3843, CVE-2019-3844</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Privilege chaining vulnerability
     - debian/patches/CVE-2019-3843.patch: introduce functionality
       for blocking chmod() for suid/sgid files with new unit
       setting RestrictSUIDSGID=
     - CVE-2019-3843
   * SECURITY UPDATE: Privilege chaining vulnerability
     - debian/patches/CVE-2019-3844.patch: imply NNP and SUID/SGID
       restriction for DynamicUser=yes service
     - CVE-2019-3844</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Privilege chaining vulnerability
     - debian/patches/CVE-2019-3843.patch: introduce functionality
       for blocking chmod() for suid/sgid files with new unit
       setting RestrictSUIDSGID=
     - CVE-2019-3843
   * SECURITY UPDATE: Privilege chaining vulnerability
     - debian/patches/CVE-2019-3844.patch: imply NNP and SUID/SGID
       restriction for DynamicUser=yes service
     - CVE-2019-3844</summary>
    <pushcount>0</pushcount>
    <issued date="2025-11-17 22:29:56 UTC" />
    <updated date="2025-11-17 22:29:56 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1763418591.html" id="CLSA-2025:1763418591" title="CLSA-2025:1763418591" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libnss-myhostname" version="241-7~deb10u10+tuxcare.els1">
          <filename>libnss-myhostname_241-7~deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">c93e46cd89482d3c53f148a719861a7187dfd1dd</sum>
        </package>
        <package arch="amd64" name="libnss-mymachines" version="241-7~deb10u10+tuxcare.els1">
          <filename>libnss-mymachines_241-7~deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">c0ccd484177469975c5ce03d7a93497d5b0573b1</sum>
        </package>
        <package arch="amd64" name="libnss-resolve" version="241-7~deb10u10+tuxcare.els1">
          <filename>libnss-resolve_241-7~deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">975b748e22bbe1705eedb8e80ab445be218f5254</sum>
        </package>
        <package arch="amd64" name="libnss-systemd" version="241-7~deb10u10+tuxcare.els1">
          <filename>libnss-systemd_241-7~deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">5c00a018c6fffcbf7076b40a49278eb5d6763116</sum>
        </package>
        <package arch="amd64" name="libpam-systemd" version="241-7~deb10u10+tuxcare.els1">
          <filename>libpam-systemd_241-7~deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">fc5a6842739d0190acaf3db471910746d25c3811</sum>
        </package>
        <package arch="amd64" name="libsystemd-dev" version="241-7~deb10u10+tuxcare.els1">
          <filename>libsystemd-dev_241-7~deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">ff379d8e785baf4718190b94358bc882a427d5af</sum>
        </package>
        <package arch="amd64" name="libsystemd0" version="241-7~deb10u10+tuxcare.els1">
          <filename>libsystemd0_241-7~deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">a98bfb7981cff195f6f626906897634ec2c5038e</sum>
        </package>
        <package arch="amd64" name="libudev-dev" version="241-7~deb10u10+tuxcare.els1">
          <filename>libudev-dev_241-7~deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">f370bd0cf41fc303c4d059ecb2246dedb52ff94e</sum>
        </package>
        <package arch="amd64" name="libudev1" version="241-7~deb10u10+tuxcare.els1">
          <filename>libudev1_241-7~deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">ae252555b09f60b5fd30354556a5cf6ba4354926</sum>
        </package>
        <package arch="amd64" name="systemd" version="241-7~deb10u10+tuxcare.els1">
          <filename>systemd_241-7~deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">c9e1287f3f72664f0278094822e5ed295a182a11</sum>
        </package>
        <package arch="amd64" name="systemd-container" version="241-7~deb10u10+tuxcare.els1">
          <filename>systemd-container_241-7~deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">e6c312927461ec4c46ef9d6f0b4a2015315648b8</sum>
        </package>
        <package arch="amd64" name="systemd-coredump" version="241-7~deb10u10+tuxcare.els1">
          <filename>systemd-coredump_241-7~deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">4feb70e8d3ef2a25585a958674cae86c96336655</sum>
        </package>
        <package arch="amd64" name="systemd-journal-remote" version="241-7~deb10u10+tuxcare.els1">
          <filename>systemd-journal-remote_241-7~deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">76d7f7eb751f67db26a0254c17cc3c6601320c0a</sum>
        </package>
        <package arch="amd64" name="systemd-sysv" version="241-7~deb10u10+tuxcare.els1">
          <filename>systemd-sysv_241-7~deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">8c343ffc8a3b1cca61e2d6cd265f6a0af6381e30</sum>
        </package>
        <package arch="amd64" name="systemd-tests" version="241-7~deb10u10+tuxcare.els1">
          <filename>systemd-tests_241-7~deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">512e6b6db4a15603c23eac430559779355c8b2c6</sum>
        </package>
        <package arch="amd64" name="udev" version="241-7~deb10u10+tuxcare.els1">
          <filename>udev_241-7~deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">0cb720ab21ed8146d4c0d4f286cce9055f4d4a50</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1763490076</id>
    <title>Fix CVE(s): CVE-2025-62168</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: failure to redact HTTP authentication credentials in error
     handling allows information disclosure
     - debian/patches/CVE-2025-62168.patch: Fix HttpRequest::pack to mask
       sensitive information to prevent disclosure
     - CVE-2025-62168</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: failure to redact HTTP authentication credentials in error
     handling allows information disclosure
     - debian/patches/CVE-2025-62168.patch: Fix HttpRequest::pack to mask
       sensitive information to prevent disclosure
     - CVE-2025-62168</summary>
    <pushcount>0</pushcount>
    <issued date="2025-11-18 18:21:20 UTC" />
    <updated date="2025-11-18 18:21:20 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1763490076.html" id="CLSA-2025:1763490076" title="CLSA-2025:1763490076" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="squid" version="4.6-1+deb10u10+tuxcare.els3">
          <filename>squid_4.6-1+deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">b5a0911b2b542c3d767f9002756d4c9637e77e28</sum>
        </package>
        <package arch="amd64" name="squid-cgi" version="4.6-1+deb10u10+tuxcare.els3">
          <filename>squid-cgi_4.6-1+deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">00a27dd7cfaf115e93964a59db9f0185e3f85bdc</sum>
        </package>
        <package arch="all" name="squid-common" version="4.6-1+deb10u10+tuxcare.els3">
          <filename>squid-common_4.6-1+deb10u10+tuxcare.els3_all.deb</filename>
          <sum type="sha">aea0564d9da3a9834fb7646c0d2d5dee9d5ca530</sum>
        </package>
        <package arch="amd64" name="squid-purge" version="4.6-1+deb10u10+tuxcare.els3">
          <filename>squid-purge_4.6-1+deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">d327868274d68cbb924cbb8e32f28c0bfef9d257</sum>
        </package>
        <package arch="all" name="squid3" version="4.6-1+deb10u10+tuxcare.els3">
          <filename>squid3_4.6-1+deb10u10+tuxcare.els3_all.deb</filename>
          <sum type="sha">608265b7e7a1ca3a2bea52badb0914dd4425d705</sum>
        </package>
        <package arch="amd64" name="squidclient" version="4.6-1+deb10u10+tuxcare.els3">
          <filename>squidclient_4.6-1+deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">facc4a36cf121f8e298c20e921355c499cc24d53</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1764151714</id>
    <title>Fix CVE(s): CVE-2020-10704</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: stack memory exhaustion vulnerability
     - debian/patches/CVE-2020-10704.patch: fix vulnerability where a deeply
       nested filter in an unauthenticated LDAP search can exhaust the LDAP
       server's attack memory causing a SIGSEGV
     - CVE-2020-10704</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: stack memory exhaustion vulnerability
     - debian/patches/CVE-2020-10704.patch: fix vulnerability where a deeply
       nested filter in an unauthenticated LDAP search can exhaust the LDAP
       server's attack memory causing a SIGSEGV
     - CVE-2020-10704</summary>
    <pushcount>0</pushcount>
    <issued date="2025-11-26 10:08:39 UTC" />
    <updated date="2025-11-26 10:08:39 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1764151714.html" id="CLSA-2025:1764151714" title="CLSA-2025:1764151714" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="ctdb" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els4">
          <filename>ctdb_4.9.5+dfsg-5+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">7bc3b7a0dad8962a4c8c9e91779d4c65ba13f21f</sum>
        </package>
        <package arch="amd64" name="libnss-winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els4">
          <filename>libnss-winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">ca44359d17df6a659d5d90394d90adb3365b42dd</sum>
        </package>
        <package arch="amd64" name="libpam-winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els4">
          <filename>libpam-winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">593bbb16c5ca2e41a0d16776c894fbd073ffb08b</sum>
        </package>
        <package arch="amd64" name="libsmbclient" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els4">
          <filename>libsmbclient_4.9.5+dfsg-5+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">056edfa7b2a246b71c769fc68678eff0359ce2df</sum>
        </package>
        <package arch="amd64" name="libsmbclient-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els4">
          <filename>libsmbclient-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">ff61cff8e5f7a09f4ed1696c5bf1e7fbb760fc28</sum>
        </package>
        <package arch="amd64" name="libwbclient-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els4">
          <filename>libwbclient-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">ee423c7e82922c1a0cb1d27f5eb4b70ef9a64f7b</sum>
        </package>
        <package arch="amd64" name="libwbclient0" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els4">
          <filename>libwbclient0_4.9.5+dfsg-5+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">9b20f09e4784fa685ad297059fa5dcf819c05820</sum>
        </package>
        <package arch="amd64" name="python-samba" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els4">
          <filename>python-samba_4.9.5+dfsg-5+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">283d61ec03ec9763ccf785dd7e5fbe8bea6423bb</sum>
        </package>
        <package arch="amd64" name="registry-tools" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els4">
          <filename>registry-tools_4.9.5+dfsg-5+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">51253a1bb8eefc8239280849f5e360cbcbec280a</sum>
        </package>
        <package arch="amd64" name="samba" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els4">
          <filename>samba_4.9.5+dfsg-5+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">810c2753d0e4699439cb1cd678a18502517b530d</sum>
        </package>
        <package arch="all" name="samba-common" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els4">
          <filename>samba-common_4.9.5+dfsg-5+deb10u5+tuxcare.els4_all.deb</filename>
          <sum type="sha">db3805b2f001bbf510a469ac02d37fe972810e8f</sum>
        </package>
        <package arch="amd64" name="samba-common-bin" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els4">
          <filename>samba-common-bin_4.9.5+dfsg-5+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">cc6635e5a69429ebc9a311268ade37a19bc4a21e</sum>
        </package>
        <package arch="amd64" name="samba-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els4">
          <filename>samba-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">fda5bd0d43ab42ffbe019e56a9ddddcb0dbe217a</sum>
        </package>
        <package arch="amd64" name="samba-dsdb-modules" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els4">
          <filename>samba-dsdb-modules_4.9.5+dfsg-5+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">d362e82d63408bf2a8e1d9e0e93a7a349016c88d</sum>
        </package>
        <package arch="amd64" name="samba-libs" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els4">
          <filename>samba-libs_4.9.5+dfsg-5+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">0869154bd25606f88cafbb0a8b17e5a807f3aaff</sum>
        </package>
        <package arch="amd64" name="samba-testsuite" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els4">
          <filename>samba-testsuite_4.9.5+dfsg-5+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">3e213062a5e0335d3099987769cd0f64a3960d78</sum>
        </package>
        <package arch="amd64" name="samba-vfs-modules" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els4">
          <filename>samba-vfs-modules_4.9.5+dfsg-5+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">2f02cc64b25d20045bc12bc156b1e9f21a7532f9</sum>
        </package>
        <package arch="amd64" name="smbclient" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els4">
          <filename>smbclient_4.9.5+dfsg-5+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">c90bb66fda8499029ef335cdd217b7a32ac92219</sum>
        </package>
        <package arch="amd64" name="winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els4">
          <filename>winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">521fc9eea913c7d9da4da7afaabe9bf225f6d18e</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1764771100</id>
    <title>Fix CVE(s): CVE-2019-1010180</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Buffer overflow when ELF section size is invalid
     - debian/patches/CVE-2019-1010180.patch: Skip processing invalid ELF sections
     - CVE-2019-1010180</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Buffer overflow when ELF section size is invalid
     - debian/patches/CVE-2019-1010180.patch: Skip processing invalid ELF sections
     - CVE-2019-1010180</summary>
    <pushcount>0</pushcount>
    <issued date="2025-12-03 14:11:44 UTC" />
    <updated date="2025-12-03 14:11:44 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1764771100.html" id="CLSA-2025:1764771100" title="CLSA-2025:1764771100" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="gdb" version="8.2.1-2+tuxcare.els1">
          <filename>gdb_8.2.1-2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">2027b788fd46a9cbcf69ac3f0403e2002d402860</sum>
        </package>
        <package arch="amd64" name="gdb-minimal" version="8.2.1-2+tuxcare.els1">
          <filename>gdb-minimal_8.2.1-2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">b2a662f937615bdb1698f61e9842d0f21b209ce8</sum>
        </package>
        <package arch="amd64" name="gdb-multiarch" version="8.2.1-2+tuxcare.els1">
          <filename>gdb-multiarch_8.2.1-2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">63a78be9c6e1e08ef437e01a4dd89de715116f67</sum>
        </package>
        <package arch="all" name="gdb-source" version="8.2.1-2+tuxcare.els1">
          <filename>gdb-source_8.2.1-2+tuxcare.els1_all.deb</filename>
          <sum type="sha">9bd45c80a7a444a93ec8959ff7f4652de382df3e</sum>
        </package>
        <package arch="amd64" name="gdbserver" version="8.2.1-2+tuxcare.els1">
          <filename>gdbserver_8.2.1-2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">0c722efc5f87d225c8a322fd5f12bef8e3905bf0</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1764868292</id>
    <title>Fix CVE(s): CVE-2025-1094</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: improper neutralization of quoting syntax in libpq
     functions allows SQL injection via psql in certain usage patterns
     - debian/patches/CVE-2025-1094.patch: Fix handling of invalidly encoded data
       in escaping functions
     - CVE-2025-1094</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: improper neutralization of quoting syntax in libpq
     functions allows SQL injection via psql in certain usage patterns
     - debian/patches/CVE-2025-1094.patch: Fix handling of invalidly encoded data
       in escaping functions
     - CVE-2025-1094</summary>
    <pushcount>0</pushcount>
    <issued date="2025-12-04 17:11:36 UTC" />
    <updated date="2025-12-04 17:11:36 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1764868292.html" id="CLSA-2025:1764868292" title="CLSA-2025:1764868292" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libecpg-compat3" version="11.22-0+deb10u2+tuxcare.els1">
          <filename>libecpg-compat3_11.22-0+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">12f696279570e0794de2b492cac4baea2e29fe55</sum>
        </package>
        <package arch="amd64" name="libecpg-dev" version="11.22-0+deb10u2+tuxcare.els1">
          <filename>libecpg-dev_11.22-0+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">c513ea3b3414d60d0d1e3b19e80bf7966d76eefd</sum>
        </package>
        <package arch="amd64" name="libecpg6" version="11.22-0+deb10u2+tuxcare.els1">
          <filename>libecpg6_11.22-0+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">dd4b15c2b23f243cc7e1d993eec302698340fb93</sum>
        </package>
        <package arch="amd64" name="libpgtypes3" version="11.22-0+deb10u2+tuxcare.els1">
          <filename>libpgtypes3_11.22-0+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">0c3b45a90d1c3e53a926a799eb27bdc641b29257</sum>
        </package>
        <package arch="amd64" name="libpq-dev" version="11.22-0+deb10u2+tuxcare.els1">
          <filename>libpq-dev_11.22-0+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">e563f53ec36e77a1b18a3bc4ab34e0a349a8dd54</sum>
        </package>
        <package arch="amd64" name="libpq5" version="11.22-0+deb10u2+tuxcare.els1">
          <filename>libpq5_11.22-0+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">493117f8077758b9f61a5a9dea31090b1aea872f</sum>
        </package>
        <package arch="amd64" name="postgresql-11" version="11.22-0+deb10u2+tuxcare.els1">
          <filename>postgresql-11_11.22-0+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">7326a97ce2ac68e523362e1b4922af5ea058a607</sum>
        </package>
        <package arch="amd64" name="postgresql-client-11" version="11.22-0+deb10u2+tuxcare.els1">
          <filename>postgresql-client-11_11.22-0+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">ca882b7d88e1cb1fa2c41743b35bfea771be90a3</sum>
        </package>
        <package arch="all" name="postgresql-doc-11" version="11.22-0+deb10u2+tuxcare.els1">
          <filename>postgresql-doc-11_11.22-0+deb10u2+tuxcare.els1_all.deb</filename>
          <sum type="sha">7627151dc79d11a681ba5faac3462eafe09c50a1</sum>
        </package>
        <package arch="amd64" name="postgresql-plperl-11" version="11.22-0+deb10u2+tuxcare.els1">
          <filename>postgresql-plperl-11_11.22-0+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">cc7daa65cc1642d585f33268824a150a9eac63e3</sum>
        </package>
        <package arch="amd64" name="postgresql-plpython-11" version="11.22-0+deb10u2+tuxcare.els1">
          <filename>postgresql-plpython-11_11.22-0+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">8d69debe71765082b9db7934714d3d6a185a135f</sum>
        </package>
        <package arch="amd64" name="postgresql-plpython3-11" version="11.22-0+deb10u2+tuxcare.els1">
          <filename>postgresql-plpython3-11_11.22-0+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">1c6b99ce33631b85fc6486c3779ec10b79d3fab9</sum>
        </package>
        <package arch="amd64" name="postgresql-pltcl-11" version="11.22-0+deb10u2+tuxcare.els1">
          <filename>postgresql-pltcl-11_11.22-0+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">5b7ed2fa1e729a2f55258a0ab4ea428f73518722</sum>
        </package>
        <package arch="amd64" name="postgresql-server-dev-11" version="11.22-0+deb10u2+tuxcare.els1">
          <filename>postgresql-server-dev-11_11.22-0+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">a4fa4b0606db2f6986e832c82cd3189bf9c706c7</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1764321086</id>
    <title>Fix CVE(s): CVE-2025-6297</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Directory permission cleanup vulnerability leading to DoS
     - debian/patches/CVE-2025-6297.patch: Fix cleanup for control member
       with restricted directories
     - CVE-2025-6297</description>
    <severity>Low</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Directory permission cleanup vulnerability leading to DoS
     - debian/patches/CVE-2025-6297.patch: Fix cleanup for control member
       with restricted directories
     - CVE-2025-6297</summary>
    <pushcount>0</pushcount>
    <issued date="2025-12-08 16:30:02 UTC" />
    <updated date="2025-12-08 16:30:02 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1764321086.html" id="CLSA-2025:1764321086" title="CLSA-2025:1764321086" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="dpkg" version="1.19.8+tuxcare.els1">
          <filename>dpkg_1.19.8+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">c26b4542ed7b9107141c8d555c35c10b3ee890e5</sum>
        </package>
        <package arch="all" name="dpkg-dev" version="1.19.8+tuxcare.els1">
          <filename>dpkg-dev_1.19.8+tuxcare.els1_all.deb</filename>
          <sum type="sha">e6c2d4237229f6e8f851bac68f3dd66821f95654</sum>
        </package>
        <package arch="amd64" name="dselect" version="1.19.8+tuxcare.els1">
          <filename>dselect_1.19.8+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">a20d8ff9cf4651879d0d486ce49cbf02b2b3a01a</sum>
        </package>
        <package arch="amd64" name="libdpkg-dev" version="1.19.8+tuxcare.els1">
          <filename>libdpkg-dev_1.19.8+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">b5329bb3c0f7a3d987ae777f7e92bd85b8001f8f</sum>
        </package>
        <package arch="all" name="libdpkg-perl" version="1.19.8+tuxcare.els1">
          <filename>libdpkg-perl_1.19.8+tuxcare.els1_all.deb</filename>
          <sum type="sha">da02c23378a24278ea01f0da8207afc68fee35bf</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1765285897</id>
    <title>Fix CVE(s): CVE-2021-3738</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: use after free in Samba AD DC RPC server
     - debian/patches/CVE-2021-3738-pre.patch: prepare service routines before
       fixing CVE-2021-3738
     - debian/patches/CVE-2021-3738.patch: avoids a crash caused by
       use-after-free in Samba AD DC RPC server
     - CVE-2021-3738.patch</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: use after free in Samba AD DC RPC server
     - debian/patches/CVE-2021-3738-pre.patch: prepare service routines before
       fixing CVE-2021-3738
     - debian/patches/CVE-2021-3738.patch: avoids a crash caused by
       use-after-free in Samba AD DC RPC server
     - CVE-2021-3738.patch</summary>
    <pushcount>0</pushcount>
    <issued date="2025-12-09 13:11:41 UTC" />
    <updated date="2025-12-09 13:11:41 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1765285897.html" id="CLSA-2025:1765285897" title="CLSA-2025:1765285897" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="ctdb" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els5">
          <filename>ctdb_4.9.5+dfsg-5+deb10u5+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">60e47cc604c848fdc9a2d3d6a75fe68f3d3e7c91</sum>
        </package>
        <package arch="amd64" name="libnss-winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els5">
          <filename>libnss-winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">f8e723110a18e0cf0879934215ad47631c51c66f</sum>
        </package>
        <package arch="amd64" name="libpam-winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els5">
          <filename>libpam-winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">a98541b46f5e1800cceea983a0a420327ce37a8a</sum>
        </package>
        <package arch="amd64" name="libsmbclient" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els5">
          <filename>libsmbclient_4.9.5+dfsg-5+deb10u5+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">e0b5d960ea15d281195744a9be5e4994ac309a4c</sum>
        </package>
        <package arch="amd64" name="libsmbclient-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els5">
          <filename>libsmbclient-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">ac8114548f773646633aa382fd4605d3290edee7</sum>
        </package>
        <package arch="amd64" name="libwbclient-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els5">
          <filename>libwbclient-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">53fb41d09c1342dd67f9df97abac82ffdf0e32fd</sum>
        </package>
        <package arch="amd64" name="libwbclient0" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els5">
          <filename>libwbclient0_4.9.5+dfsg-5+deb10u5+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">0fd552a897a039be2450254d23a39d40fc36b1fe</sum>
        </package>
        <package arch="amd64" name="python-samba" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els5">
          <filename>python-samba_4.9.5+dfsg-5+deb10u5+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">127e78d34a16a185fd6d5014831f31057e59a530</sum>
        </package>
        <package arch="amd64" name="registry-tools" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els5">
          <filename>registry-tools_4.9.5+dfsg-5+deb10u5+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">71723c56ce0bdfd25dd0b75bfbad0538e913fd1f</sum>
        </package>
        <package arch="amd64" name="samba" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els5">
          <filename>samba_4.9.5+dfsg-5+deb10u5+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">f9a3cf847283b8e3e7cc197cea8855487117a13b</sum>
        </package>
        <package arch="all" name="samba-common" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els5">
          <filename>samba-common_4.9.5+dfsg-5+deb10u5+tuxcare.els5_all.deb</filename>
          <sum type="sha">6425005446902119af5fa2a409270fc96ebcd175</sum>
        </package>
        <package arch="amd64" name="samba-common-bin" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els5">
          <filename>samba-common-bin_4.9.5+dfsg-5+deb10u5+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">00963eaffefa9d0a6a8a8b3c49c2907731052131</sum>
        </package>
        <package arch="amd64" name="samba-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els5">
          <filename>samba-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">47c048e18797cdf6dbc3d16aabb931182723f0f0</sum>
        </package>
        <package arch="amd64" name="samba-dsdb-modules" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els5">
          <filename>samba-dsdb-modules_4.9.5+dfsg-5+deb10u5+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">2b4ca214e9321a55d4849812a0ff0a9d54c25a62</sum>
        </package>
        <package arch="amd64" name="samba-libs" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els5">
          <filename>samba-libs_4.9.5+dfsg-5+deb10u5+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">3bc4d38b09b76ed9fcba3888f7fc65b9498e98b3</sum>
        </package>
        <package arch="amd64" name="samba-testsuite" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els5">
          <filename>samba-testsuite_4.9.5+dfsg-5+deb10u5+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">29c33b7e5c4794595b865035b17e8ba6afcb0b67</sum>
        </package>
        <package arch="amd64" name="samba-vfs-modules" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els5">
          <filename>samba-vfs-modules_4.9.5+dfsg-5+deb10u5+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">44ed72602987e3b50183bd43f51d4e615cb69b5d</sum>
        </package>
        <package arch="amd64" name="smbclient" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els5">
          <filename>smbclient_4.9.5+dfsg-5+deb10u5+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">25e4b254c657cd8ce264f6df2112a2f3d8951f28</sum>
        </package>
        <package arch="amd64" name="winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els5">
          <filename>winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">79cbca1d1a64a2f7cbc1599eacd98ab1a93f2c36</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1765286037</id>
    <title>Fix CVE(s): CVE-2025-22134</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Heap-buffer overflow when switching buffers in visual mode
     - debian/patches/CVE-2025-22134.patch: fix visual mode heap-buffer-overflow
       by resetting VIsual mode on :all
     - CVE-2025-22134</description>
    <severity>Moderate</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Heap-buffer overflow when switching buffers in visual mode
     - debian/patches/CVE-2025-22134.patch: fix visual mode heap-buffer-overflow
       by resetting VIsual mode on :all
     - CVE-2025-22134</summary>
    <pushcount>0</pushcount>
    <issued date="2025-12-09 13:14:00 UTC" />
    <updated date="2025-12-09 13:14:00 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1765286037.html" id="CLSA-2025:1765286037" title="CLSA-2025:1765286037" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="vim" version="2:8.1.0875-5+deb10u6+tuxcare.els14">
          <filename>vim_8.1.0875-5+deb10u6+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">6369f6ae9b8cb3bd6ac547477798bd85f1eadb84</sum>
        </package>
        <package arch="amd64" name="vim-athena" version="2:8.1.0875-5+deb10u6+tuxcare.els14">
          <filename>vim-athena_8.1.0875-5+deb10u6+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">1f1ef329c0b61d5e14ec7415d69ac13ba753b650</sum>
        </package>
        <package arch="all" name="vim-common" version="2:8.1.0875-5+deb10u6+tuxcare.els14">
          <filename>vim-common_8.1.0875-5+deb10u6+tuxcare.els14_all.deb</filename>
          <sum type="sha">ab06abf2b24bd560823f46290f90d31ab35595e7</sum>
        </package>
        <package arch="all" name="vim-doc" version="2:8.1.0875-5+deb10u6+tuxcare.els14">
          <filename>vim-doc_8.1.0875-5+deb10u6+tuxcare.els14_all.deb</filename>
          <sum type="sha">46bbc207cfa2e32cff9840eb7b0d9bd17e212dfa</sum>
        </package>
        <package arch="amd64" name="vim-gtk" version="2:8.1.0875-5+deb10u6+tuxcare.els14">
          <filename>vim-gtk_8.1.0875-5+deb10u6+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">19acb3bfe4fb0eec2097c82cd3e1a06b9818a7f8</sum>
        </package>
        <package arch="amd64" name="vim-gtk3" version="2:8.1.0875-5+deb10u6+tuxcare.els14">
          <filename>vim-gtk3_8.1.0875-5+deb10u6+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">25a5e11672ac1add8abe7a2d961896fc29cef825</sum>
        </package>
        <package arch="all" name="vim-gui-common" version="2:8.1.0875-5+deb10u6+tuxcare.els14">
          <filename>vim-gui-common_8.1.0875-5+deb10u6+tuxcare.els14_all.deb</filename>
          <sum type="sha">3b8ae32220a929f6462ea1adce3d2b2d12bffd4d</sum>
        </package>
        <package arch="amd64" name="vim-nox" version="2:8.1.0875-5+deb10u6+tuxcare.els14">
          <filename>vim-nox_8.1.0875-5+deb10u6+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">4fb07d198e1beb3db12f1c08dd10fbf687f48eb1</sum>
        </package>
        <package arch="all" name="vim-runtime" version="2:8.1.0875-5+deb10u6+tuxcare.els14">
          <filename>vim-runtime_8.1.0875-5+deb10u6+tuxcare.els14_all.deb</filename>
          <sum type="sha">95dd2dec147d12441f42a8b579b6b15a83fdf513</sum>
        </package>
        <package arch="amd64" name="vim-tiny" version="2:8.1.0875-5+deb10u6+tuxcare.els14">
          <filename>vim-tiny_8.1.0875-5+deb10u6+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">4f04fc31e9766d06550dc1b594415b5dcc9c4ad7</sum>
        </package>
        <package arch="amd64" name="xxd" version="2:8.1.0875-5+deb10u6+tuxcare.els14">
          <filename>xxd_8.1.0875-5+deb10u6+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">e4f43db94a906e224435ada481df6935b5848a89</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1766136770</id>
    <title>Fix CVE(s): CVE-2025-26465</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: VerifyHostKeyDNS server impersonation
     - debian/patches/CVE-2025-26465.patch: Fix cases where error codes
       were not correctly set
     - CVE-2025-26465</description>
    <severity>Moderate</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: VerifyHostKeyDNS server impersonation
     - debian/patches/CVE-2025-26465.patch: Fix cases where error codes
       were not correctly set
     - CVE-2025-26465</summary>
    <pushcount>0</pushcount>
    <issued date="2025-12-19 09:32:53 UTC" />
    <updated date="2025-12-19 09:32:53 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1766136770.html" id="CLSA-2025:1766136770" title="CLSA-2025:1766136770" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="openssh-client" version="1:7.9p1-10+deb10u4+tuxcare.els1">
          <filename>openssh-client_7.9p1-10+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">d6d3a62ae52c08b84d505c4c32dd8bf1147c31b9</sum>
        </package>
        <package arch="amd64" name="openssh-server" version="1:7.9p1-10+deb10u4+tuxcare.els1">
          <filename>openssh-server_7.9p1-10+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">112605b9718c54d8727bfd499672a3c771ba8526</sum>
        </package>
        <package arch="amd64" name="openssh-sftp-server" version="1:7.9p1-10+deb10u4+tuxcare.els1">
          <filename>openssh-sftp-server_7.9p1-10+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">d5500435c1028fb8a18ef6598b61596f77b88265</sum>
        </package>
        <package arch="amd64" name="openssh-tests" version="1:7.9p1-10+deb10u4+tuxcare.els1">
          <filename>openssh-tests_7.9p1-10+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">92460bf35bb5096eaf92566874f6f6ea4d95a065</sum>
        </package>
        <package arch="all" name="ssh" version="1:7.9p1-10+deb10u4+tuxcare.els1">
          <filename>ssh_7.9p1-10+deb10u4+tuxcare.els1_all.deb</filename>
          <sum type="sha">ce2c3c02881de42b1aee90e780190ba2c488b8e9</sum>
        </package>
        <package arch="amd64" name="ssh-askpass-gnome" version="1:7.9p1-10+deb10u4+tuxcare.els1">
          <filename>ssh-askpass-gnome_7.9p1-10+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">7bd13c2feb16954cd63c23ddcc6a94b4e88ef0d6</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1766567499</id>
    <title>Fix CVE(s): CVE-2020-1472</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: elevation of privilege vulnerability
     - debian/patches/CVE-2020-1472.patch: fix vulnerability when an attacker
       establishes a vulnerable Netlogon secure channel connection to a domain
       controller, using the Netlogon Remote Protocol (MS-NRPC)
     - CVE-2020-1472</description>
    <severity>Low</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: elevation of privilege vulnerability
     - debian/patches/CVE-2020-1472.patch: fix vulnerability when an attacker
       establishes a vulnerable Netlogon secure channel connection to a domain
       controller, using the Netlogon Remote Protocol (MS-NRPC)
     - CVE-2020-1472</summary>
    <pushcount>0</pushcount>
    <issued date="2025-12-24 09:11:43 UTC" />
    <updated date="2025-12-24 09:11:43 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1766567499.html" id="CLSA-2025:1766567499" title="CLSA-2025:1766567499" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="ctdb" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els7">
          <filename>ctdb_4.9.5+dfsg-5+deb10u5+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">1b724b1375beea7ef51ca1b92598265732bf1e0d</sum>
        </package>
        <package arch="amd64" name="libnss-winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els7">
          <filename>libnss-winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">0570f9ac785c5cf6555a8cfb58f6022f94556f3c</sum>
        </package>
        <package arch="amd64" name="libpam-winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els7">
          <filename>libpam-winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">e24c1d8d9103ece96ab906199ea46ebe4b4327d7</sum>
        </package>
        <package arch="amd64" name="libsmbclient" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els7">
          <filename>libsmbclient_4.9.5+dfsg-5+deb10u5+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">2ea7502b207070cca875c0c1d4482d1bbceb225a</sum>
        </package>
        <package arch="amd64" name="libsmbclient-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els7">
          <filename>libsmbclient-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">7a329de8e9f1cbbad85ff7393853750b3a0b1d63</sum>
        </package>
        <package arch="amd64" name="libwbclient-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els7">
          <filename>libwbclient-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">144b34dc0bf7b067bbfb2c7750cc04035b37dc43</sum>
        </package>
        <package arch="amd64" name="libwbclient0" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els7">
          <filename>libwbclient0_4.9.5+dfsg-5+deb10u5+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">f6fd52fdefd908b2c20598562c73ac4ebd70ae34</sum>
        </package>
        <package arch="amd64" name="python-samba" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els7">
          <filename>python-samba_4.9.5+dfsg-5+deb10u5+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">8f47cebbb075bf2075e749ed88270a5f09d0b348</sum>
        </package>
        <package arch="amd64" name="registry-tools" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els7">
          <filename>registry-tools_4.9.5+dfsg-5+deb10u5+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">1b3fb01219a1c135d8a63c7d3e07844d2a86d139</sum>
        </package>
        <package arch="amd64" name="samba" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els7">
          <filename>samba_4.9.5+dfsg-5+deb10u5+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">fe11449cf7c5028375176586b2a224d169382298</sum>
        </package>
        <package arch="all" name="samba-common" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els7">
          <filename>samba-common_4.9.5+dfsg-5+deb10u5+tuxcare.els7_all.deb</filename>
          <sum type="sha">5e08addf9f518678c0cb252cb81f7c33033b7bb2</sum>
        </package>
        <package arch="amd64" name="samba-common-bin" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els7">
          <filename>samba-common-bin_4.9.5+dfsg-5+deb10u5+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">407533701508456c4e769a47547d26ba18200281</sum>
        </package>
        <package arch="amd64" name="samba-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els7">
          <filename>samba-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">5baddbdbd73916a93af0ab612d8ad1000c097c49</sum>
        </package>
        <package arch="amd64" name="samba-dsdb-modules" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els7">
          <filename>samba-dsdb-modules_4.9.5+dfsg-5+deb10u5+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">0f748c768a1ca67b53df6a19f3478cb66febe815</sum>
        </package>
        <package arch="amd64" name="samba-libs" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els7">
          <filename>samba-libs_4.9.5+dfsg-5+deb10u5+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">e5e3968806e4b1e6caaac57941d54037e4d752dc</sum>
        </package>
        <package arch="amd64" name="samba-testsuite" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els7">
          <filename>samba-testsuite_4.9.5+dfsg-5+deb10u5+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">53dcdb123343fb1bf8d77420d0517a87f2d79074</sum>
        </package>
        <package arch="amd64" name="samba-vfs-modules" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els7">
          <filename>samba-vfs-modules_4.9.5+dfsg-5+deb10u5+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">61392270424ecc7cca4b2a5a2498de306f758148</sum>
        </package>
        <package arch="amd64" name="smbclient" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els7">
          <filename>smbclient_4.9.5+dfsg-5+deb10u5+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">6a063c41a6d9f6260d8713607f4b4f3883df50aa</sum>
        </package>
        <package arch="amd64" name="winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els7">
          <filename>winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">2ee34d90ce00baf5ea182687438cc2f5491e4bd6</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1766567686</id>
    <title>Fix CVE(s): CVE-2025-32728</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: DisableForwarding directive does not adhere to the
     documentation stating that it disables X11 and agent forwarding.
     - debian/patches/CVE-2025-32728.patch: fix logic error in DisableForwarding
       option
     - CVE-2025-32728</description>
    <severity>Low</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: DisableForwarding directive does not adhere to the
     documentation stating that it disables X11 and agent forwarding.
     - debian/patches/CVE-2025-32728.patch: fix logic error in DisableForwarding
       option
     - CVE-2025-32728</summary>
    <pushcount>0</pushcount>
    <issued date="2025-12-24 09:14:50 UTC" />
    <updated date="2025-12-24 09:14:50 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1766567686.html" id="CLSA-2025:1766567686" title="CLSA-2025:1766567686" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="openssh-client" version="1:7.9p1-10+deb10u4+tuxcare.els2">
          <filename>openssh-client_7.9p1-10+deb10u4+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">5dab2a0d587da068025eb7b918a391e9a37e2804</sum>
        </package>
        <package arch="amd64" name="openssh-server" version="1:7.9p1-10+deb10u4+tuxcare.els2">
          <filename>openssh-server_7.9p1-10+deb10u4+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">c1f4b35912913a15900c0793bfc13d12d0f3fb24</sum>
        </package>
        <package arch="amd64" name="openssh-sftp-server" version="1:7.9p1-10+deb10u4+tuxcare.els2">
          <filename>openssh-sftp-server_7.9p1-10+deb10u4+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">eac5365fc77f190d90c059b17d23a358bf988b19</sum>
        </package>
        <package arch="amd64" name="openssh-tests" version="1:7.9p1-10+deb10u4+tuxcare.els2">
          <filename>openssh-tests_7.9p1-10+deb10u4+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">d27cc5a10e9323a0556bfb3257937f331b3c5308</sum>
        </package>
        <package arch="all" name="ssh" version="1:7.9p1-10+deb10u4+tuxcare.els2">
          <filename>ssh_7.9p1-10+deb10u4+tuxcare.els2_all.deb</filename>
          <sum type="sha">c6f457787455f8f9fc08fbf113cfccd802d18a34</sum>
        </package>
        <package arch="amd64" name="ssh-askpass-gnome" version="1:7.9p1-10+deb10u4+tuxcare.els2">
          <filename>ssh-askpass-gnome_7.9p1-10+deb10u4+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">08c681eaed56c620821e7d2399075a13a467e11c</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1767870671</id>
    <title>Fix CVE(s): CVE-2024-52006</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Carriage Return injection in credential protocol
     - debian/patches/CVE-2024-52006.patch: fix Carriage Return injection
       in credential protocol
     - CVE-2024-52006</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Carriage Return injection in credential protocol
     - debian/patches/CVE-2024-52006.patch: fix Carriage Return injection
       in credential protocol
     - CVE-2024-52006</summary>
    <pushcount>0</pushcount>
    <issued date="2026-01-08 11:11:15 UTC" />
    <updated date="2026-01-08 11:11:15 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1767870671.html" id="CLSA-2026:1767870671" title="CLSA-2026:1767870671" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="git" version="1:2.20.1-2+deb10u9+tuxcare.els1">
          <filename>git_2.20.1-2+deb10u9+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">f3e5bfce9f302c5fca26c9740ad6ec31c4bdfc68</sum>
        </package>
        <package arch="all" name="git-all" version="1:2.20.1-2+deb10u9+tuxcare.els1">
          <filename>git-all_2.20.1-2+deb10u9+tuxcare.els1_all.deb</filename>
          <sum type="sha">e3f6ae14e84355b2283eb6e870d7b1ce68b5b4ba</sum>
        </package>
        <package arch="all" name="git-cvs" version="1:2.20.1-2+deb10u9+tuxcare.els1">
          <filename>git-cvs_2.20.1-2+deb10u9+tuxcare.els1_all.deb</filename>
          <sum type="sha">3e6265bde9c738290716f4da756811b4fc578748</sum>
        </package>
        <package arch="all" name="git-daemon-run" version="1:2.20.1-2+deb10u9+tuxcare.els1">
          <filename>git-daemon-run_2.20.1-2+deb10u9+tuxcare.els1_all.deb</filename>
          <sum type="sha">33ceba492ec56f51223db415590882c30a59e25e</sum>
        </package>
        <package arch="all" name="git-daemon-sysvinit" version="1:2.20.1-2+deb10u9+tuxcare.els1">
          <filename>git-daemon-sysvinit_2.20.1-2+deb10u9+tuxcare.els1_all.deb</filename>
          <sum type="sha">42ec486a1bd4d419f8ad38e8ae97de3284fe0081</sum>
        </package>
        <package arch="all" name="git-doc" version="1:2.20.1-2+deb10u9+tuxcare.els1">
          <filename>git-doc_2.20.1-2+deb10u9+tuxcare.els1_all.deb</filename>
          <sum type="sha">f5d85641605508b2eede7367150726f36eea15a2</sum>
        </package>
        <package arch="all" name="git-el" version="1:2.20.1-2+deb10u9+tuxcare.els1">
          <filename>git-el_2.20.1-2+deb10u9+tuxcare.els1_all.deb</filename>
          <sum type="sha">5da3e104d59ee8e170165a418dffac3150b1ef33</sum>
        </package>
        <package arch="all" name="git-email" version="1:2.20.1-2+deb10u9+tuxcare.els1">
          <filename>git-email_2.20.1-2+deb10u9+tuxcare.els1_all.deb</filename>
          <sum type="sha">019bc5e73e6da476680ac5cdfe56e7c8fecfdc06</sum>
        </package>
        <package arch="all" name="git-gui" version="1:2.20.1-2+deb10u9+tuxcare.els1">
          <filename>git-gui_2.20.1-2+deb10u9+tuxcare.els1_all.deb</filename>
          <sum type="sha">76d82453698bed650548c08d5464c691c4175912</sum>
        </package>
        <package arch="all" name="git-man" version="1:2.20.1-2+deb10u9+tuxcare.els1">
          <filename>git-man_2.20.1-2+deb10u9+tuxcare.els1_all.deb</filename>
          <sum type="sha">132b08cec4248f360305af5b3b96e1e39264783e</sum>
        </package>
        <package arch="all" name="git-mediawiki" version="1:2.20.1-2+deb10u9+tuxcare.els1">
          <filename>git-mediawiki_2.20.1-2+deb10u9+tuxcare.els1_all.deb</filename>
          <sum type="sha">a122373503c43088cf1ae067f45f5e36908767dc</sum>
        </package>
        <package arch="all" name="git-svn" version="1:2.20.1-2+deb10u9+tuxcare.els1">
          <filename>git-svn_2.20.1-2+deb10u9+tuxcare.els1_all.deb</filename>
          <sum type="sha">58a4da87cb9c17051519dd905c54857bdf6e5c53</sum>
        </package>
        <package arch="all" name="gitk" version="1:2.20.1-2+deb10u9+tuxcare.els1">
          <filename>gitk_2.20.1-2+deb10u9+tuxcare.els1_all.deb</filename>
          <sum type="sha">f4a16a7b5693cdd34e3f7e4f8c93223bde5aeb27</sum>
        </package>
        <package arch="all" name="gitweb" version="1:2.20.1-2+deb10u9+tuxcare.els1">
          <filename>gitweb_2.20.1-2+deb10u9+tuxcare.els1_all.deb</filename>
          <sum type="sha">2316e1b0ce91b29fdd264e2912c419ba0b08ed10</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1768299147</id>
    <title>Fix CVE(s): CVE-2025-14178</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: heap buffer overflow in array_merge()
     - debian/patches/CVE-2025-14178.patch: fix integer overflow in
       the precomputation of element counts using zend_hash_num_elements()
     - CVE-2025-14178</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: heap buffer overflow in array_merge()
     - debian/patches/CVE-2025-14178.patch: fix integer overflow in
       the precomputation of element counts using zend_hash_num_elements()
     - CVE-2025-14178</summary>
    <pushcount>0</pushcount>
    <issued date="2026-01-13 10:12:32 UTC" />
    <updated date="2026-01-13 10:12:32 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1768299147.html" id="CLSA-2026:1768299147" title="CLSA-2026:1768299147" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libapache2-mod-php7.3" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>libapache2-mod-php7.3_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">0fb63a3012370581d9eaa55b7452d2f81a7975ba</sum>
        </package>
        <package arch="amd64" name="libphp7.3-embed" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>libphp7.3-embed_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">1bb06842e3894d12014b2a89da18fea7e93614ab</sum>
        </package>
        <package arch="all" name="php7.3" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3_7.3.31-1~deb10u7+tuxcare.els3_all.deb</filename>
          <sum type="sha">b13524e4731aa1c3df3258d05411094d6e46e775</sum>
        </package>
        <package arch="amd64" name="php7.3-bcmath" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-bcmath_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">a3fe0a64f6d5c0dc0876219ce47065c2c668d7be</sum>
        </package>
        <package arch="amd64" name="php7.3-bz2" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-bz2_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">669121128b4543b71511d8ba01a51e2d18c16168</sum>
        </package>
        <package arch="amd64" name="php7.3-cgi" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-cgi_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">0d1eb9c227b71cf8fb9da1a3d9503d4bf4ad95bb</sum>
        </package>
        <package arch="amd64" name="php7.3-cli" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-cli_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">5d4469c9ba28e4c5a32ab0f6ebfb1ce39a578439</sum>
        </package>
        <package arch="amd64" name="php7.3-common" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-common_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">515d612755b61d1613aae896e105f664a8e34285</sum>
        </package>
        <package arch="amd64" name="php7.3-curl" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-curl_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">7c537f44b6e0525bdd1b79b87dc1553ad24de266</sum>
        </package>
        <package arch="amd64" name="php7.3-dba" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-dba_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">4a96498bf6aa8c4e1b0cf7a372960b2d2ba7bb50</sum>
        </package>
        <package arch="amd64" name="php7.3-dev" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-dev_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">a83106af62d6b7f4566f8424494792eef1c23065</sum>
        </package>
        <package arch="amd64" name="php7.3-enchant" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-enchant_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">340eef202d1ab9ae5c5bb15194cba970109c7e94</sum>
        </package>
        <package arch="amd64" name="php7.3-fpm" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-fpm_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">d9f703ba6534e43fe228f45ad62318bd69c2f3e7</sum>
        </package>
        <package arch="amd64" name="php7.3-gd" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-gd_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">8e6a61097eabf84deb40758986489c4b50ac348a</sum>
        </package>
        <package arch="amd64" name="php7.3-gmp" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-gmp_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">77c981fdc78729171a5b2a855c063f5cdfa65e6a</sum>
        </package>
        <package arch="amd64" name="php7.3-imap" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-imap_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">6f1faa0ccc50aa92a985166e001732f2d190888e</sum>
        </package>
        <package arch="amd64" name="php7.3-interbase" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-interbase_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">1bc36a06e2b5c85ae11435d277b38b3ed2c5fc6d</sum>
        </package>
        <package arch="amd64" name="php7.3-intl" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-intl_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">8d1c46404c42a821ffe90ff3500b921eea3dc438</sum>
        </package>
        <package arch="amd64" name="php7.3-json" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-json_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">18a8860162f7c4fb2ccdffe6b954817aa54e5ba3</sum>
        </package>
        <package arch="amd64" name="php7.3-ldap" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-ldap_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">c3ebf1d2303d8df482e41aacd85a2de2f6c1b198</sum>
        </package>
        <package arch="amd64" name="php7.3-mbstring" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-mbstring_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">10dcca962ddedbbfbd1ca3020511ee268cfdf0b7</sum>
        </package>
        <package arch="amd64" name="php7.3-mysql" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-mysql_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">e5e16a94fb4fa62560b51aa541b85a67de4410b3</sum>
        </package>
        <package arch="amd64" name="php7.3-odbc" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-odbc_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">2f13a188167f6ab26d26332954b414fbaf9973b9</sum>
        </package>
        <package arch="amd64" name="php7.3-opcache" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-opcache_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">3f334e302ca447d76a3234708a73f059d89b126f</sum>
        </package>
        <package arch="amd64" name="php7.3-pgsql" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-pgsql_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">47852db4dc5dadaf1194e78cd3d5c948f2397081</sum>
        </package>
        <package arch="amd64" name="php7.3-phpdbg" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-phpdbg_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">64aea0b774b9bb177eebae8cc6e8077e6ab33e78</sum>
        </package>
        <package arch="amd64" name="php7.3-pspell" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-pspell_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">9cd2721f05c4de83919e71ed7ebdcfbb1e321235</sum>
        </package>
        <package arch="amd64" name="php7.3-readline" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-readline_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">e5ab5857d3f4dcc0e2938742a3e01def6a0ed09b</sum>
        </package>
        <package arch="amd64" name="php7.3-recode" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-recode_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">8e183ad7c9d50abdad7850f3d9bb7978e54d61e3</sum>
        </package>
        <package arch="amd64" name="php7.3-snmp" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-snmp_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">cd08a04747f0f2e3aab9b5bf12866618d8e54a62</sum>
        </package>
        <package arch="amd64" name="php7.3-soap" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-soap_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">9a2fdb4a25157d7291c2170cc32de9ecadc2d7ed</sum>
        </package>
        <package arch="amd64" name="php7.3-sqlite3" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-sqlite3_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">78524dabcabcd076ce39d83284807fcd105889e4</sum>
        </package>
        <package arch="amd64" name="php7.3-sybase" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-sybase_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">75064a8e3a8d05b46460707ea44a84434aa115d5</sum>
        </package>
        <package arch="amd64" name="php7.3-tidy" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-tidy_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">16aff3fb911a49a0f270d6df11d13ded13f678eb</sum>
        </package>
        <package arch="amd64" name="php7.3-xml" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-xml_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">020e136299b66cb48263fd9fbf5947ff433cf39a</sum>
        </package>
        <package arch="amd64" name="php7.3-xmlrpc" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-xmlrpc_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">2ad04dd3d5037c93588603fb1151f45f65ce4f8b</sum>
        </package>
        <package arch="all" name="php7.3-xsl" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-xsl_7.3.31-1~deb10u7+tuxcare.els3_all.deb</filename>
          <sum type="sha">99623dc35a3afbf8a0aecfe3082878fa9e8e8728</sum>
        </package>
        <package arch="amd64" name="php7.3-zip" version="7.3.31-1~deb10u7+tuxcare.els3">
          <filename>php7.3-zip_7.3.31-1~deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">b72e9415eb79b42e8ab2f6c338c5fe0299807679</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1768300368</id>
    <title>Fix CVE(s): CVE-2025-58436</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix DoS by a client that connect to cupsd sends slow
     messages.
     - debian/patches/CVE-2025-58436.patch: fix unresponsive cupsd process
       caused by a slow client.
     - CVE-2025-58436.
   * Fix test/run-stp-tests.sh
     - debian/patches/waiting-limit.patch: limit the waiting for a server
       dunring tests</description>
    <severity>Moderate</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix DoS by a client that connect to cupsd sends slow
     messages.
     - debian/patches/CVE-2025-58436.patch: fix unresponsive cupsd process
       caused by a slow client.
     - CVE-2025-58436.
   * Fix test/run-stp-tests.sh
     - debian/patches/waiting-limit.patch: limit the waiting for a server
       dunring tests</summary>
    <pushcount>0</pushcount>
    <issued date="2026-01-13 10:32:54 UTC" />
    <updated date="2026-01-13 10:32:54 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1768300368.html" id="CLSA-2026:1768300368" title="CLSA-2026:1768300368" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="cups" version="2.2.10-6+deb10u10+tuxcare.els1">
          <filename>cups_2.2.10-6+deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">ba1014d103737fd11bcc722f5e8963098963299f</sum>
        </package>
        <package arch="amd64" name="cups-bsd" version="2.2.10-6+deb10u10+tuxcare.els1">
          <filename>cups-bsd_2.2.10-6+deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">f515a7ef22f7b92020202ba8fbbef1260f5b37d8</sum>
        </package>
        <package arch="amd64" name="cups-client" version="2.2.10-6+deb10u10+tuxcare.els1">
          <filename>cups-client_2.2.10-6+deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">6020c98127617c08792d173d47d8a91b5fabc1ac</sum>
        </package>
        <package arch="all" name="cups-common" version="2.2.10-6+deb10u10+tuxcare.els1">
          <filename>cups-common_2.2.10-6+deb10u10+tuxcare.els1_all.deb</filename>
          <sum type="sha">73ed25b3cada79564ab2370459bab84eaa19ba57</sum>
        </package>
        <package arch="amd64" name="cups-core-drivers" version="2.2.10-6+deb10u10+tuxcare.els1">
          <filename>cups-core-drivers_2.2.10-6+deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">f396ad3167af076a941100722374909db4bf3dc9</sum>
        </package>
        <package arch="amd64" name="cups-daemon" version="2.2.10-6+deb10u10+tuxcare.els1">
          <filename>cups-daemon_2.2.10-6+deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">74e382bcf2e17ee9b8ead792a132e8af82c1206c</sum>
        </package>
        <package arch="amd64" name="cups-ipp-utils" version="2.2.10-6+deb10u10+tuxcare.els1">
          <filename>cups-ipp-utils_2.2.10-6+deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">647c5f8232b1d1ab947a283448af07640a46613d</sum>
        </package>
        <package arch="amd64" name="cups-ppdc" version="2.2.10-6+deb10u10+tuxcare.els1">
          <filename>cups-ppdc_2.2.10-6+deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">d9870824914895c48e654ac16c60c1a62d6a5625</sum>
        </package>
        <package arch="all" name="cups-server-common" version="2.2.10-6+deb10u10+tuxcare.els1">
          <filename>cups-server-common_2.2.10-6+deb10u10+tuxcare.els1_all.deb</filename>
          <sum type="sha">67ea76043c850a9794f90a5012d5a9f24cc61a1b</sum>
        </package>
        <package arch="amd64" name="libcups2" version="2.2.10-6+deb10u10+tuxcare.els1">
          <filename>libcups2_2.2.10-6+deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">4a1553945c9a6e2fa0cad07cace80d0961c5e580</sum>
        </package>
        <package arch="amd64" name="libcups2-dev" version="2.2.10-6+deb10u10+tuxcare.els1">
          <filename>libcups2-dev_2.2.10-6+deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">97af18f7ff5bb4d177c7ba6c5c36556c66a05389</sum>
        </package>
        <package arch="amd64" name="libcupsimage2" version="2.2.10-6+deb10u10+tuxcare.els1">
          <filename>libcupsimage2_2.2.10-6+deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">1b99714fc8958a8ba73cdec99dd94670e31b083b</sum>
        </package>
        <package arch="amd64" name="libcupsimage2-dev" version="2.2.10-6+deb10u10+tuxcare.els1">
          <filename>libcupsimage2-dev_2.2.10-6+deb10u10+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">90af05395dafd7506ece26d28c7c38327bf50d95</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1768300849</id>
    <title>Fix CVE(s): CVE-2024-50349</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: improper encoding or escaping of credential handling
   - debian/patches/CVE-2024-50349.patch: fix ANSI escape sequence
     vulnerability that occurs when asking for credentials interactively
   - CVE-2024-50349</description>
    <severity>Moderate</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: improper encoding or escaping of credential handling
   - debian/patches/CVE-2024-50349.patch: fix ANSI escape sequence
     vulnerability that occurs when asking for credentials interactively
   - CVE-2024-50349</summary>
    <pushcount>0</pushcount>
    <issued date="2026-01-13 10:40:54 UTC" />
    <updated date="2026-01-13 10:40:54 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1768300849.html" id="CLSA-2026:1768300849" title="CLSA-2026:1768300849" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="git" version="1:2.20.1-2+deb10u9+tuxcare.els2">
          <filename>git_2.20.1-2+deb10u9+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">3ddda04d9ec11732a1ec64d973c892c93a2f2cf7</sum>
        </package>
        <package arch="all" name="git-all" version="1:2.20.1-2+deb10u9+tuxcare.els2">
          <filename>git-all_2.20.1-2+deb10u9+tuxcare.els2_all.deb</filename>
          <sum type="sha">2133c1c3f1cf91583441d8318255610008827ebf</sum>
        </package>
        <package arch="all" name="git-cvs" version="1:2.20.1-2+deb10u9+tuxcare.els2">
          <filename>git-cvs_2.20.1-2+deb10u9+tuxcare.els2_all.deb</filename>
          <sum type="sha">cdfe00bae70b10bada0b2073983dd4b6694b020b</sum>
        </package>
        <package arch="all" name="git-daemon-run" version="1:2.20.1-2+deb10u9+tuxcare.els2">
          <filename>git-daemon-run_2.20.1-2+deb10u9+tuxcare.els2_all.deb</filename>
          <sum type="sha">f387d34b40b6ebf3db427d7e7cb572caac7972e1</sum>
        </package>
        <package arch="all" name="git-daemon-sysvinit" version="1:2.20.1-2+deb10u9+tuxcare.els2">
          <filename>git-daemon-sysvinit_2.20.1-2+deb10u9+tuxcare.els2_all.deb</filename>
          <sum type="sha">e44a00c33d55549ba4cf2d2c8b91f4f5b1a3ec57</sum>
        </package>
        <package arch="all" name="git-doc" version="1:2.20.1-2+deb10u9+tuxcare.els2">
          <filename>git-doc_2.20.1-2+deb10u9+tuxcare.els2_all.deb</filename>
          <sum type="sha">7b5c1c28dc2c9fb1a1584a37ceb4475bcc4f2839</sum>
        </package>
        <package arch="all" name="git-el" version="1:2.20.1-2+deb10u9+tuxcare.els2">
          <filename>git-el_2.20.1-2+deb10u9+tuxcare.els2_all.deb</filename>
          <sum type="sha">10557a8237d8738b046898823b775c8942ab41e9</sum>
        </package>
        <package arch="all" name="git-email" version="1:2.20.1-2+deb10u9+tuxcare.els2">
          <filename>git-email_2.20.1-2+deb10u9+tuxcare.els2_all.deb</filename>
          <sum type="sha">59a3f983b1eb5e488505133b9f6f35341be98048</sum>
        </package>
        <package arch="all" name="git-gui" version="1:2.20.1-2+deb10u9+tuxcare.els2">
          <filename>git-gui_2.20.1-2+deb10u9+tuxcare.els2_all.deb</filename>
          <sum type="sha">837d075f8fd5c26cb5ef72e0a1da3835fdab8019</sum>
        </package>
        <package arch="all" name="git-man" version="1:2.20.1-2+deb10u9+tuxcare.els2">
          <filename>git-man_2.20.1-2+deb10u9+tuxcare.els2_all.deb</filename>
          <sum type="sha">36d8371dece680ffd1a49d0e7a053076497d0eae</sum>
        </package>
        <package arch="all" name="git-mediawiki" version="1:2.20.1-2+deb10u9+tuxcare.els2">
          <filename>git-mediawiki_2.20.1-2+deb10u9+tuxcare.els2_all.deb</filename>
          <sum type="sha">4ef5794067613155af0a182c6586898fd3a7207f</sum>
        </package>
        <package arch="all" name="git-svn" version="1:2.20.1-2+deb10u9+tuxcare.els2">
          <filename>git-svn_2.20.1-2+deb10u9+tuxcare.els2_all.deb</filename>
          <sum type="sha">095455a4ea49acc82fa728d6100bf27ec9ab38fd</sum>
        </package>
        <package arch="all" name="gitk" version="1:2.20.1-2+deb10u9+tuxcare.els2">
          <filename>gitk_2.20.1-2+deb10u9+tuxcare.els2_all.deb</filename>
          <sum type="sha">ac2b015a994910c8c7037bf200b95ebae9ec2da4</sum>
        </package>
        <package arch="all" name="gitweb" version="1:2.20.1-2+deb10u9+tuxcare.els2">
          <filename>gitweb_2.20.1-2+deb10u9+tuxcare.els2_all.deb</filename>
          <sum type="sha">c7b2cbda4f75c94ae79d76664befc34cb8672257</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1768395600</id>
    <title>Fix CVE(s): CVE-2024-32004</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Ownership checks for local repositories
     - debian/patches/CVE-2024-32004.patch: add fix for ownership check in
       local repositories
     - CVE-2024-32004</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Ownership checks for local repositories
     - debian/patches/CVE-2024-32004.patch: add fix for ownership check in
       local repositories
     - CVE-2024-32004</summary>
    <pushcount>0</pushcount>
    <issued date="2026-01-14 13:00:04 UTC" />
    <updated date="2026-01-14 13:00:04 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1768395600.html" id="CLSA-2026:1768395600" title="CLSA-2026:1768395600" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="git" version="1:2.20.1-2+deb10u9+tuxcare.els3">
          <filename>git_2.20.1-2+deb10u9+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">27caaa75a2797e923531e03f865bce3556a118c7</sum>
        </package>
        <package arch="all" name="git-all" version="1:2.20.1-2+deb10u9+tuxcare.els3">
          <filename>git-all_2.20.1-2+deb10u9+tuxcare.els3_all.deb</filename>
          <sum type="sha">d6eb0812c899270e1fbf317ffed7157888409b13</sum>
        </package>
        <package arch="all" name="git-cvs" version="1:2.20.1-2+deb10u9+tuxcare.els3">
          <filename>git-cvs_2.20.1-2+deb10u9+tuxcare.els3_all.deb</filename>
          <sum type="sha">ce3984418a2307519919929b129cd7a7231bcb8c</sum>
        </package>
        <package arch="all" name="git-daemon-run" version="1:2.20.1-2+deb10u9+tuxcare.els3">
          <filename>git-daemon-run_2.20.1-2+deb10u9+tuxcare.els3_all.deb</filename>
          <sum type="sha">cc221cad0f78d10fba71abb45c9b35f10030f272</sum>
        </package>
        <package arch="all" name="git-daemon-sysvinit" version="1:2.20.1-2+deb10u9+tuxcare.els3">
          <filename>git-daemon-sysvinit_2.20.1-2+deb10u9+tuxcare.els3_all.deb</filename>
          <sum type="sha">6623338b86321d263cb25aead62634df1c95cb5f</sum>
        </package>
        <package arch="all" name="git-doc" version="1:2.20.1-2+deb10u9+tuxcare.els3">
          <filename>git-doc_2.20.1-2+deb10u9+tuxcare.els3_all.deb</filename>
          <sum type="sha">1d0b90e91c4601156a98c16ee1021b838d50efe5</sum>
        </package>
        <package arch="all" name="git-el" version="1:2.20.1-2+deb10u9+tuxcare.els3">
          <filename>git-el_2.20.1-2+deb10u9+tuxcare.els3_all.deb</filename>
          <sum type="sha">ec594f6beb66bef10dbd7a41af1754f876d8c314</sum>
        </package>
        <package arch="all" name="git-email" version="1:2.20.1-2+deb10u9+tuxcare.els3">
          <filename>git-email_2.20.1-2+deb10u9+tuxcare.els3_all.deb</filename>
          <sum type="sha">d1468d685b776f67903d15bb30e7d0257b3d1c1a</sum>
        </package>
        <package arch="all" name="git-gui" version="1:2.20.1-2+deb10u9+tuxcare.els3">
          <filename>git-gui_2.20.1-2+deb10u9+tuxcare.els3_all.deb</filename>
          <sum type="sha">48faf3c9b9c5ce976330e94308be9463a2b1d75c</sum>
        </package>
        <package arch="all" name="git-man" version="1:2.20.1-2+deb10u9+tuxcare.els3">
          <filename>git-man_2.20.1-2+deb10u9+tuxcare.els3_all.deb</filename>
          <sum type="sha">54be7521ce5542fbfc9df6936bafc7f302e83a51</sum>
        </package>
        <package arch="all" name="git-mediawiki" version="1:2.20.1-2+deb10u9+tuxcare.els3">
          <filename>git-mediawiki_2.20.1-2+deb10u9+tuxcare.els3_all.deb</filename>
          <sum type="sha">82be2ded1dabcc42098b054c0cea6523fbe519bb</sum>
        </package>
        <package arch="all" name="git-svn" version="1:2.20.1-2+deb10u9+tuxcare.els3">
          <filename>git-svn_2.20.1-2+deb10u9+tuxcare.els3_all.deb</filename>
          <sum type="sha">a21509faca7d06d827d3e683bcf9c13910edf501</sum>
        </package>
        <package arch="all" name="gitk" version="1:2.20.1-2+deb10u9+tuxcare.els3">
          <filename>gitk_2.20.1-2+deb10u9+tuxcare.els3_all.deb</filename>
          <sum type="sha">9f76bd4c7701c69eb4c1e0d68c6dd14d2a29aea0</sum>
        </package>
        <package arch="all" name="gitweb" version="1:2.20.1-2+deb10u9+tuxcare.els3">
          <filename>gitweb_2.20.1-2+deb10u9+tuxcare.els3_all.deb</filename>
          <sum type="sha">ac516fe351830597adca891c3643cb7fd591334f</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1769524269</id>
    <title>Fix CVE(s): CVE-2025-68973</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: memory corruption in armor parser
     - debian/patches/CVE-2025-68973.patch: fix faulty double increment.
     - CVE-2025-68973</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: memory corruption in armor parser
     - debian/patches/CVE-2025-68973.patch: fix faulty double increment.
     - CVE-2025-68973</summary>
    <pushcount>0</pushcount>
    <issued date="2026-01-27 14:31:13 UTC" />
    <updated date="2026-01-27 14:31:13 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1769524269.html" id="CLSA-2026:1769524269" title="CLSA-2026:1769524269" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="dirmngr" version="2.2.12-1+deb10u2+tuxcare.els1">
          <filename>dirmngr_2.2.12-1+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">990c1eb963c9fc0904fe0214842ec14206e2ae01</sum>
        </package>
        <package arch="all" name="gnupg" version="2.2.12-1+deb10u2+tuxcare.els1">
          <filename>gnupg_2.2.12-1+deb10u2+tuxcare.els1_all.deb</filename>
          <sum type="sha">8b688e87acb083673e76306fd2def06a02e1f8a6</sum>
        </package>
        <package arch="all" name="gnupg-agent" version="2.2.12-1+deb10u2+tuxcare.els1">
          <filename>gnupg-agent_2.2.12-1+deb10u2+tuxcare.els1_all.deb</filename>
          <sum type="sha">73779d20c5a59ce622127b3df182f90d23f478c0</sum>
        </package>
        <package arch="all" name="gnupg-l10n" version="2.2.12-1+deb10u2+tuxcare.els1">
          <filename>gnupg-l10n_2.2.12-1+deb10u2+tuxcare.els1_all.deb</filename>
          <sum type="sha">41bb43464346773d5161fceea1529c0b9d4c35e2</sum>
        </package>
        <package arch="amd64" name="gnupg-utils" version="2.2.12-1+deb10u2+tuxcare.els1">
          <filename>gnupg-utils_2.2.12-1+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">caf9baad999eacd6007c2f0a18878eea390dc798</sum>
        </package>
        <package arch="all" name="gnupg2" version="2.2.12-1+deb10u2+tuxcare.els1">
          <filename>gnupg2_2.2.12-1+deb10u2+tuxcare.els1_all.deb</filename>
          <sum type="sha">37f3a078b65914147d46776e30e504cd38634869</sum>
        </package>
        <package arch="amd64" name="gpg" version="2.2.12-1+deb10u2+tuxcare.els1">
          <filename>gpg_2.2.12-1+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">d06c5984c1e399cb75c879490d12abcb40a7d479</sum>
        </package>
        <package arch="amd64" name="gpg-agent" version="2.2.12-1+deb10u2+tuxcare.els1">
          <filename>gpg-agent_2.2.12-1+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">8a62ece0f16979f0b44f0cf4a608970bf67c5c29</sum>
        </package>
        <package arch="amd64" name="gpg-wks-client" version="2.2.12-1+deb10u2+tuxcare.els1">
          <filename>gpg-wks-client_2.2.12-1+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">06036914067dcf2b77a8d55526c238dc63db1639</sum>
        </package>
        <package arch="amd64" name="gpg-wks-server" version="2.2.12-1+deb10u2+tuxcare.els1">
          <filename>gpg-wks-server_2.2.12-1+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">62908330a05856037ae13968ff2e886ac5ea6c07</sum>
        </package>
        <package arch="amd64" name="gpgconf" version="2.2.12-1+deb10u2+tuxcare.els1">
          <filename>gpgconf_2.2.12-1+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">b3c9831abc9fd00194cd430afdb9854c957c5470</sum>
        </package>
        <package arch="amd64" name="gpgsm" version="2.2.12-1+deb10u2+tuxcare.els1">
          <filename>gpgsm_2.2.12-1+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">e9a4380c421b566669f5cb56cde85e527e7fe23d</sum>
        </package>
        <package arch="amd64" name="gpgv" version="2.2.12-1+deb10u2+tuxcare.els1">
          <filename>gpgv_2.2.12-1+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">a3eab44079db215162c5125b7df9616ab88873fd</sum>
        </package>
        <package arch="amd64" name="gpgv-static" version="2.2.12-1+deb10u2+tuxcare.els1">
          <filename>gpgv-static_2.2.12-1+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">e29eac9869f00fd5d3fa48896cf2f15db69a0ca0</sum>
        </package>
        <package arch="all" name="gpgv-win32" version="2.2.12-1+deb10u2+tuxcare.els1">
          <filename>gpgv-win32_2.2.12-1+deb10u2+tuxcare.els1_all.deb</filename>
          <sum type="sha">366253367800bde0445eb219baaeecb132353734</sum>
        </package>
        <package arch="all" name="gpgv2" version="2.2.12-1+deb10u2+tuxcare.els1">
          <filename>gpgv2_2.2.12-1+deb10u2+tuxcare.els1_all.deb</filename>
          <sum type="sha">f1a7ac83b61133b2b366b059b8284306ec6b7136</sum>
        </package>
        <package arch="amd64" name="scdaemon" version="2.2.12-1+deb10u2+tuxcare.els1">
          <filename>scdaemon_2.2.12-1+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">1c83962721f9b1d72cfe0fdd2c061f45519770b8</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1770707507</id>
    <title>Fix CVE(s): CVE-2026-24515</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Make XML_ExternalEntityParserCreate copy unknown encoding  handler user data
     - debian/patches/CVE-2026-24515.patch: copy unknown encoding
       handler user data and add tests to cover effect
     - CVE-2026-24515</description>
    <severity>Low</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Make XML_ExternalEntityParserCreate copy unknown encoding  handler user data
     - debian/patches/CVE-2026-24515.patch: copy unknown encoding
       handler user data and add tests to cover effect
     - CVE-2026-24515</summary>
    <pushcount>0</pushcount>
    <issued date="2026-02-10 07:11:52 UTC" />
    <updated date="2026-02-10 07:11:52 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1770707507.html" id="CLSA-2026:1770707507" title="CLSA-2026:1770707507" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="expat" version="2.2.6-2+deb10u7+tuxcare.els2">
          <filename>expat_2.2.6-2+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">fe01a9b5a94d6ae9349e3604e7ac6f9e3e3bfa66</sum>
        </package>
        <package arch="amd64" name="libexpat1" version="2.2.6-2+deb10u7+tuxcare.els2">
          <filename>libexpat1_2.2.6-2+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">02b1da5b11ab82da85f026a267445ec3fb6f3fea</sum>
        </package>
        <package arch="amd64" name="libexpat1-dev" version="2.2.6-2+deb10u7+tuxcare.els2">
          <filename>libexpat1-dev_2.2.6-2+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">978ca1d77c8b328af12ca9c642ccb4a6a4c96f03</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1770717529</id>
    <title>Fix CVE(s): CVE-2025-69421</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: check oct argument for NULL in PKCS12_item_decrypt_d2i_e()
     - debian/patches/CVE-2025-69421.patch: fix a NULL pointer dereference
       in the PKCS12_item_decrypt_d2i_ex() function.
     - CVE-2025-69421</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: check oct argument for NULL in PKCS12_item_decrypt_d2i_e()
     - debian/patches/CVE-2025-69421.patch: fix a NULL pointer dereference
       in the PKCS12_item_decrypt_d2i_ex() function.
     - CVE-2025-69421</summary>
    <pushcount>0</pushcount>
    <issued date="2026-02-10 09:58:53 UTC" />
    <updated date="2026-02-10 09:58:53 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1770717529.html" id="CLSA-2026:1770717529" title="CLSA-2026:1770717529" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libssl-dev" version="1.1.1n-0+deb10u6+tuxcare.els1">
          <filename>libssl-dev_1.1.1n-0+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">1c5e572a0891b467b09686654306e94057115fc1</sum>
        </package>
        <package arch="all" name="libssl-doc" version="1.1.1n-0+deb10u6+tuxcare.els1">
          <filename>libssl-doc_1.1.1n-0+deb10u6+tuxcare.els1_all.deb</filename>
          <sum type="sha">c60f726831020fc51c91a8abff9deaa17ef89980</sum>
        </package>
        <package arch="amd64" name="libssl1.1" version="1.1.1n-0+deb10u6+tuxcare.els1">
          <filename>libssl1.1_1.1.1n-0+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">37f176170462b471d7eceb4dc5c2ced6efe4283e</sum>
        </package>
        <package arch="amd64" name="openssl" version="1.1.1n-0+deb10u6+tuxcare.els1">
          <filename>openssl_1.1.1n-0+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">3235b017eea076f98c451692dac60874c96b2a80</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1771237525</id>
    <title>Fix CVE(s): CVE-2025-69419</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: check return code of UTF8_putc
     - debian/patches/CVE-2025-69419.patch: add missing return code checks
       for UTF8_putc in a_strex.c and OPENSSL_uni2utf8 in p12_utl.c.
     - CVE-2025-69419</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: check return code of UTF8_putc
     - debian/patches/CVE-2025-69419.patch: add missing return code checks
       for UTF8_putc in a_strex.c and OPENSSL_uni2utf8 in p12_utl.c.
     - CVE-2025-69419</summary>
    <pushcount>0</pushcount>
    <issued date="2026-02-16 10:25:29 UTC" />
    <updated date="2026-02-16 10:25:29 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1771237525.html" id="CLSA-2026:1771237525" title="CLSA-2026:1771237525" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libssl-dev" version="1.1.1n-0+deb10u6+tuxcare.els2">
          <filename>libssl-dev_1.1.1n-0+deb10u6+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">7af3393f69294912972538f042d3533ea649f0a2</sum>
        </package>
        <package arch="all" name="libssl-doc" version="1.1.1n-0+deb10u6+tuxcare.els2">
          <filename>libssl-doc_1.1.1n-0+deb10u6+tuxcare.els2_all.deb</filename>
          <sum type="sha">d64c4dc722b55e7341b397a3e3682ec5f5d4c380</sum>
        </package>
        <package arch="amd64" name="libssl1.1" version="1.1.1n-0+deb10u6+tuxcare.els2">
          <filename>libssl1.1_1.1.1n-0+deb10u6+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">f6050967ccbf26cebcbf604cbbd9cf70bd3e3db2</sum>
        </package>
        <package arch="amd64" name="openssl" version="1.1.1n-0+deb10u6+tuxcare.els2">
          <filename>openssl_1.1.1n-0+deb10u6+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">52c7e59894c504260e553a1a98c70959fb48c59b</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1771857466</id>
    <title>Fix CVE(s): CVE-2025-14087</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Buffer underflow / integer overflow in GVariant text
     format parser
     - debian/patches/CVE-2025-14087.patch: fix potential integer overflow
       parsing strings, bytestrings, and child element counts in
       gvariant-parser.c
     - CVE-2025-14087</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Buffer underflow / integer overflow in GVariant text
     format parser
     - debian/patches/CVE-2025-14087.patch: fix potential integer overflow
       parsing strings, bytestrings, and child element counts in
       gvariant-parser.c
     - CVE-2025-14087</summary>
    <pushcount>0</pushcount>
    <issued date="2026-02-23 14:37:50 UTC" />
    <updated date="2026-02-23 14:37:50 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1771857466.html" id="CLSA-2026:1771857466" title="CLSA-2026:1771857466" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libglib2.0-0" version="2.58.3-2+deb10u6+tuxcare.els2">
          <filename>libglib2.0-0_2.58.3-2+deb10u6+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">55f900b3d956134ec6f0234fb76e4b8fdc89adb3</sum>
        </package>
        <package arch="amd64" name="libglib2.0-bin" version="2.58.3-2+deb10u6+tuxcare.els2">
          <filename>libglib2.0-bin_2.58.3-2+deb10u6+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">517c3cd3499d5472d733828c68668be257467f92</sum>
        </package>
        <package arch="all" name="libglib2.0-data" version="2.58.3-2+deb10u6+tuxcare.els2">
          <filename>libglib2.0-data_2.58.3-2+deb10u6+tuxcare.els2_all.deb</filename>
          <sum type="sha">70ff4fa0b8129bf87739e4865cf018d7227f8018</sum>
        </package>
        <package arch="amd64" name="libglib2.0-dev" version="2.58.3-2+deb10u6+tuxcare.els2">
          <filename>libglib2.0-dev_2.58.3-2+deb10u6+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">ec528152e575b0345314e3b50d3fcdd6a146a4fb</sum>
        </package>
        <package arch="amd64" name="libglib2.0-dev-bin" version="2.58.3-2+deb10u6+tuxcare.els2">
          <filename>libglib2.0-dev-bin_2.58.3-2+deb10u6+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">d9d993f9fade496168daa27d3d34d51e9afb23e2</sum>
        </package>
        <package arch="all" name="libglib2.0-doc" version="2.58.3-2+deb10u6+tuxcare.els2">
          <filename>libglib2.0-doc_2.58.3-2+deb10u6+tuxcare.els2_all.deb</filename>
          <sum type="sha">bb84cb5d5ca1a72ebea91cad80ee6700aee2c617</sum>
        </package>
        <package arch="amd64" name="libglib2.0-tests" version="2.58.3-2+deb10u6+tuxcare.els2">
          <filename>libglib2.0-tests_2.58.3-2+deb10u6+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">4e00a53f5b2a01064240abfa8a6d637c79958669</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1772443907</id>
    <title>Fix CVE(s): CVE-2025-14524</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: bearer token leakage to IMAP/LDAP/POP3/SMTP hosts via
     cross-protocol redirects
     - debian/patches/CVE-2025-14524.patch: Require permission when redirected
       for bearer use and prevent sending bearer token to other hosts; fix
       unconditional reuse of oauth bearer during redirects.
     - CVE-2025-14524</description>
    <severity>Low</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: bearer token leakage to IMAP/LDAP/POP3/SMTP hosts via
     cross-protocol redirects
     - debian/patches/CVE-2025-14524.patch: Require permission when redirected
       for bearer use and prevent sending bearer token to other hosts; fix
       unconditional reuse of oauth bearer during redirects.
     - CVE-2025-14524</summary>
    <pushcount>0</pushcount>
    <issued date="2026-03-02 09:31:51 UTC" />
    <updated date="2026-03-02 09:31:51 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1772443907.html" id="CLSA-2026:1772443907" title="CLSA-2026:1772443907" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="curl" version="7.64.0-4+deb10u9+tuxcare.els1">
          <filename>curl_7.64.0-4+deb10u9+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">0a2c933d802e76ba0b6c4af1f375f2bc6e4ca358</sum>
        </package>
        <package arch="amd64" name="libcurl3-gnutls" version="7.64.0-4+deb10u9+tuxcare.els1">
          <filename>libcurl3-gnutls_7.64.0-4+deb10u9+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">bac9bfd6822852691801680c7c0cab0846ef3b86</sum>
        </package>
        <package arch="amd64" name="libcurl3-nss" version="7.64.0-4+deb10u9+tuxcare.els1">
          <filename>libcurl3-nss_7.64.0-4+deb10u9+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">98ef3e68f569654b4322fe4cd93bb2caaa91420b</sum>
        </package>
        <package arch="amd64" name="libcurl4" version="7.64.0-4+deb10u9+tuxcare.els1">
          <filename>libcurl4_7.64.0-4+deb10u9+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">7e4b5c5e05056649ef8cac09b25730ddfebc11ab</sum>
        </package>
        <package arch="all" name="libcurl4-doc" version="7.64.0-4+deb10u9+tuxcare.els1">
          <filename>libcurl4-doc_7.64.0-4+deb10u9+tuxcare.els1_all.deb</filename>
          <sum type="sha">fb3b130b036e80829dab59b7bd9a81c26244bb31</sum>
        </package>
        <package arch="amd64" name="libcurl4-gnutls-dev" version="7.64.0-4+deb10u9+tuxcare.els1">
          <filename>libcurl4-gnutls-dev_7.64.0-4+deb10u9+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">96784fd51d7f7b2842b5c1827c107a3f45e88496</sum>
        </package>
        <package arch="amd64" name="libcurl4-nss-dev" version="7.64.0-4+deb10u9+tuxcare.els1">
          <filename>libcurl4-nss-dev_7.64.0-4+deb10u9+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">912f34a5444d06189d8d521ec9a346ab1777208d</sum>
        </package>
        <package arch="amd64" name="libcurl4-openssl-dev" version="7.64.0-4+deb10u9+tuxcare.els1">
          <filename>libcurl4-openssl-dev_7.64.0-4+deb10u9+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">99a93620602bd6c75cab8be60c0ee99cf2919223</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1773141936</id>
    <title>Fix CVE(s): CVE-2026-26269</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Stack-Based buffer overflow in Netbeans
     - debian/patches/CVE-2026-26269.patch: fix stack-based buffer overflow in
       NetBeans integration that could lead to a crash or arbitrary code execution
       via a malicious server
     - CVE-2026-26269</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Stack-Based buffer overflow in Netbeans
     - debian/patches/CVE-2026-26269.patch: fix stack-based buffer overflow in
       NetBeans integration that could lead to a crash or arbitrary code execution
       via a malicious server
     - CVE-2026-26269</summary>
    <pushcount>0</pushcount>
    <issued date="2026-03-10 11:25:41 UTC" />
    <updated date="2026-03-10 11:25:41 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1773141936.html" id="CLSA-2026:1773141936" title="CLSA-2026:1773141936" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="vim" version="2:8.1.0875-5+deb10u6+tuxcare.els15">
          <filename>vim_8.1.0875-5+deb10u6+tuxcare.els15_amd64.deb</filename>
          <sum type="sha">abc45121bb12ec6530361653eb685533033303f5</sum>
        </package>
        <package arch="amd64" name="vim-athena" version="2:8.1.0875-5+deb10u6+tuxcare.els15">
          <filename>vim-athena_8.1.0875-5+deb10u6+tuxcare.els15_amd64.deb</filename>
          <sum type="sha">08fca655f7035e74a035002b74864f5cef7c6b25</sum>
        </package>
        <package arch="all" name="vim-common" version="2:8.1.0875-5+deb10u6+tuxcare.els15">
          <filename>vim-common_8.1.0875-5+deb10u6+tuxcare.els15_all.deb</filename>
          <sum type="sha">f3041c01a10a2dd744b5cec89c40f240cac929e1</sum>
        </package>
        <package arch="all" name="vim-doc" version="2:8.1.0875-5+deb10u6+tuxcare.els15">
          <filename>vim-doc_8.1.0875-5+deb10u6+tuxcare.els15_all.deb</filename>
          <sum type="sha">f559d7be92af9714b978577a51980c486c497c2d</sum>
        </package>
        <package arch="amd64" name="vim-gtk" version="2:8.1.0875-5+deb10u6+tuxcare.els15">
          <filename>vim-gtk_8.1.0875-5+deb10u6+tuxcare.els15_amd64.deb</filename>
          <sum type="sha">dc7551f3f2c5472260291453227925ce16d6cc1c</sum>
        </package>
        <package arch="amd64" name="vim-gtk3" version="2:8.1.0875-5+deb10u6+tuxcare.els15">
          <filename>vim-gtk3_8.1.0875-5+deb10u6+tuxcare.els15_amd64.deb</filename>
          <sum type="sha">e378abf44a2d17393fa54e4478bdee2a3504cefc</sum>
        </package>
        <package arch="all" name="vim-gui-common" version="2:8.1.0875-5+deb10u6+tuxcare.els15">
          <filename>vim-gui-common_8.1.0875-5+deb10u6+tuxcare.els15_all.deb</filename>
          <sum type="sha">dba57900bbdcc6d73652c35571850c0453f92653</sum>
        </package>
        <package arch="amd64" name="vim-nox" version="2:8.1.0875-5+deb10u6+tuxcare.els15">
          <filename>vim-nox_8.1.0875-5+deb10u6+tuxcare.els15_amd64.deb</filename>
          <sum type="sha">d8ab148d74999694f58f5e2ce73d93428d78fbe3</sum>
        </package>
        <package arch="all" name="vim-runtime" version="2:8.1.0875-5+deb10u6+tuxcare.els15">
          <filename>vim-runtime_8.1.0875-5+deb10u6+tuxcare.els15_all.deb</filename>
          <sum type="sha">934db2259bb0fed5c5d8eec6c76e35c3654fcec8</sum>
        </package>
        <package arch="amd64" name="vim-tiny" version="2:8.1.0875-5+deb10u6+tuxcare.els15">
          <filename>vim-tiny_8.1.0875-5+deb10u6+tuxcare.els15_amd64.deb</filename>
          <sum type="sha">9485549ea1dc81bb095a5e398c579462ecbdf3e9</sum>
        </package>
        <package arch="amd64" name="xxd" version="2:8.1.0875-5+deb10u6+tuxcare.els15">
          <filename>xxd_8.1.0875-5+deb10u6+tuxcare.els15_amd64.deb</filename>
          <sum type="sha">b95ae425d80578522050da441a109b9d96a9955c</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1773145958</id>
    <title>Fix CVE(s): CVE-2024-37370, CVE-2024-37371</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Fix vulnerabilities in GSS message token handling
     - debian/patches/CVE-2024-37370-CVE-2024-37371.patch: Verify Extra
       Count field in CFX wrap tokens, validate plaintext length in
       gss_unwrap, and prevent IOV unwrap header buffer overrun
     - CVE-2024-37370
     - CVE-2024-37371</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Fix vulnerabilities in GSS message token handling
     - debian/patches/CVE-2024-37370-CVE-2024-37371.patch: Verify Extra
       Count field in CFX wrap tokens, validate plaintext length in
       gss_unwrap, and prevent IOV unwrap header buffer overrun
     - CVE-2024-37370
     - CVE-2024-37371</summary>
    <pushcount>0</pushcount>
    <issued date="2026-03-10 12:32:43 UTC" />
    <updated date="2026-03-10 12:32:43 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1773145958.html" id="CLSA-2026:1773145958" title="CLSA-2026:1773145958" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="krb5-admin-server" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>krb5-admin-server_1.17-3+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">2e6559065a21cbbff6f46fd7da95ecba1a63c08f</sum>
        </package>
        <package arch="all" name="krb5-doc" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>krb5-doc_1.17-3+deb10u6+tuxcare.els1_all.deb</filename>
          <sum type="sha">698695fed118f914fa9ff9144ef27071bc42b31d</sum>
        </package>
        <package arch="amd64" name="krb5-gss-samples" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>krb5-gss-samples_1.17-3+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">d6adba1f9e6485d6a2db0ca848ccc706f3d0a8e1</sum>
        </package>
        <package arch="amd64" name="krb5-k5tls" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>krb5-k5tls_1.17-3+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">6e0e52f461ba4a23631685d30ce22023c1ec4ca0</sum>
        </package>
        <package arch="amd64" name="krb5-kdc" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>krb5-kdc_1.17-3+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">41233ea900afdf4b98af51bcaa442aee412f4b4c</sum>
        </package>
        <package arch="amd64" name="krb5-kdc-ldap" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>krb5-kdc-ldap_1.17-3+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">540b8b85450fbb198393c595169e3cc6e629de8f</sum>
        </package>
        <package arch="amd64" name="krb5-kpropd" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>krb5-kpropd_1.17-3+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">e1e3b3e0755cee67f9be44dcf066304d9144a97b</sum>
        </package>
        <package arch="all" name="krb5-locales" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>krb5-locales_1.17-3+deb10u6+tuxcare.els1_all.deb</filename>
          <sum type="sha">6041dbfc369aaa3c8dd67f5faaf11f4414d01290</sum>
        </package>
        <package arch="amd64" name="krb5-multidev" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>krb5-multidev_1.17-3+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">68cdf064b11df5ab3e5d095bd948eb91f563958f</sum>
        </package>
        <package arch="amd64" name="krb5-otp" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>krb5-otp_1.17-3+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">8721b5b02d468baad8cecb7663907c1a46a5cd71</sum>
        </package>
        <package arch="amd64" name="krb5-pkinit" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>krb5-pkinit_1.17-3+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">fdb331721bd010b882619a969aaf3256186ee918</sum>
        </package>
        <package arch="amd64" name="krb5-user" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>krb5-user_1.17-3+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">caceb36b87f2d7c70f3295b5c9cbac4f5a5c8ddd</sum>
        </package>
        <package arch="amd64" name="libgssapi-krb5-2" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>libgssapi-krb5-2_1.17-3+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">35663b5cade74614507f1dc0d7dfba08d7145d4b</sum>
        </package>
        <package arch="amd64" name="libgssrpc4" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>libgssrpc4_1.17-3+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">d9266cb49260465cded3b3f02a988a4a35920d6c</sum>
        </package>
        <package arch="amd64" name="libk5crypto3" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>libk5crypto3_1.17-3+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">1a2c0024632f3af0fb19d51cbacae74030bcda3b</sum>
        </package>
        <package arch="amd64" name="libkadm5clnt-mit11" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>libkadm5clnt-mit11_1.17-3+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">6f40a6fab8bb4daa351ea5e77de5911c9bce865c</sum>
        </package>
        <package arch="amd64" name="libkadm5srv-mit11" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>libkadm5srv-mit11_1.17-3+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">34c6f62081e403f82b9dcf33b45be8c232341316</sum>
        </package>
        <package arch="amd64" name="libkdb5-9" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>libkdb5-9_1.17-3+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">07fa1125543b019f96baf6e16e068ccaaa92b088</sum>
        </package>
        <package arch="amd64" name="libkrad-dev" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>libkrad-dev_1.17-3+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">263dcff0a3c8f21c7d29d6ea3cc0d845cb14672f</sum>
        </package>
        <package arch="amd64" name="libkrad0" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>libkrad0_1.17-3+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">c6c57482423708d2725547a24b3a24371e385108</sum>
        </package>
        <package arch="amd64" name="libkrb5-3" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>libkrb5-3_1.17-3+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">baa5dbc26f1905ea8eb7841ebaba28eadb6e93cb</sum>
        </package>
        <package arch="amd64" name="libkrb5-dev" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>libkrb5-dev_1.17-3+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">42c6f552fece32cd502a46deed68d7f09bcc9fc8</sum>
        </package>
        <package arch="amd64" name="libkrb5support0" version="1.17-3+deb10u6+tuxcare.els1">
          <filename>libkrb5support0_1.17-3+deb10u6+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">fa1232660e9193d792702ab3e0ed754136f713bf</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1773161124</id>
    <title>Fix CVE(s): CVE-2021-22876, CVE-2025-15079</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: acceptance of hosts not listed in specified known_hosts
     file during SSH-based transfers
     - debian/patches/CVE-2025-15079.patch: Set both knownhosts options to same
       file and fix surprises caused by libssh exposing separate KNOWNHOSTS and
       GLOBAL_KNOWNHOSTS options.
     - CVE-2025-15079
   * Regenerate Server-localhost-lastSAN-sv test certificate with SHA-256
     - debian/patches/regenerate-lastSAN-cert-sha256.patch: Fix "ca md too weak"
       error with OpenSSL 1.1.1+ by replacing SHA-1 signed certificate with
       SHA-256. Also fixes Makefile.am bug for lastSAN target.
   * Update failed test
     - debian/patches/26_CVE-2021-22876.patch: Update test to avoid using
       unsupported commands
   * Update failed test
     - debian/patches/fix-test323-errorcode.patch: two valid error codes now
   * Disable some tests
     - debian/rules: add option to disable tests marked as flaky, fail the
       build if any test fails
     - debian/patches/add-flaky-to-test1592.patch: mark test1592 as flaky
     - debian/patches/disable-nss-failing-tests.patch: libnsspem.so is not
       available on Debian 10
   * Remove unsupported test:
     - debian/patches/test8-verify-that-ctrl-byte-cookies-are-ignored.patch:
       no ctrl-byte-cookies are supported</description>
    <severity>Low</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: acceptance of hosts not listed in specified known_hosts
     file during SSH-based transfers
     - debian/patches/CVE-2025-15079.patch: Set both knownhosts options to same
       file and fix surprises caused by libssh exposing separate KNOWNHOSTS and
       GLOBAL_KNOWNHOSTS options.
     - CVE-2025-15079
   * Regenerate Server-localhost-lastSAN-sv test certificate with SHA-256
     - debian/patches/regenerate-lastSAN-cert-sha256.patch: Fix "ca md too weak"
       error with OpenSSL 1.1.1+ by replacing SHA-1 signed certificate with
       SHA-256. Also fixes Makefile.am bug for lastSAN target.
   * Update failed test
     - debian/patches/26_CVE-2021-22876.patch: Update test to avoid using
       unsupported commands
   * Update failed test
     - debian/patches/fix-test323-errorcode.patch: two valid error codes now
   * Disable some tests
     - debian/rules: add option to disable tests marked as flaky, fail the
       build if any test fails
     - debian/patches/add-flaky-to-test1592.patch: mark test1592 as flaky
     - debian/patches/disable-nss-failing-tests.patch: libnsspem.so is not
       available on Debian 10
   * Remove unsupported test:
     - debian/patches/test8-verify-that-ctrl-byte-cookies-are-ignored.patch:
       no ctrl-byte-cookies are supported</summary>
    <pushcount>0</pushcount>
    <issued date="2026-03-10 16:45:29 UTC" />
    <updated date="2026-03-10 16:45:29 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1773161124.html" id="CLSA-2026:1773161124" title="CLSA-2026:1773161124" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="curl" version="7.64.0-4+deb10u9+tuxcare.els2">
          <filename>curl_7.64.0-4+deb10u9+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">89851431a7d5b5a442403649d2976f1e7d002373</sum>
        </package>
        <package arch="amd64" name="libcurl3-gnutls" version="7.64.0-4+deb10u9+tuxcare.els2">
          <filename>libcurl3-gnutls_7.64.0-4+deb10u9+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">8cefbd9cd4ec628b2d29251391d6d07221b6d101</sum>
        </package>
        <package arch="amd64" name="libcurl3-nss" version="7.64.0-4+deb10u9+tuxcare.els2">
          <filename>libcurl3-nss_7.64.0-4+deb10u9+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">d7945a7065efdf890c72280f3c15d03d4dcffd95</sum>
        </package>
        <package arch="amd64" name="libcurl4" version="7.64.0-4+deb10u9+tuxcare.els2">
          <filename>libcurl4_7.64.0-4+deb10u9+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">6949ad359e25dbce4975d35e2614950b785e1810</sum>
        </package>
        <package arch="all" name="libcurl4-doc" version="7.64.0-4+deb10u9+tuxcare.els2">
          <filename>libcurl4-doc_7.64.0-4+deb10u9+tuxcare.els2_all.deb</filename>
          <sum type="sha">84b3c7382e52bdf7b4238fcebd34e72b6c2edda5</sum>
        </package>
        <package arch="amd64" name="libcurl4-gnutls-dev" version="7.64.0-4+deb10u9+tuxcare.els2">
          <filename>libcurl4-gnutls-dev_7.64.0-4+deb10u9+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">500de9ca945078b0fddf08a1cf4b6d8f1265ed9b</sum>
        </package>
        <package arch="amd64" name="libcurl4-nss-dev" version="7.64.0-4+deb10u9+tuxcare.els2">
          <filename>libcurl4-nss-dev_7.64.0-4+deb10u9+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">1facfd0b0c276b9fa5b6f75eec5ff4a04de262a7</sum>
        </package>
        <package arch="amd64" name="libcurl4-openssl-dev" version="7.64.0-4+deb10u9+tuxcare.els2">
          <filename>libcurl4-openssl-dev_7.64.0-4+deb10u9+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">e0a7ed926796b4bee43de390ebbe3351458c0bc7</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1774260216</id>
    <title>Fix CVE(s): CVE-2026-1965, CVE-2026-3783, CVE-2026-3784</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: reuse of connections using HTTP Negotiate
     - debian/patches/CVE-2026-1965.patch: fix reuse of connections using
       HTTP Negotiate and fix copy and paste url_match_auth_nego mistake.
     - CVE-2026-1965
   * Bearer token sent without checking auth is allowed
     - debian/patches/CVE-2026-3783.patch: only send bearer if auth is
       allowed.
     - CVE-2026-3783
   * Proxy credential reuse across different credentials
     - debian/patches/CVE-2026-3784.patch: compare proxy credentials in
       proxy_info_matches to prevent connection reuse with wrong auth.
     - CVE-2026-3784</description>
    <severity>Moderate</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: reuse of connections using HTTP Negotiate
     - debian/patches/CVE-2026-1965.patch: fix reuse of connections using
       HTTP Negotiate and fix copy and paste url_match_auth_nego mistake.
     - CVE-2026-1965
   * Bearer token sent without checking auth is allowed
     - debian/patches/CVE-2026-3783.patch: only send bearer if auth is
       allowed.
     - CVE-2026-3783
   * Proxy credential reuse across different credentials
     - debian/patches/CVE-2026-3784.patch: compare proxy credentials in
       proxy_info_matches to prevent connection reuse with wrong auth.
     - CVE-2026-3784</summary>
    <pushcount>0</pushcount>
    <issued date="2026-03-23 10:03:44 UTC" />
    <updated date="2026-03-23 10:03:44 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1774260216.html" id="CLSA-2026:1774260216" title="CLSA-2026:1774260216" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="curl" version="7.64.0-4+deb10u9+tuxcare.els3">
          <filename>curl_7.64.0-4+deb10u9+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">97c75240669e95d5c51397a76d3e6c94446cb506</sum>
        </package>
        <package arch="amd64" name="libcurl3-gnutls" version="7.64.0-4+deb10u9+tuxcare.els3">
          <filename>libcurl3-gnutls_7.64.0-4+deb10u9+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">480f4c99d18b018ccae7546164152c4167a7b02c</sum>
        </package>
        <package arch="amd64" name="libcurl3-nss" version="7.64.0-4+deb10u9+tuxcare.els3">
          <filename>libcurl3-nss_7.64.0-4+deb10u9+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">65f8c5835c5ae77542093f1641d180a1c1edf650</sum>
        </package>
        <package arch="amd64" name="libcurl4" version="7.64.0-4+deb10u9+tuxcare.els3">
          <filename>libcurl4_7.64.0-4+deb10u9+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">908a61c5f54078a4905f70aaf1627064de4905fc</sum>
        </package>
        <package arch="all" name="libcurl4-doc" version="7.64.0-4+deb10u9+tuxcare.els3">
          <filename>libcurl4-doc_7.64.0-4+deb10u9+tuxcare.els3_all.deb</filename>
          <sum type="sha">d6df046b2689cef25595212e1fadfde9a5a3d519</sum>
        </package>
        <package arch="amd64" name="libcurl4-gnutls-dev" version="7.64.0-4+deb10u9+tuxcare.els3">
          <filename>libcurl4-gnutls-dev_7.64.0-4+deb10u9+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">65c397f3bed0fafae637fd0c486770817ce0102a</sum>
        </package>
        <package arch="amd64" name="libcurl4-nss-dev" version="7.64.0-4+deb10u9+tuxcare.els3">
          <filename>libcurl4-nss-dev_7.64.0-4+deb10u9+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">1f9a0532ca196e0e6eb7e09fdee0f7333b4d2172</sum>
        </package>
        <package arch="amd64" name="libcurl4-openssl-dev" version="7.64.0-4+deb10u9+tuxcare.els3">
          <filename>libcurl4-openssl-dev_7.64.0-4+deb10u9+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">c37f1956b8bf623c4b9110ebc2876562e523bfd2</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1774283473</id>
    <title>Fix CVE(s): CVE-2026-25210</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Improve determination of buffer size bufSize in
   function doContent
     - debian/patches/CVE-2026-25210.patch: fix integer overflow in
       doContent tag buffer reallocation
     - CVE-2026-25210</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Improve determination of buffer size bufSize in
   function doContent
     - debian/patches/CVE-2026-25210.patch: fix integer overflow in
       doContent tag buffer reallocation
     - CVE-2026-25210</summary>
    <pushcount>0</pushcount>
    <issued date="2026-03-23 16:31:18 UTC" />
    <updated date="2026-03-23 16:31:18 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1774283473.html" id="CLSA-2026:1774283473" title="CLSA-2026:1774283473" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="expat" version="2.2.6-2+deb10u7+tuxcare.els3">
          <filename>expat_2.2.6-2+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">122f93bc2cf48ef64bf764d282ff39fbbd3febdb</sum>
        </package>
        <package arch="amd64" name="libexpat1" version="2.2.6-2+deb10u7+tuxcare.els3">
          <filename>libexpat1_2.2.6-2+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">0168f309b34e4a8fdab1a1b2f1d8a5f31786036c</sum>
        </package>
        <package arch="amd64" name="libexpat1-dev" version="2.2.6-2+deb10u7+tuxcare.els3">
          <filename>libexpat1-dev_2.2.6-2+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">61ac939da0cba1ad6361fe9ed6f1922add4e06c3</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1774426919</id>
    <title>Fix CVE(s): CVE-2025-66614</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: SNI hostname not stored for NIO2 and APR connectors
     - debian/patches/CVE-2025-66614.patch: store SNI hostname for NIO2 and
       APR connections so that SNI checks are not bypassed
     - CVE-2025-66614</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: SNI hostname not stored for NIO2 and APR connectors
     - debian/patches/CVE-2025-66614.patch: store SNI hostname for NIO2 and
       APR connections so that SNI checks are not bypassed
     - CVE-2025-66614</summary>
    <pushcount>0</pushcount>
    <issued date="2026-03-25 08:22:04 UTC" />
    <updated date="2026-03-25 08:22:04 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1774426919.html" id="CLSA-2026:1774426919" title="CLSA-2026:1774426919" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="all" name="libtomcat9-embed-java" version="9.0.31-1~deb10u12+tuxcare.els4">
          <filename>libtomcat9-embed-java_9.0.31-1~deb10u12+tuxcare.els4_all.deb</filename>
          <sum type="sha">9c69548e267d3e151122ec3b278c3e97dcdd4539</sum>
        </package>
        <package arch="all" name="libtomcat9-java" version="9.0.31-1~deb10u12+tuxcare.els4">
          <filename>libtomcat9-java_9.0.31-1~deb10u12+tuxcare.els4_all.deb</filename>
          <sum type="sha">ffa0ccd4daea3521924240120e55ff46316a3071</sum>
        </package>
        <package arch="all" name="tomcat9" version="9.0.31-1~deb10u12+tuxcare.els4">
          <filename>tomcat9_9.0.31-1~deb10u12+tuxcare.els4_all.deb</filename>
          <sum type="sha">8d9301a6a36d2009a9dffb48baeca9635316f693</sum>
        </package>
        <package arch="all" name="tomcat9-admin" version="9.0.31-1~deb10u12+tuxcare.els4">
          <filename>tomcat9-admin_9.0.31-1~deb10u12+tuxcare.els4_all.deb</filename>
          <sum type="sha">5b47f54f3c896b3d625e07e94437fa1a6e1cb01e</sum>
        </package>
        <package arch="all" name="tomcat9-common" version="9.0.31-1~deb10u12+tuxcare.els4">
          <filename>tomcat9-common_9.0.31-1~deb10u12+tuxcare.els4_all.deb</filename>
          <sum type="sha">4751bbaaa2386dd977d668a977d6ea378e7db9f0</sum>
        </package>
        <package arch="all" name="tomcat9-docs" version="9.0.31-1~deb10u12+tuxcare.els4">
          <filename>tomcat9-docs_9.0.31-1~deb10u12+tuxcare.els4_all.deb</filename>
          <sum type="sha">79fdc8f6a238edc1b67b7cddf5bb173fa6c57399</sum>
        </package>
        <package arch="all" name="tomcat9-examples" version="9.0.31-1~deb10u12+tuxcare.els4">
          <filename>tomcat9-examples_9.0.31-1~deb10u12+tuxcare.els4_all.deb</filename>
          <sum type="sha">840388ba182195ff827b2fe525046162cbd869c7</sum>
        </package>
        <package arch="all" name="tomcat9-user" version="9.0.31-1~deb10u12+tuxcare.els4">
          <filename>tomcat9-user_9.0.31-1~deb10u12+tuxcare.els4_all.deb</filename>
          <sum type="sha">b9ad502bc1572491f7c2816d4c2d3b691216ba9a</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1774526052</id>
    <title>Fix CVE(s): CVE-2026-28417, CVE-2026-28421</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Crash when recovering a corrupted swap file
     - debian/patches/CVE-2026-28421.patch: add bounds checks in swap file
       recovery to prevent heap-buffer-overflow and SEGV from crafted swap files
     - CVE-2026-28421
   * SECURITY UPDATE: Command injection via crafted netrw URIs
     - debian/patches/CVE-2026-28417.patch: fix command injection in netrw
       via crafted scp:// URIs by adding strict hostname validation and
       shellescape()
     - CVE-2026-28417</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Crash when recovering a corrupted swap file
     - debian/patches/CVE-2026-28421.patch: add bounds checks in swap file
       recovery to prevent heap-buffer-overflow and SEGV from crafted swap files
     - CVE-2026-28421
   * SECURITY UPDATE: Command injection via crafted netrw URIs
     - debian/patches/CVE-2026-28417.patch: fix command injection in netrw
       via crafted scp:// URIs by adding strict hostname validation and
       shellescape()
     - CVE-2026-28417</summary>
    <pushcount>0</pushcount>
    <issued date="2026-03-26 11:54:17 UTC" />
    <updated date="2026-03-26 11:54:17 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1774526052.html" id="CLSA-2026:1774526052" title="CLSA-2026:1774526052" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="vim" version="2:8.1.0875-5+deb10u6+tuxcare.els16">
          <filename>vim_8.1.0875-5+deb10u6+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">e288e204fa1e269dbf7abcf090ed5d9bcdec30f0</sum>
        </package>
        <package arch="amd64" name="vim-athena" version="2:8.1.0875-5+deb10u6+tuxcare.els16">
          <filename>vim-athena_8.1.0875-5+deb10u6+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">656267ab7270fa293a8b3f97a4f03483a6218de6</sum>
        </package>
        <package arch="all" name="vim-common" version="2:8.1.0875-5+deb10u6+tuxcare.els16">
          <filename>vim-common_8.1.0875-5+deb10u6+tuxcare.els16_all.deb</filename>
          <sum type="sha">ed90cd2ca4f5c784c1c7342f6d7d72535107c3b1</sum>
        </package>
        <package arch="all" name="vim-doc" version="2:8.1.0875-5+deb10u6+tuxcare.els16">
          <filename>vim-doc_8.1.0875-5+deb10u6+tuxcare.els16_all.deb</filename>
          <sum type="sha">4113966a9d8f7725f71d92ac69a053d8cfa0eda6</sum>
        </package>
        <package arch="amd64" name="vim-gtk" version="2:8.1.0875-5+deb10u6+tuxcare.els16">
          <filename>vim-gtk_8.1.0875-5+deb10u6+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">1dddc1c860405a7ffe713fb1853355a19ba6c670</sum>
        </package>
        <package arch="amd64" name="vim-gtk3" version="2:8.1.0875-5+deb10u6+tuxcare.els16">
          <filename>vim-gtk3_8.1.0875-5+deb10u6+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">f3f77b58aedbec873260d9d629c2eaf5f969174f</sum>
        </package>
        <package arch="all" name="vim-gui-common" version="2:8.1.0875-5+deb10u6+tuxcare.els16">
          <filename>vim-gui-common_8.1.0875-5+deb10u6+tuxcare.els16_all.deb</filename>
          <sum type="sha">0557127776d7694f6207b1abf87ef9fbdc23c87c</sum>
        </package>
        <package arch="amd64" name="vim-nox" version="2:8.1.0875-5+deb10u6+tuxcare.els16">
          <filename>vim-nox_8.1.0875-5+deb10u6+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">738b2d5cfbed2d59d12a763076d5f8a7889679ac</sum>
        </package>
        <package arch="all" name="vim-runtime" version="2:8.1.0875-5+deb10u6+tuxcare.els16">
          <filename>vim-runtime_8.1.0875-5+deb10u6+tuxcare.els16_all.deb</filename>
          <sum type="sha">a70c8295818fdb0ed4ffe376e73ac6a9f669c98b</sum>
        </package>
        <package arch="amd64" name="vim-tiny" version="2:8.1.0875-5+deb10u6+tuxcare.els16">
          <filename>vim-tiny_8.1.0875-5+deb10u6+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">5b4043c5a47679e889bea4b2ed82b319f843c494</sum>
        </package>
        <package arch="amd64" name="xxd" version="2:8.1.0875-5+deb10u6+tuxcare.els16">
          <filename>xxd_8.1.0875-5+deb10u6+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">27675dd5097ea0c62004e7bd41786e32af7076b2</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1774947465</id>
    <title>Fix CVE(s): CVE-2026-32748, CVE-2026-33515, CVE-2026-33526</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Denial of Service in ICP request handling via double
     rfc1738_escape() call causing heap use-after-free
     - debian/patches/CVE-2026-33526.patch: Remove redundant rfc1738_escape()
       call in icpGetRequest()
     - CVE-2026-33526
   * SECURITY UPDATE: Denial of Service in ICP v3 query handling via
     use-after-free of HttpRequest object
     - debian/patches/CVE-2026-32748.patch: Add proper HTTPMSGLOCK/HTTPMSGUNLOCK
       to doV3Query() to match doV2Query() locking pattern
     - CVE-2026-32748
   * SECURITY UPDATE: Out-of-bounds read in ICP message handling allows
     information disclosure
     - debian/patches/CVE-2026-33515.patch: Add icpGetUrl() validation function
       to check packet bounds and NUL-termination of URLs in ICP messages
     - CVE-2026-33515</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Denial of Service in ICP request handling via double
     rfc1738_escape() call causing heap use-after-free
     - debian/patches/CVE-2026-33526.patch: Remove redundant rfc1738_escape()
       call in icpGetRequest()
     - CVE-2026-33526
   * SECURITY UPDATE: Denial of Service in ICP v3 query handling via
     use-after-free of HttpRequest object
     - debian/patches/CVE-2026-32748.patch: Add proper HTTPMSGLOCK/HTTPMSGUNLOCK
       to doV3Query() to match doV2Query() locking pattern
     - CVE-2026-32748
   * SECURITY UPDATE: Out-of-bounds read in ICP message handling allows
     information disclosure
     - debian/patches/CVE-2026-33515.patch: Add icpGetUrl() validation function
       to check packet bounds and NUL-termination of URLs in ICP messages
     - CVE-2026-33515</summary>
    <pushcount>0</pushcount>
    <issued date="2026-03-31 08:57:50 UTC" />
    <updated date="2026-03-31 08:57:50 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1774947465.html" id="CLSA-2026:1774947465" title="CLSA-2026:1774947465" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="squid" version="4.6-1+deb10u10+tuxcare.els4">
          <filename>squid_4.6-1+deb10u10+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">fbd8bd2f199de7fc49df2d9b7a46cc28f1568b5d</sum>
        </package>
        <package arch="amd64" name="squid-cgi" version="4.6-1+deb10u10+tuxcare.els4">
          <filename>squid-cgi_4.6-1+deb10u10+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">466108633c86276ff1af9d42559f1b8800f354be</sum>
        </package>
        <package arch="all" name="squid-common" version="4.6-1+deb10u10+tuxcare.els4">
          <filename>squid-common_4.6-1+deb10u10+tuxcare.els4_all.deb</filename>
          <sum type="sha">06315839150619eef4f57a8eb74c0df074ca1afd</sum>
        </package>
        <package arch="amd64" name="squid-purge" version="4.6-1+deb10u10+tuxcare.els4">
          <filename>squid-purge_4.6-1+deb10u10+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">fde27d9a1be6144bc323ba03c0609e44c1f41466</sum>
        </package>
        <package arch="all" name="squid3" version="4.6-1+deb10u10+tuxcare.els4">
          <filename>squid3_4.6-1+deb10u10+tuxcare.els4_all.deb</filename>
          <sum type="sha">10d8ca8573e9e47986ca387775224c19e07b52d4</sum>
        </package>
        <package arch="amd64" name="squidclient" version="4.6-1+deb10u10+tuxcare.els4">
          <filename>squidclient_4.6-1+deb10u10+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">2e9dde0eeb6f9e3288c77543ae6b9ad3ca9ae803</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1776159098</id>
    <title>Fix CVE(s): CVE-2025-30258</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: signature verification DoS via malicious subkey
     - debian/patches/CVE-2025-30258.patch: require signing usage when
       looking up public key for signature verification, filtering out
       subkeys without valid backsig. Include upstream regression fixes
       to preserve verification of signatures from expired/revoked keys.
       Widen pubkey_usage and req_usage fields from byte to u16 to
       prevent PUBKEY_USAGE_VERIFY (16384) from being truncated on
       GnuPG 2.2.x. Add primary-key-only lookup during import to
       prevent malicious subkey attack at import time. Fix double-free
       in check_signature_over_key_or_uid when signer is caller-owned.
     - CVE-2025-30258</description>
    <severity>Moderate</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: signature verification DoS via malicious subkey
     - debian/patches/CVE-2025-30258.patch: require signing usage when
       looking up public key for signature verification, filtering out
       subkeys without valid backsig. Include upstream regression fixes
       to preserve verification of signatures from expired/revoked keys.
       Widen pubkey_usage and req_usage fields from byte to u16 to
       prevent PUBKEY_USAGE_VERIFY (16384) from being truncated on
       GnuPG 2.2.x. Add primary-key-only lookup during import to
       prevent malicious subkey attack at import time. Fix double-free
       in check_signature_over_key_or_uid when signer is caller-owned.
     - CVE-2025-30258</summary>
    <pushcount>0</pushcount>
    <issued date="2026-04-14 09:31:43 UTC" />
    <updated date="2026-04-14 09:31:43 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1776159098.html" id="CLSA-2026:1776159098" title="CLSA-2026:1776159098" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="dirmngr" version="2.2.12-1+deb10u2+tuxcare.els2">
          <filename>dirmngr_2.2.12-1+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">9f7193778db5aea55707c09aeb4c45ada0291514</sum>
        </package>
        <package arch="all" name="gnupg" version="2.2.12-1+deb10u2+tuxcare.els2">
          <filename>gnupg_2.2.12-1+deb10u2+tuxcare.els2_all.deb</filename>
          <sum type="sha">199cde1d738f0f72527836865b2c3ec01ef1098e</sum>
        </package>
        <package arch="all" name="gnupg-agent" version="2.2.12-1+deb10u2+tuxcare.els2">
          <filename>gnupg-agent_2.2.12-1+deb10u2+tuxcare.els2_all.deb</filename>
          <sum type="sha">5d2c1e812bfbb228f149b6e4fb6e015d391f320c</sum>
        </package>
        <package arch="all" name="gnupg-l10n" version="2.2.12-1+deb10u2+tuxcare.els2">
          <filename>gnupg-l10n_2.2.12-1+deb10u2+tuxcare.els2_all.deb</filename>
          <sum type="sha">6d2444c4a6da540317e070c268b18a10fdbff00a</sum>
        </package>
        <package arch="amd64" name="gnupg-utils" version="2.2.12-1+deb10u2+tuxcare.els2">
          <filename>gnupg-utils_2.2.12-1+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">d966e6e453f49d407900bb48758c64f0ff89b84c</sum>
        </package>
        <package arch="all" name="gnupg2" version="2.2.12-1+deb10u2+tuxcare.els2">
          <filename>gnupg2_2.2.12-1+deb10u2+tuxcare.els2_all.deb</filename>
          <sum type="sha">b48eca80f9fd6995d77568f631d64481c660a685</sum>
        </package>
        <package arch="amd64" name="gpg" version="2.2.12-1+deb10u2+tuxcare.els2">
          <filename>gpg_2.2.12-1+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">0b14ddbcc0d4ca970e5f3056f829f58e97fdee50</sum>
        </package>
        <package arch="amd64" name="gpg-agent" version="2.2.12-1+deb10u2+tuxcare.els2">
          <filename>gpg-agent_2.2.12-1+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">b6a5576de42822d15f885afcb05c831392d09903</sum>
        </package>
        <package arch="amd64" name="gpg-wks-client" version="2.2.12-1+deb10u2+tuxcare.els2">
          <filename>gpg-wks-client_2.2.12-1+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">485341eb249c8fe33fa5eed69a719a9f3f823ac4</sum>
        </package>
        <package arch="amd64" name="gpg-wks-server" version="2.2.12-1+deb10u2+tuxcare.els2">
          <filename>gpg-wks-server_2.2.12-1+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">03c50b85002c0f22284e97a68884e9ab6e87e27d</sum>
        </package>
        <package arch="amd64" name="gpgconf" version="2.2.12-1+deb10u2+tuxcare.els2">
          <filename>gpgconf_2.2.12-1+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">c53d1c771077f6689253f039fb78604659a75d4c</sum>
        </package>
        <package arch="amd64" name="gpgsm" version="2.2.12-1+deb10u2+tuxcare.els2">
          <filename>gpgsm_2.2.12-1+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">1359d1dcecc93faee4ae5660d5ef2a2b5807591a</sum>
        </package>
        <package arch="amd64" name="gpgv" version="2.2.12-1+deb10u2+tuxcare.els2">
          <filename>gpgv_2.2.12-1+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">816ff192f1af1f5a039ed16b6bd9ba770f153f05</sum>
        </package>
        <package arch="amd64" name="gpgv-static" version="2.2.12-1+deb10u2+tuxcare.els2">
          <filename>gpgv-static_2.2.12-1+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">2d8fa840178d76bd3028b33bf0b34c386b3b5f00</sum>
        </package>
        <package arch="all" name="gpgv-win32" version="2.2.12-1+deb10u2+tuxcare.els2">
          <filename>gpgv-win32_2.2.12-1+deb10u2+tuxcare.els2_all.deb</filename>
          <sum type="sha">8f6f33895dda0655c8551b02a92efc9d19d5b074</sum>
        </package>
        <package arch="all" name="gpgv2" version="2.2.12-1+deb10u2+tuxcare.els2">
          <filename>gpgv2_2.2.12-1+deb10u2+tuxcare.els2_all.deb</filename>
          <sum type="sha">6bce4709acd3ec991ab57a98491f198bf29215c1</sum>
        </package>
        <package arch="amd64" name="scdaemon" version="2.2.12-1+deb10u2+tuxcare.els2">
          <filename>scdaemon_2.2.12-1+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">04b54c4dbe52e856d6a2037a753e3e975f8a2a98</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1776177493</id>
    <title>Fix CVE(s): CVE-2025-11082</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix heap-based buffer overflow in _bfd_elf_parse_eh_frame
     - debian/patches/CVE-2025-11082.patch: add bounds check before reading
       buf[1] in the legacy "eh" CIE path
     - CVE-2025-11082</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix heap-based buffer overflow in _bfd_elf_parse_eh_frame
     - debian/patches/CVE-2025-11082.patch: add bounds check before reading
       buf[1] in the legacy "eh" CIE path
     - CVE-2025-11082</summary>
    <pushcount>0</pushcount>
    <issued date="2026-04-14 14:38:18 UTC" />
    <updated date="2026-04-14 14:38:18 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1776177493.html" id="CLSA-2026:1776177493" title="CLSA-2026:1776177493" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="binutils" version="2.31.1-16+tuxcare.els10">
          <filename>binutils_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">0aba913c14fe4ca890ef317cbc9f48c631a99b40</sum>
        </package>
        <package arch="amd64" name="binutils-aarch64-linux-gnu" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-aarch64-linux-gnu_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">498ae58bf5e5a74f789fa22e4e2713c13772d683</sum>
        </package>
        <package arch="amd64" name="binutils-alpha-linux-gnu" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-alpha-linux-gnu_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">d13c2cfef369531fb3fb87d9a7297eefc79187c4</sum>
        </package>
        <package arch="amd64" name="binutils-arm-linux-gnueabi" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-arm-linux-gnueabi_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">3a66077765355cf087871b54225c495999a1bb9e</sum>
        </package>
        <package arch="amd64" name="binutils-arm-linux-gnueabihf" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-arm-linux-gnueabihf_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">0a8768d3960944469a7d2b6daf10c1ddbb19c522</sum>
        </package>
        <package arch="amd64" name="binutils-common" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-common_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">a21019f0af74c3430783222c5f0781a3b8169697</sum>
        </package>
        <package arch="amd64" name="binutils-dev" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-dev_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">19784bf09722c263d7b8330f9ad3a1a746e91cd5</sum>
        </package>
        <package arch="all" name="binutils-doc" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-doc_2.31.1-16+tuxcare.els10_all.deb</filename>
          <sum type="sha">e3df8253190ef35dc159cb44cd921ac791daa011</sum>
        </package>
        <package arch="all" name="binutils-for-build" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-for-build_2.31.1-16+tuxcare.els10_all.deb</filename>
          <sum type="sha">8605229f7ca206c3eabf390d13bedbb109a7845f</sum>
        </package>
        <package arch="amd64" name="binutils-for-host" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-for-host_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">3b0418148e29ae191c5b773ce039eb03e3dbb764</sum>
        </package>
        <package arch="amd64" name="binutils-hppa-linux-gnu" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-hppa-linux-gnu_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">64f69ed3cf2ae9ae835892728041445bdfbbbec4</sum>
        </package>
        <package arch="amd64" name="binutils-hppa64-linux-gnu" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-hppa64-linux-gnu_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">7f8a61d57c3fdd8e7b2283f56e2dacbcd5e73a1e</sum>
        </package>
        <package arch="amd64" name="binutils-i686-gnu" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-i686-gnu_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">6ee187dafb5765c1f1041d65aebd2ddb12c22337</sum>
        </package>
        <package arch="amd64" name="binutils-i686-kfreebsd-gnu" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-i686-kfreebsd-gnu_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">0b2c0b4dd132cb526262df8ec7e7df97a7d83fc2</sum>
        </package>
        <package arch="amd64" name="binutils-i686-linux-gnu" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-i686-linux-gnu_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">537254f3983d7acc1af8540d5ae133d37e674a2f</sum>
        </package>
        <package arch="amd64" name="binutils-ia64-linux-gnu" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-ia64-linux-gnu_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">f32a465caa0bfa62ea8d78f6e755b04cfe41f258</sum>
        </package>
        <package arch="amd64" name="binutils-m68k-linux-gnu" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-m68k-linux-gnu_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">4866a9ca64d99ba207ef3913e78f7fd9b1ffd458</sum>
        </package>
        <package arch="amd64" name="binutils-mips-linux-gnu" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-mips-linux-gnu_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">7c7246976ff3adf5d312abcf52fed4da868c4730</sum>
        </package>
        <package arch="amd64" name="binutils-mips64el-linux-gnuabi64" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-mips64el-linux-gnuabi64_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">af3521c3a884e3f8fa466a78b776cd0ca0eb7f40</sum>
        </package>
        <package arch="amd64" name="binutils-mipsel-linux-gnu" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-mipsel-linux-gnu_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">fe6abaa9d4deb6c87d7feea384e891c0945b994b</sum>
        </package>
        <package arch="amd64" name="binutils-multiarch" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-multiarch_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">e1ab7d3287ab730c143c1506be29bbe6b3adce33</sum>
        </package>
        <package arch="amd64" name="binutils-multiarch-dev" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-multiarch-dev_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">02fe354213c59ebc9890be8f7129901d072c2b10</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc-linux-gnu" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-powerpc-linux-gnu_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">858e4300b886091c0cd74466d37edc99f28bf55b</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc-linux-gnuspe" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-powerpc-linux-gnuspe_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">dc8465fce5377b74b05f1dc8e30ea6a339e7c6fe</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc64-linux-gnu" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-powerpc64-linux-gnu_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">69ae33aa95c57f3976f71e0ba3ed7746feb83bba</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc64le-linux-gnu" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-powerpc64le-linux-gnu_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">d944da8cb0fa16674518dfd862ab46b36d6baeb7</sum>
        </package>
        <package arch="amd64" name="binutils-riscv64-linux-gnu" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-riscv64-linux-gnu_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">8f6c5565b6f6b4334e3a57017b1df9c7948e961a</sum>
        </package>
        <package arch="amd64" name="binutils-s390x-linux-gnu" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-s390x-linux-gnu_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">c5e23541b11b222fa380852fed24a89fead9afc1</sum>
        </package>
        <package arch="amd64" name="binutils-sh4-linux-gnu" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-sh4-linux-gnu_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">df954725723863af3543817ab9ef653b85dd2c19</sum>
        </package>
        <package arch="all" name="binutils-source" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-source_2.31.1-16+tuxcare.els10_all.deb</filename>
          <sum type="sha">76cbc04c8698a05f38697dbedc4bb8958c2e8e39</sum>
        </package>
        <package arch="amd64" name="binutils-sparc64-linux-gnu" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-sparc64-linux-gnu_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">cbc67e713e4045bf6a713276b80b205ec8652e35</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-kfreebsd-gnu" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-x86-64-kfreebsd-gnu_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">bcbf15132b30164176a515ad6b21e60f71ff7018</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-linux-gnu" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-x86-64-linux-gnu_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">27d43a551d43f17a60ff86bd168fc8296fdb30d0</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-linux-gnux32" version="2.31.1-16+tuxcare.els10">
          <filename>binutils-x86-64-linux-gnux32_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">651c2e4c17b6cd430498abf78a2b0a16558ff860</sum>
        </package>
        <package arch="amd64" name="libbinutils" version="2.31.1-16+tuxcare.els10">
          <filename>libbinutils_2.31.1-16+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">566e5fed399bf004331dd1804c92d2d0bd1cb990</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1776178825</id>
    <title>Fix of 8 CVEs</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix vulnerability in stream handling
     - debian/patches/CVE-2025-53019.patch: fix vulnerability in stream handling
     - CVE-2025-53019
   * SECURITY UPDATE: fix integer overflow in resize
     - debian/patches/CVE-2025-55212.patch: fix integer overflow in resize
     - CVE-2025-55212
   * SECURITY UPDATE: fix heap-based buffer overflow in image processing
     - debian/patches/CVE-2025-55298.patch: fix heap-based buffer overflow in image processing
     - CVE-2025-55298
   * SECURITY UPDATE: fix buffer overflow in BMP coder
     - debian/patches/CVE-2025-57803.patch: fix buffer overflow in BMP coder
     - CVE-2025-57803
   * SECURITY UPDATE: fix vulnerability in PNG coder
     - debian/patches/CVE-2025-55154.patch: fix vulnerability in PNG coder
     - CVE-2025-55154
   * SECURITY UPDATE: fix buffer overflow in BMP coder on 32-bit systems
     - debian/patches/CVE-2025-62171.patch: fix buffer overflow in BMP coder on 32-bit systems
     - CVE-2025-62171
   * SECURITY UPDATE: fix stack overflow via infinite recursion in MSL and SVG coders
     - debian/patches/CVE-2025-68618.patch: fix stack overflow via infinite recursion in MSL and SVG coders
     - CVE-2025-68618
   * SECURITY UPDATE: fix denial of service in SVG coder
     - debian/patches/CVE-2025-69204.patch: fix denial of service in SVG coder
     - CVE-2025-69204</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix vulnerability in stream handling
     - debian/patches/CVE-2025-53019.patch: fix vulnerability in stream handling
     - CVE-2025-53019
   * SECURITY UPDATE: fix integer overflow in resize
     - debian/patches/CVE-2025-55212.patch: fix integer overflow in resize
     - CVE-2025-55212
   * SECURITY UPDATE: fix heap-based buffer overflow in image processing
     - debian/patches/CVE-2025-55298.patch: fix heap-based buffer overflow in image processing
     - CVE-2025-55298
   * SECURITY UPDATE: fix buffer overflow in BMP coder
     - debian/patches/CVE-2025-57803.patch: fix buffer overflow in BMP coder
     - CVE-2025-57803
   * SECURITY UPDATE: fix vulnerability in PNG coder
     - debian/patches/CVE-2025-55154.patch: fix vulnerability in PNG coder
     - CVE-2025-55154
   * SECURITY UPDATE: fix buffer overflow in BMP coder on 32-bit systems
     - debian/patches/CVE-2025-62171.patch: fix buffer overflow in BMP coder on 32-bit systems
     - CVE-2025-62171
   * SECURITY UPDATE: fix stack overflow via infinite recursion in MSL and SVG coders
     - debian/patches/CVE-2025-68618.patch: fix stack overflow via infinite recursion in MSL and SVG coders
     - CVE-2025-68618
   * SECURITY UPDATE: fix denial of service in SVG coder
     - debian/patches/CVE-2025-69204.patch: fix denial of service in SVG coder
     - CVE-2025-69204</summary>
    <pushcount>0</pushcount>
    <issued date="2026-04-14 15:00:30 UTC" />
    <updated date="2026-04-14 15:00:30 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1776178825.html" id="CLSA-2026:1776178825" title="CLSA-2026:1776178825" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="imagemagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>imagemagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">bc11d6cbd76458b24059f9c18f5d80a4a5fc13d6</sum>
        </package>
        <package arch="all" name="imagemagick-6-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>imagemagick-6-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_all.deb</filename>
          <sum type="sha">69135e92e6774c76d020534570452b6b539b20a5</sum>
        </package>
        <package arch="all" name="imagemagick-6-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>imagemagick-6-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_all.deb</filename>
          <sum type="sha">565283cba4898c4454d6a4a0e0492d851c25accf</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>imagemagick-6.q16_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">51122accdb3024bbd61e0598ae3cf83d51978190</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16hdri" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>imagemagick-6.q16hdri_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">b6acb0653ff07bd796a1b235757104a87f247450</sum>
        </package>
        <package arch="all" name="imagemagick-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>imagemagick-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_all.deb</filename>
          <sum type="sha">246ac87a238634c75219c218b08673b46f13383a</sum>
        </package>
        <package arch="all" name="imagemagick-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>imagemagick-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_all.deb</filename>
          <sum type="sha">45d3c9a1c1df9ecd9e20acc8c1609ad1db611291</sum>
        </package>
        <package arch="all" name="libimage-magick-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libimage-magick-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_all.deb</filename>
          <sum type="sha">eb35ec30be6f00954f3eb392b11e731d1a2f0a20</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libimage-magick-q16-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">3332bc805e852a124942820d39a123101d9185fd</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16hdri-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libimage-magick-q16hdri-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">49590a79eda6ea44bceef1ce4a9c81a1fc557a3f</sum>
        </package>
        <package arch="all" name="libmagick++-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libmagick++-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_all.deb</filename>
          <sum type="sha">1d287d966e1fe144d6e97d804d50a0347f55f099</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libmagick++-6.q16-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">87e6cd232405a8c1b669bab56446d3e8e83baefe</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libmagick++-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">9bd78eadf52ebc6b4c5001b68a510eb54604f3be</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libmagick++-6.q16hdri-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">9295d9d744869297b5be24c5d8804b8abaf64349</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libmagick++-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">c3587917667017653a610fc0829fcbcb1858ba59</sum>
        </package>
        <package arch="all" name="libmagick++-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libmagick++-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_all.deb</filename>
          <sum type="sha">31e73cbfefbe0f996d2b40bc705ee29407a653fb</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6-arch-config" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libmagickcore-6-arch-config_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">7460d5984d6f06e37706da8943ac4997e01a832f</sum>
        </package>
        <package arch="all" name="libmagickcore-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libmagickcore-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_all.deb</filename>
          <sum type="sha">e92bccbf1bf1f99e9280b543a62daa49bdca7cc5</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libmagickcore-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">a94d68551cb65ebc5be2ba23a1f3977126a1b493</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libmagickcore-6.q16-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">438c809f075feb40fda35583b64a85eff04daa02</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libmagickcore-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">d75b816b090dc10c88b63ff8546d522dec5487f4</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libmagickcore-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">4c346ffa84bf5b7601d8e98b13e8c22620f0a10f</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libmagickcore-6.q16hdri-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">e4441950e813f605375c56ce656fd3f15257601a</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libmagickcore-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">80b94a239be97baa91f5292efdad1c57ab3973da</sum>
        </package>
        <package arch="all" name="libmagickcore-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libmagickcore-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_all.deb</filename>
          <sum type="sha">38a02e467a6ac9179e5c29fad2abf817e404e8bc</sum>
        </package>
        <package arch="all" name="libmagickwand-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libmagickwand-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_all.deb</filename>
          <sum type="sha">03ebbc53793eb68cd36066c14a36d7c1ce7ea6ee</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libmagickwand-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">cb0df94de2ad2fca1e19bd35063cb1bae0b7786f</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libmagickwand-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">8fd077a47f3b28b993bb5976073ae3bf92eb370d</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libmagickwand-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">a639d8a9caff19d19e93cb2648e43920f9fe2d28</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libmagickwand-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">df53cd9cbac8b31ab2a9aa202c84b6b3be15584e</sum>
        </package>
        <package arch="all" name="libmagickwand-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>libmagickwand-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_all.deb</filename>
          <sum type="sha">ab72e34b88eed67082c695e4f4164e724c6563a0</sum>
        </package>
        <package arch="all" name="perlmagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2">
          <filename>perlmagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els2_all.deb</filename>
          <sum type="sha">e55680e72ea0c2b3e4a131d6ca8eef7f7087845a</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1776179155</id>
    <title>Fix of 8 CVEs</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix division by zero in YUV coder
     - debian/patches/CVE-2026-25799.patch: fix division by zero in YUV coder
     - CVE-2026-25799
   * SECURITY UPDATE: fix NULL pointer dereference in SFW coder
     - debian/patches/CVE-2026-25795.patch: fix NULL pointer dereference in SFW coder
     - CVE-2026-25795
   * SECURITY UPDATE: fix infinite loop in META coder
     - debian/patches/CVE-2026-26066.patch: fix infinite loop in META coder
     - CVE-2026-26066
   * SECURITY UPDATE: fix vulnerability in JPEG coder
     - debian/patches/CVE-2026-26283.patch: fix vulnerability in JPEG coder
     - CVE-2026-26283
   * SECURITY UPDATE: fix NULL pointer dereference in cache handling
     - debian/patches/CVE-2026-25798.patch: fix NULL pointer dereference in cache handling
     - CVE-2026-25798
   * SECURITY UPDATE: fix vulnerability in PSD coder
     - debian/patches/CVE-2026-24481.patch: fix vulnerability in PSD coder
     - CVE-2026-24481
   * SECURITY UPDATE: fix vulnerability in stegano coder
     - debian/patches/CVE-2026-25796.patch: fix vulnerability in stegano coder
     - CVE-2026-25796
   * SECURITY UPDATE: fix vulnerability in FX processing
     - debian/patches/CVE-2026-27798.patch: fix vulnerability in FX processing
     - CVE-2026-27798</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix division by zero in YUV coder
     - debian/patches/CVE-2026-25799.patch: fix division by zero in YUV coder
     - CVE-2026-25799
   * SECURITY UPDATE: fix NULL pointer dereference in SFW coder
     - debian/patches/CVE-2026-25795.patch: fix NULL pointer dereference in SFW coder
     - CVE-2026-25795
   * SECURITY UPDATE: fix infinite loop in META coder
     - debian/patches/CVE-2026-26066.patch: fix infinite loop in META coder
     - CVE-2026-26066
   * SECURITY UPDATE: fix vulnerability in JPEG coder
     - debian/patches/CVE-2026-26283.patch: fix vulnerability in JPEG coder
     - CVE-2026-26283
   * SECURITY UPDATE: fix NULL pointer dereference in cache handling
     - debian/patches/CVE-2026-25798.patch: fix NULL pointer dereference in cache handling
     - CVE-2026-25798
   * SECURITY UPDATE: fix vulnerability in PSD coder
     - debian/patches/CVE-2026-24481.patch: fix vulnerability in PSD coder
     - CVE-2026-24481
   * SECURITY UPDATE: fix vulnerability in stegano coder
     - debian/patches/CVE-2026-25796.patch: fix vulnerability in stegano coder
     - CVE-2026-25796
   * SECURITY UPDATE: fix vulnerability in FX processing
     - debian/patches/CVE-2026-27798.patch: fix vulnerability in FX processing
     - CVE-2026-27798</summary>
    <pushcount>0</pushcount>
    <issued date="2026-04-14 15:05:59 UTC" />
    <updated date="2026-04-14 15:05:59 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1776179155.html" id="CLSA-2026:1776179155" title="CLSA-2026:1776179155" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="imagemagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>imagemagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">d36a42d5837a6eb565427a794148e1c12ba08b3f</sum>
        </package>
        <package arch="all" name="imagemagick-6-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>imagemagick-6-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_all.deb</filename>
          <sum type="sha">b8362d7ab3d4c5b12d445f2ff0843e874f3b34a9</sum>
        </package>
        <package arch="all" name="imagemagick-6-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>imagemagick-6-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_all.deb</filename>
          <sum type="sha">015a6342845ea155e46dbadd7785edf242a9048b</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>imagemagick-6.q16_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">f29d0e89e61f70fde13ffee4a4ad4aa24cfd2cc5</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16hdri" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>imagemagick-6.q16hdri_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">fc8630daadfc5036d31f49b11360a095fcae74d1</sum>
        </package>
        <package arch="all" name="imagemagick-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>imagemagick-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_all.deb</filename>
          <sum type="sha">68c793b3de8aef4f94a137002b5daf4c063f2825</sum>
        </package>
        <package arch="all" name="imagemagick-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>imagemagick-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_all.deb</filename>
          <sum type="sha">d0bd18c879edbd6ceef1b46740f6bc340fa75a4e</sum>
        </package>
        <package arch="all" name="libimage-magick-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libimage-magick-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_all.deb</filename>
          <sum type="sha">d46eaf7345a5a1fbcc85ce5ef490101c5b8e7918</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libimage-magick-q16-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">27681cef324d8ce41bc1c9b48021b9ae0955aa38</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16hdri-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libimage-magick-q16hdri-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">7aee80296099695ff9e3c7f1530a1ccf0a83a656</sum>
        </package>
        <package arch="all" name="libmagick++-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libmagick++-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_all.deb</filename>
          <sum type="sha">0b1ad83f17b422ef0eb0772d8a9d3075e902e5f0</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libmagick++-6.q16-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">5b84b3b7205f8b852c8f8916cf923cee13597e9b</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libmagick++-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">088ab24c1dd296bfc59d12f29ff65464043410b0</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libmagick++-6.q16hdri-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">a2f1a3e262137c8460443e4f11fd357e37e3db33</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libmagick++-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">40032108c7ec1172e23a78c86a4670b6fec48024</sum>
        </package>
        <package arch="all" name="libmagick++-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libmagick++-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_all.deb</filename>
          <sum type="sha">0a1b3be0c757a3b190c1782e78bc17bc015cc429</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6-arch-config" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libmagickcore-6-arch-config_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">55688c9499b81d1ba2f762147866ff9b971be330</sum>
        </package>
        <package arch="all" name="libmagickcore-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libmagickcore-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_all.deb</filename>
          <sum type="sha">15c31d59079f25d1638e3d8767c5090444077bfa</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libmagickcore-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">508a2959e6095ef1de4af02ca025399636755936</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libmagickcore-6.q16-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">3b738b4aa94af2c2a4ec278cdfa778bc099fe115</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libmagickcore-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">05eef9e01014d668300eb3a6bebb9491af5ef7c2</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libmagickcore-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">617876b27db25f0ca055a2644886160eed9516d9</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libmagickcore-6.q16hdri-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">3e7f43a85f5450060c8d17ed3fd7778a0c2e4e24</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libmagickcore-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">0c92a833a879187909b9ee2ae54427c9c6e10551</sum>
        </package>
        <package arch="all" name="libmagickcore-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libmagickcore-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_all.deb</filename>
          <sum type="sha">c0a21175844b5f73b1ba46825155dee7f568e8de</sum>
        </package>
        <package arch="all" name="libmagickwand-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libmagickwand-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_all.deb</filename>
          <sum type="sha">586c9a50585835a5abb94ada06ef2c06c53830a4</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libmagickwand-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">3c19889f78bbdc26a5a62b9a180456e23e5c5893</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libmagickwand-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">b70693bf4c98f1f705cb1fa8692d0053fe66caf5</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libmagickwand-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">3cdffba77a7b93786fd3684c209428d4e8e41789</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libmagickwand-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">4fde1441d2136c2d79431fb7da0d18828f32ca24</sum>
        </package>
        <package arch="all" name="libmagickwand-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>libmagickwand-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_all.deb</filename>
          <sum type="sha">76ed97c5f581e28308c6c90aef1ba37a67b8f49d</sum>
        </package>
        <package arch="all" name="perlmagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3">
          <filename>perlmagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els3_all.deb</filename>
          <sum type="sha">b3823c6f9d516edc660fc8f6e6c3bd3560c7c7d2</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1776180138</id>
    <title>Fix of 12 CVEs</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix vulnerability in image handling
     - debian/patches/CVE-2025-53101.patch: fix vulnerability in image handling
     - CVE-2025-53101
   * SECURITY UPDATE: fix vulnerability in image handling
     - debian/patches/CVE-2025-53014.patch: fix vulnerability in image handling
     - CVE-2025-53014
   * SECURITY UPDATE: fix heap-based buffer overflow in blob handling
     - debian/patches/CVE-2025-57807.patch: fix heap-based buffer overflow in blob handling
     - CVE-2025-57807
   * SECURITY UPDATE: fix heap-based buffer overflow in XBM coder
     - debian/patches/CVE-2026-23876.patch: fix heap-based buffer overflow in XBM coder
     - CVE-2026-23876
   * SECURITY UPDATE: fix buffer overflow in SUN coder
     - debian/patches/CVE-2026-25897.patch: fix buffer overflow in SUN coder
     - CVE-2026-25897
   * SECURITY UPDATE: fix buffer overflow in PCD coder
     - debian/patches/CVE-2026-26284.patch: fix buffer overflow in PCD coder
     - CVE-2026-26284
   * SECURITY UPDATE: fix vulnerability in MSL coder
     - debian/patches/CVE-2026-25968.patch: fix vulnerability in MSL coder
     - CVE-2026-25968
   * SECURITY UPDATE: fix buffer overflow in YUV coder
     - debian/patches/CVE-2026-25986.patch: fix buffer overflow in YUV coder
     - CVE-2026-25986
   * SECURITY UPDATE: fix buffer overflow in MAP coder
     - debian/patches/CVE-2026-25987.patch: fix buffer overflow in MAP coder
     - CVE-2026-25987
   * SECURITY UPDATE: fix buffer overflow in UIL and XPM coders
     - debian/patches/CVE-2026-25898.patch: fix buffer overflow in UIL and XPM coders
     - CVE-2026-25898
   * SECURITY UPDATE: fix heap-use-after-free in MSL coder
     - debian/patches/CVE-2026-25983.patch: fix heap-use-after-free in MSL coder
     - CVE-2026-25983
   * SECURITY UPDATE: fix stack overflow via infinite recursion in MSL, SVG, and draw handling
     - debian/patches/CVE-2026-25971.patch: fix stack overflow via infinite recursion in MSL, SVG, and draw handling
     - CVE-2026-25971</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix vulnerability in image handling
     - debian/patches/CVE-2025-53101.patch: fix vulnerability in image handling
     - CVE-2025-53101
   * SECURITY UPDATE: fix vulnerability in image handling
     - debian/patches/CVE-2025-53014.patch: fix vulnerability in image handling
     - CVE-2025-53014
   * SECURITY UPDATE: fix heap-based buffer overflow in blob handling
     - debian/patches/CVE-2025-57807.patch: fix heap-based buffer overflow in blob handling
     - CVE-2025-57807
   * SECURITY UPDATE: fix heap-based buffer overflow in XBM coder
     - debian/patches/CVE-2026-23876.patch: fix heap-based buffer overflow in XBM coder
     - CVE-2026-23876
   * SECURITY UPDATE: fix buffer overflow in SUN coder
     - debian/patches/CVE-2026-25897.patch: fix buffer overflow in SUN coder
     - CVE-2026-25897
   * SECURITY UPDATE: fix buffer overflow in PCD coder
     - debian/patches/CVE-2026-26284.patch: fix buffer overflow in PCD coder
     - CVE-2026-26284
   * SECURITY UPDATE: fix vulnerability in MSL coder
     - debian/patches/CVE-2026-25968.patch: fix vulnerability in MSL coder
     - CVE-2026-25968
   * SECURITY UPDATE: fix buffer overflow in YUV coder
     - debian/patches/CVE-2026-25986.patch: fix buffer overflow in YUV coder
     - CVE-2026-25986
   * SECURITY UPDATE: fix buffer overflow in MAP coder
     - debian/patches/CVE-2026-25987.patch: fix buffer overflow in MAP coder
     - CVE-2026-25987
   * SECURITY UPDATE: fix buffer overflow in UIL and XPM coders
     - debian/patches/CVE-2026-25898.patch: fix buffer overflow in UIL and XPM coders
     - CVE-2026-25898
   * SECURITY UPDATE: fix heap-use-after-free in MSL coder
     - debian/patches/CVE-2026-25983.patch: fix heap-use-after-free in MSL coder
     - CVE-2026-25983
   * SECURITY UPDATE: fix stack overflow via infinite recursion in MSL, SVG, and draw handling
     - debian/patches/CVE-2026-25971.patch: fix stack overflow via infinite recursion in MSL, SVG, and draw handling
     - CVE-2026-25971</summary>
    <pushcount>0</pushcount>
    <issued date="2026-04-14 15:22:23 UTC" />
    <updated date="2026-04-14 15:22:23 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1776180138.html" id="CLSA-2026:1776180138" title="CLSA-2026:1776180138" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="imagemagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>imagemagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">f39c6ada77de4a2d4df7fa85ba59c07cdf5ebfe8</sum>
        </package>
        <package arch="all" name="imagemagick-6-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>imagemagick-6-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_all.deb</filename>
          <sum type="sha">8443c9b971c21be1b020bd19325b9229c05008a2</sum>
        </package>
        <package arch="all" name="imagemagick-6-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>imagemagick-6-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_all.deb</filename>
          <sum type="sha">8ccca8f94d9a5567b41d17f0fdde85c1cbf30989</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>imagemagick-6.q16_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">946d931692681156d77f3f3d29b59dc7ffbf592f</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16hdri" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>imagemagick-6.q16hdri_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">1ef6e6070093ac5fde678d2c9057286fa9de045b</sum>
        </package>
        <package arch="all" name="imagemagick-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>imagemagick-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_all.deb</filename>
          <sum type="sha">90e1d3cb78e8654d0ce06f83020ce3ca52274336</sum>
        </package>
        <package arch="all" name="imagemagick-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>imagemagick-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_all.deb</filename>
          <sum type="sha">1d3e890e715e41613271d4d411c7f00f9f628513</sum>
        </package>
        <package arch="all" name="libimage-magick-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libimage-magick-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_all.deb</filename>
          <sum type="sha">b465ac6b26261d3ca0946f3af30130dccd340671</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libimage-magick-q16-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">f6c910be6572187160e4a14ac4133e15af828960</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16hdri-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libimage-magick-q16hdri-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">a5d5765a9e61648ff2532dd6d56341f08c9ec74a</sum>
        </package>
        <package arch="all" name="libmagick++-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libmagick++-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_all.deb</filename>
          <sum type="sha">592c3ef948d57b1fcb68b17d5f401882918ee566</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libmagick++-6.q16-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">4af44805884c4245d17a89fc5f8ec478ff11413e</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libmagick++-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">dc810f35747e27e248eefe93ea41172c046176b4</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libmagick++-6.q16hdri-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">e526b32f6db3b31828da3e61becdeea4fe07f5db</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libmagick++-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">cc853c9f34385e1cec09324a9a0bb6802690cb8a</sum>
        </package>
        <package arch="all" name="libmagick++-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libmagick++-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_all.deb</filename>
          <sum type="sha">4f66ff41a5f727dd461331d2eca5d646f5f800b0</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6-arch-config" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libmagickcore-6-arch-config_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">06c0d6e4e37cc08d8a81b889a1abda533d216f9c</sum>
        </package>
        <package arch="all" name="libmagickcore-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libmagickcore-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_all.deb</filename>
          <sum type="sha">3e9a86680bb7bf374013bf114e8fdfeeceb3b524</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libmagickcore-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">7d3b63b7cf1c124a838c836a44c0ff7a6bcc6c09</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libmagickcore-6.q16-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">f77ba1af663cb5d6880627ee037cab02e39985bc</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libmagickcore-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">4e815b833a8afbd74e697844fc9d0a7d934f382b</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libmagickcore-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">e09c3e9539a0bec0d9647ca197f3581fce29e265</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libmagickcore-6.q16hdri-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">67e094201d15fc25b655ad42366e3017c56e5274</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libmagickcore-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">63498adac8ef58e037f89634ab3a5e44e39d3dee</sum>
        </package>
        <package arch="all" name="libmagickcore-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libmagickcore-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_all.deb</filename>
          <sum type="sha">e70b9f52ee47d939e4c44406abd7367158d18acb</sum>
        </package>
        <package arch="all" name="libmagickwand-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libmagickwand-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_all.deb</filename>
          <sum type="sha">c6e24cecf43063823681cde6222fe0c505460b1e</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libmagickwand-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">f5b7db21c0ac60644cf67dc178262c84a91792ac</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libmagickwand-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">b691aca167bc87d611c6ef31b063c32301b9742e</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libmagickwand-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">a0a8f22a433c6ef488d2b8e3bbcfda4e90158258</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libmagickwand-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">1cbcca598adac98430d013c0b9f83f4c2eaad914</sum>
        </package>
        <package arch="all" name="libmagickwand-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>libmagickwand-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_all.deb</filename>
          <sum type="sha">ba414c72a665a3a9401aa1eb118add092bb67d55</sum>
        </package>
        <package arch="all" name="perlmagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1">
          <filename>perlmagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els1_all.deb</filename>
          <sum type="sha">0562faa37f3374e849de888c3a73c6a947da2dec</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1777042487</id>
    <title>Fix CVE(s): CVE-2026-34980</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: filter control characters from option values in the
     scheduler to prevent PPD keyword injection via Print-Job.
     - debian/patches/CVE-2026-34980.patch: filter out control characters
       from IPP option values in scheduler/job.c and filter out special
       PPD keywords in the CUPSD_LOG_PPD branch of update_job().
     - CVE-2026-34980.</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: filter control characters from option values in the
     scheduler to prevent PPD keyword injection via Print-Job.
     - debian/patches/CVE-2026-34980.patch: filter out control characters
       from IPP option values in scheduler/job.c and filter out special
       PPD keywords in the CUPSD_LOG_PPD branch of update_job().
     - CVE-2026-34980.</summary>
    <pushcount>0</pushcount>
    <issued date="2026-04-24 16:18:05 UTC" />
    <updated date="2026-04-24 16:18:05 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1777042487.html" id="CLSA-2026:1777042487" title="CLSA-2026:1777042487" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="cups" version="2.2.10-6+deb10u10+tuxcare.els2">
          <filename>cups_2.2.10-6+deb10u10+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">bb13118c1863bd036d7a2154e56a070e26b83a12</sum>
        </package>
        <package arch="amd64" name="cups-bsd" version="2.2.10-6+deb10u10+tuxcare.els2">
          <filename>cups-bsd_2.2.10-6+deb10u10+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">e008ea1d0497814da691df3c47cf41e7f21b7a50</sum>
        </package>
        <package arch="amd64" name="cups-client" version="2.2.10-6+deb10u10+tuxcare.els2">
          <filename>cups-client_2.2.10-6+deb10u10+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">eca2cb700e3edb2e063f4989c685b97112f57d68</sum>
        </package>
        <package arch="all" name="cups-common" version="2.2.10-6+deb10u10+tuxcare.els2">
          <filename>cups-common_2.2.10-6+deb10u10+tuxcare.els2_all.deb</filename>
          <sum type="sha">c3ba2dd8e152a1718836a42e3dcbe2a0b3fb0464</sum>
        </package>
        <package arch="amd64" name="cups-core-drivers" version="2.2.10-6+deb10u10+tuxcare.els2">
          <filename>cups-core-drivers_2.2.10-6+deb10u10+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">f179557d237f431d4a055b77e5a1eb9ea5ff65b8</sum>
        </package>
        <package arch="amd64" name="cups-daemon" version="2.2.10-6+deb10u10+tuxcare.els2">
          <filename>cups-daemon_2.2.10-6+deb10u10+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">e8e3a9d29e1ceca338cc5e6c43270474ee77b7cc</sum>
        </package>
        <package arch="amd64" name="cups-ipp-utils" version="2.2.10-6+deb10u10+tuxcare.els2">
          <filename>cups-ipp-utils_2.2.10-6+deb10u10+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">098dc3ec43a871514fd47c704f7b507865019eb9</sum>
        </package>
        <package arch="amd64" name="cups-ppdc" version="2.2.10-6+deb10u10+tuxcare.els2">
          <filename>cups-ppdc_2.2.10-6+deb10u10+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">b3fa74cf557016150c38c4f0e218c991bf3ba5d9</sum>
        </package>
        <package arch="all" name="cups-server-common" version="2.2.10-6+deb10u10+tuxcare.els2">
          <filename>cups-server-common_2.2.10-6+deb10u10+tuxcare.els2_all.deb</filename>
          <sum type="sha">a47d1abbad56b0db668713209a221556dc502397</sum>
        </package>
        <package arch="amd64" name="libcups2" version="2.2.10-6+deb10u10+tuxcare.els2">
          <filename>libcups2_2.2.10-6+deb10u10+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">ee42e1f93684e835e66f50bf0b59f70d5758f944</sum>
        </package>
        <package arch="amd64" name="libcups2-dev" version="2.2.10-6+deb10u10+tuxcare.els2">
          <filename>libcups2-dev_2.2.10-6+deb10u10+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">aa16adbda5b7f6ca384599492198faee8958e34f</sum>
        </package>
        <package arch="amd64" name="libcupsimage2" version="2.2.10-6+deb10u10+tuxcare.els2">
          <filename>libcupsimage2_2.2.10-6+deb10u10+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">0566ef7f367e963b86d27d8beb85d22db303842d</sum>
        </package>
        <package arch="amd64" name="libcupsimage2-dev" version="2.2.10-6+deb10u10+tuxcare.els2">
          <filename>libcupsimage2-dev_2.2.10-6+deb10u10+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">6ee117f21ccbc75997363f3fc4fefe00f9dfa6f6</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1777386117</id>
    <title>Fix CVE(s): CVE-2026-33412</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Command injection via newline in glob() on Unix-like systems
     - debian/patches/CVE-2026-33412.patch: add '\n' to the SHELL_SPECIAL macro
       in src/os_unix.c so mch_expand_wildcards() escapes embedded newlines
       before passing the glob pattern to the shell
     - CVE-2026-33412</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Command injection via newline in glob() on Unix-like systems
     - debian/patches/CVE-2026-33412.patch: add '\n' to the SHELL_SPECIAL macro
       in src/os_unix.c so mch_expand_wildcards() escapes embedded newlines
       before passing the glob pattern to the shell
     - CVE-2026-33412</summary>
    <pushcount>0</pushcount>
    <issued date="2026-04-28 14:22:02 UTC" />
    <updated date="2026-04-28 14:22:02 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1777386117.html" id="CLSA-2026:1777386117" title="CLSA-2026:1777386117" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="vim" version="2:8.1.0875-5+deb10u6+tuxcare.els17">
          <filename>vim_8.1.0875-5+deb10u6+tuxcare.els17_amd64.deb</filename>
          <sum type="sha">1a5da2f714a7652a73050fa9eb59d54f6a095cac</sum>
        </package>
        <package arch="amd64" name="vim-athena" version="2:8.1.0875-5+deb10u6+tuxcare.els17">
          <filename>vim-athena_8.1.0875-5+deb10u6+tuxcare.els17_amd64.deb</filename>
          <sum type="sha">df20fb42069bf8d7696117b4ccc2d692a30533cf</sum>
        </package>
        <package arch="all" name="vim-common" version="2:8.1.0875-5+deb10u6+tuxcare.els17">
          <filename>vim-common_8.1.0875-5+deb10u6+tuxcare.els17_all.deb</filename>
          <sum type="sha">18b0ee4401cce351974e8f112ac110b83d89c9e2</sum>
        </package>
        <package arch="all" name="vim-doc" version="2:8.1.0875-5+deb10u6+tuxcare.els17">
          <filename>vim-doc_8.1.0875-5+deb10u6+tuxcare.els17_all.deb</filename>
          <sum type="sha">5aa46f1db5715eb10ac3c29d22481fd0c5ea5ae3</sum>
        </package>
        <package arch="amd64" name="vim-gtk" version="2:8.1.0875-5+deb10u6+tuxcare.els17">
          <filename>vim-gtk_8.1.0875-5+deb10u6+tuxcare.els17_amd64.deb</filename>
          <sum type="sha">628af394baaa5672756353acc6befdd6334bc5c8</sum>
        </package>
        <package arch="amd64" name="vim-gtk3" version="2:8.1.0875-5+deb10u6+tuxcare.els17">
          <filename>vim-gtk3_8.1.0875-5+deb10u6+tuxcare.els17_amd64.deb</filename>
          <sum type="sha">ff7f19ef3b1373f3c7002f51e91108cc5859e03a</sum>
        </package>
        <package arch="all" name="vim-gui-common" version="2:8.1.0875-5+deb10u6+tuxcare.els17">
          <filename>vim-gui-common_8.1.0875-5+deb10u6+tuxcare.els17_all.deb</filename>
          <sum type="sha">e5ac427ed71e785b4f4939adc3c7fcf8f253ab67</sum>
        </package>
        <package arch="amd64" name="vim-nox" version="2:8.1.0875-5+deb10u6+tuxcare.els17">
          <filename>vim-nox_8.1.0875-5+deb10u6+tuxcare.els17_amd64.deb</filename>
          <sum type="sha">9c385259a2523272d46a0fd2cde149a63d5ce605</sum>
        </package>
        <package arch="all" name="vim-runtime" version="2:8.1.0875-5+deb10u6+tuxcare.els17">
          <filename>vim-runtime_8.1.0875-5+deb10u6+tuxcare.els17_all.deb</filename>
          <sum type="sha">698fcc46d99b938254ba94398808512612ea55ec</sum>
        </package>
        <package arch="amd64" name="vim-tiny" version="2:8.1.0875-5+deb10u6+tuxcare.els17">
          <filename>vim-tiny_8.1.0875-5+deb10u6+tuxcare.els17_amd64.deb</filename>
          <sum type="sha">cdc693a920e98da30c5564a0be5dbb1499f7d40f</sum>
        </package>
        <package arch="amd64" name="xxd" version="2:8.1.0875-5+deb10u6+tuxcare.els17">
          <filename>xxd_8.1.0875-5+deb10u6+tuxcare.els17_amd64.deb</filename>
          <sum type="sha">e80ba34e6b96bffd4a755070dab6b1d5450c08a7</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1777456923</id>
    <title>Fix CVE(s): CVE-2026-32636</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix out-of-bounds write in ConvertUTF16ToUTF8 in NewXMLTree
     - debian/patches/CVE-2026-32636.patch: fix out-of-bounds write in ConvertUTF16ToUTF8 in NewXMLTree
     - CVE-2026-32636</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix out-of-bounds write in ConvertUTF16ToUTF8 in NewXMLTree
     - debian/patches/CVE-2026-32636.patch: fix out-of-bounds write in ConvertUTF16ToUTF8 in NewXMLTree
     - CVE-2026-32636</summary>
    <pushcount>0</pushcount>
    <issued date="2026-04-29 10:02:07 UTC" />
    <updated date="2026-04-29 10:02:07 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1777456923.html" id="CLSA-2026:1777456923" title="CLSA-2026:1777456923" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="imagemagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>imagemagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">c6cf3ce6280ca37e804c0d0fb995dab5167686f7</sum>
        </package>
        <package arch="all" name="imagemagick-6-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>imagemagick-6-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_all.deb</filename>
          <sum type="sha">d319c56b20b8ce9c22a1b793c014b4b6051a6873</sum>
        </package>
        <package arch="all" name="imagemagick-6-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>imagemagick-6-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_all.deb</filename>
          <sum type="sha">3d027644ae35810a89ebedde9f14e5b3fda5560a</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>imagemagick-6.q16_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">696716022a9238f8bb4e18d94b37ee64da99d7d0</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16hdri" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>imagemagick-6.q16hdri_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">c49c4aae62f5d47fa8690e7915311d26c3ad04fc</sum>
        </package>
        <package arch="all" name="imagemagick-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>imagemagick-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_all.deb</filename>
          <sum type="sha">5d330035795a016c3e36f87a790d010b79cbac67</sum>
        </package>
        <package arch="all" name="imagemagick-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>imagemagick-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_all.deb</filename>
          <sum type="sha">f2c7fbebdfc30f2ff1a9afe0e0d2a46edd559c39</sum>
        </package>
        <package arch="all" name="libimage-magick-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libimage-magick-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_all.deb</filename>
          <sum type="sha">cb0c6837ffc496268581783c2027345d65c78765</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libimage-magick-q16-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">5c0abaf10a39b5c0852058aad14bda083348dbed</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16hdri-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libimage-magick-q16hdri-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">daefc8a9fadf28f7454521511dc930c00c0bb245</sum>
        </package>
        <package arch="all" name="libmagick++-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libmagick++-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_all.deb</filename>
          <sum type="sha">9abc27b61cf32c4b66e41f2dba3f35b2536647c3</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libmagick++-6.q16-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">235cb6fb9b3dd86bdd0d944ee946ef518a604d87</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libmagick++-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">12e420db4b57693a406db0e9b81384338d6d6603</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libmagick++-6.q16hdri-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">80646b9d21d921b2b3adcb9513353b62703c2753</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libmagick++-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">0b93480c708abe756c7e240ef7bbbc47e8376545</sum>
        </package>
        <package arch="all" name="libmagick++-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libmagick++-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_all.deb</filename>
          <sum type="sha">02ed1d8b7d74d86075822cfb3cf2b9023371c24b</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6-arch-config" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libmagickcore-6-arch-config_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">dab5f89deec887542d8a52ee8e0c9b3204eaf9a9</sum>
        </package>
        <package arch="all" name="libmagickcore-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libmagickcore-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_all.deb</filename>
          <sum type="sha">e99d80a3948b939c63d03f63b8ec3b7f218b7d01</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libmagickcore-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">df3974c93edf5b15e7eab735f42696177145340c</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libmagickcore-6.q16-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">20ea8d4641495c6f440a32179c41038a33553253</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libmagickcore-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">dfb61d0dfa3ce24c594ad5d6b412db945f0e996d</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libmagickcore-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">e6a8dba92947753e29c613590e85589ede201c8f</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libmagickcore-6.q16hdri-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">021e33414dd005cfe718b26e8880e709ed456e95</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libmagickcore-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">9584da0d22d30de6ef40e407870adc8dbd536361</sum>
        </package>
        <package arch="all" name="libmagickcore-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libmagickcore-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_all.deb</filename>
          <sum type="sha">7ef20a25f90c64f4e396919227e8c1a3acf09e76</sum>
        </package>
        <package arch="all" name="libmagickwand-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libmagickwand-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_all.deb</filename>
          <sum type="sha">4e1f070808ffd305393802dadf8c551930111309</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libmagickwand-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">5100bed7efd83f2c16a48e5221a2cc2c60829c8d</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libmagickwand-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">4ddbc190197873ace7e15c4bc7d251ef63a946eb</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libmagickwand-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">d2f5de10e9264d4824ad11993e171bd5d426b3de</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libmagickwand-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">7bd10140652eccfe3ef9ffcc123e2f63e4bfa4a8</sum>
        </package>
        <package arch="all" name="libmagickwand-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>libmagickwand-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_all.deb</filename>
          <sum type="sha">08f1a3b7310ee69a6e8b6fdb151b81bd3fa023fe</sum>
        </package>
        <package arch="all" name="perlmagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5">
          <filename>perlmagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els5_all.deb</filename>
          <sum type="sha">09ace3d70a1be7d57817e4df3d71252ede388fd5</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1777480556</id>
    <title>Fix CVE(s): CVE-2025-69720</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: stack-based buffer overflow in infocmp
     - debian/patches/CVE-2025-69720.patch: add a bounds check on strlen(cp)
       in analyze_string() in progs/infocmp.c and grow buf2 by one byte so
       a maliciously long SGR parameter list can no longer overflow the
       stack buffer.
     - CVE-2025-69720</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: stack-based buffer overflow in infocmp
     - debian/patches/CVE-2025-69720.patch: add a bounds check on strlen(cp)
       in analyze_string() in progs/infocmp.c and grow buf2 by one byte so
       a maliciously long SGR parameter list can no longer overflow the
       stack buffer.
     - CVE-2025-69720</summary>
    <pushcount>0</pushcount>
    <issued date="2026-04-29 16:36:01 UTC" />
    <updated date="2026-04-29 16:36:01 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1777480556.html" id="CLSA-2026:1777480556" title="CLSA-2026:1777480556" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="lib32ncurses-dev" version="6.1+20181013-2+deb10u5+tuxcare.els1">
          <filename>lib32ncurses-dev_6.1+20181013-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">6a11cb327cb601d9b8398d9f719ef6600856444a</sum>
        </package>
        <package arch="amd64" name="lib32ncurses6" version="6.1+20181013-2+deb10u5+tuxcare.els1">
          <filename>lib32ncurses6_6.1+20181013-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">3b8a20433bb0593b1e949c519d37d15ee9d5b55b</sum>
        </package>
        <package arch="amd64" name="lib32ncursesw6" version="6.1+20181013-2+deb10u5+tuxcare.els1">
          <filename>lib32ncursesw6_6.1+20181013-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">c2c02c76d8f345a2b9b88955259e68bb7f88f421</sum>
        </package>
        <package arch="amd64" name="lib32tinfo6" version="6.1+20181013-2+deb10u5+tuxcare.els1">
          <filename>lib32tinfo6_6.1+20181013-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">cdaea2b2dfafea938f9e7d2ad3b19aacaa34fe08</sum>
        </package>
        <package arch="amd64" name="libncurses-dev" version="6.1+20181013-2+deb10u5+tuxcare.els1">
          <filename>libncurses-dev_6.1+20181013-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">88bc88c9860514b7ee4d37dbbfbb852b91f5cf4e</sum>
        </package>
        <package arch="amd64" name="libncurses5" version="6.1+20181013-2+deb10u5+tuxcare.els1">
          <filename>libncurses5_6.1+20181013-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">ab7e879a693cbeb0a36ef86b7f0d4ac3147e1bdc</sum>
        </package>
        <package arch="amd64" name="libncurses5-dev" version="6.1+20181013-2+deb10u5+tuxcare.els1">
          <filename>libncurses5-dev_6.1+20181013-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">da2bac4349653e44f2efd58dee6fc15566f4c43c</sum>
        </package>
        <package arch="amd64" name="libncurses6" version="6.1+20181013-2+deb10u5+tuxcare.els1">
          <filename>libncurses6_6.1+20181013-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">d6b99dbe5c3beb344fcc1dc2bb88e7b79d6b9ae2</sum>
        </package>
        <package arch="amd64" name="libncursesw5" version="6.1+20181013-2+deb10u5+tuxcare.els1">
          <filename>libncursesw5_6.1+20181013-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">55a1b31e8688317d9ca6e88552f2c7629a51ee34</sum>
        </package>
        <package arch="amd64" name="libncursesw5-dev" version="6.1+20181013-2+deb10u5+tuxcare.els1">
          <filename>libncursesw5-dev_6.1+20181013-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">833db48d938164c1af70d9f124d8a9e27ad7923f</sum>
        </package>
        <package arch="amd64" name="libncursesw6" version="6.1+20181013-2+deb10u5+tuxcare.els1">
          <filename>libncursesw6_6.1+20181013-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">e9f17f2664ae43b7d0041a65b317a572f8406a75</sum>
        </package>
        <package arch="amd64" name="libtinfo-dev" version="6.1+20181013-2+deb10u5+tuxcare.els1">
          <filename>libtinfo-dev_6.1+20181013-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">bc9170a617c1135ae1a850f19686f6f738b4bf0c</sum>
        </package>
        <package arch="amd64" name="libtinfo5" version="6.1+20181013-2+deb10u5+tuxcare.els1">
          <filename>libtinfo5_6.1+20181013-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">da9874dad984a922098fcd7d802e18c06b43a7d2</sum>
        </package>
        <package arch="amd64" name="libtinfo6" version="6.1+20181013-2+deb10u5+tuxcare.els1">
          <filename>libtinfo6_6.1+20181013-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">4e79aacea6493af17974dc0efa08c9aa7dba5bed</sum>
        </package>
        <package arch="all" name="ncurses-base" version="6.1+20181013-2+deb10u5+tuxcare.els1">
          <filename>ncurses-base_6.1+20181013-2+deb10u5+tuxcare.els1_all.deb</filename>
          <sum type="sha">9c38d596e91e8b3410444c9f5500d690b1ed0a4b</sum>
        </package>
        <package arch="amd64" name="ncurses-bin" version="6.1+20181013-2+deb10u5+tuxcare.els1">
          <filename>ncurses-bin_6.1+20181013-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">6ba29b6029525b2551b5f1bbe840c154d8feb0d0</sum>
        </package>
        <package arch="all" name="ncurses-doc" version="6.1+20181013-2+deb10u5+tuxcare.els1">
          <filename>ncurses-doc_6.1+20181013-2+deb10u5+tuxcare.els1_all.deb</filename>
          <sum type="sha">959ca4c3fbd91d6c0805cdcf5f931510579758de</sum>
        </package>
        <package arch="amd64" name="ncurses-examples" version="6.1+20181013-2+deb10u5+tuxcare.els1">
          <filename>ncurses-examples_6.1+20181013-2+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">8b26ec8621657a294f4436db70d4e9bf2d8a30f7</sum>
        </package>
        <package arch="all" name="ncurses-term" version="6.1+20181013-2+deb10u5+tuxcare.els1">
          <filename>ncurses-term_6.1+20181013-2+deb10u5+tuxcare.els1_all.deb</filename>
          <sum type="sha">c6d705a2db22a669fd17741eb4f900aa85e6cf7a</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1777466211</id>
    <title>Fix CVE(s): CVE-2025-7545</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: heap-based buffer overflow in copy_section function
     - debian/patches/CVE-2025-7545.patch: Prevent output section size from
       being extended beyond the input section size to avoid heap-based buffer
       overflow when copying sections with interleaving
     - CVE-2025-7545</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: heap-based buffer overflow in copy_section function
     - debian/patches/CVE-2025-7545.patch: Prevent output section size from
       being extended beyond the input section size to avoid heap-based buffer
       overflow when copying sections with interleaving
     - CVE-2025-7545</summary>
    <pushcount>0</pushcount>
    <issued date="2026-04-29 16:42:03 UTC" />
    <updated date="2026-04-29 16:42:03 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1777466211.html" id="CLSA-2026:1777466211" title="CLSA-2026:1777466211" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="binutils" version="2.31.1-16+tuxcare.els11">
          <filename>binutils_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">df35e1a9d0b2a4197f94367b43034d1c9b4df140</sum>
        </package>
        <package arch="amd64" name="binutils-aarch64-linux-gnu" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-aarch64-linux-gnu_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">cdeaf58fdefed7c5c100905b6b6ce4a7f9eb739f</sum>
        </package>
        <package arch="amd64" name="binutils-alpha-linux-gnu" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-alpha-linux-gnu_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">31672a95cd4f601447917d81fdf1698be6a85502</sum>
        </package>
        <package arch="amd64" name="binutils-arm-linux-gnueabi" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-arm-linux-gnueabi_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">1b023985183cd3b9d489b5097a70ed918212383c</sum>
        </package>
        <package arch="amd64" name="binutils-arm-linux-gnueabihf" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-arm-linux-gnueabihf_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">352a7790733f60d7babd0ccf32f1b18c01313b8e</sum>
        </package>
        <package arch="amd64" name="binutils-common" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-common_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">190addb4fc7d6b49e6e336c476e7faff9f9fce6c</sum>
        </package>
        <package arch="amd64" name="binutils-dev" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-dev_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">8c6acc75687da4e6776ed75e77b8b44a48ea1bc0</sum>
        </package>
        <package arch="all" name="binutils-doc" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-doc_2.31.1-16+tuxcare.els11_all.deb</filename>
          <sum type="sha">32a59156b56d272cb1a422b8b21dcd29349466b9</sum>
        </package>
        <package arch="all" name="binutils-for-build" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-for-build_2.31.1-16+tuxcare.els11_all.deb</filename>
          <sum type="sha">849c31053991c32c9f3717ac466f7fbb5cdf039d</sum>
        </package>
        <package arch="amd64" name="binutils-for-host" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-for-host_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">daf99af15c0de7139f6ceb1322dabb67db9361d8</sum>
        </package>
        <package arch="amd64" name="binutils-hppa-linux-gnu" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-hppa-linux-gnu_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">55090119349d8650225d3d3cb25bbdee20527bd0</sum>
        </package>
        <package arch="amd64" name="binutils-hppa64-linux-gnu" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-hppa64-linux-gnu_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">a30786a1f7deaa7c9ae5ea82d4eacf763f50a8d2</sum>
        </package>
        <package arch="amd64" name="binutils-i686-gnu" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-i686-gnu_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">b00e1bdc5968ee77eda1dca1f1505d3657552136</sum>
        </package>
        <package arch="amd64" name="binutils-i686-kfreebsd-gnu" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-i686-kfreebsd-gnu_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">dd953d62ca1f0cacdf9355c26ae00a5d9f8e3e23</sum>
        </package>
        <package arch="amd64" name="binutils-i686-linux-gnu" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-i686-linux-gnu_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">f579f4310c11d600ac2c6640581de0007dadf24d</sum>
        </package>
        <package arch="amd64" name="binutils-ia64-linux-gnu" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-ia64-linux-gnu_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">f08599a575b19722e07361ca736d39302ced5775</sum>
        </package>
        <package arch="amd64" name="binutils-m68k-linux-gnu" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-m68k-linux-gnu_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">67a55a87f9ff1c4e729d928319f4e20b3ce833a6</sum>
        </package>
        <package arch="amd64" name="binutils-mips-linux-gnu" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-mips-linux-gnu_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">ab8f07ab08f0e86c6d1268150d004c87cebdce87</sum>
        </package>
        <package arch="amd64" name="binutils-mips64el-linux-gnuabi64" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-mips64el-linux-gnuabi64_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">3b58dbb5dbef340554cd4ba93084d63996bfa9d3</sum>
        </package>
        <package arch="amd64" name="binutils-mipsel-linux-gnu" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-mipsel-linux-gnu_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">7ca8cc59d3bbdc6b165e22804d28ac9d3c010c3d</sum>
        </package>
        <package arch="amd64" name="binutils-multiarch" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-multiarch_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">0aa949dd13bce2e14be57a4cdf30eb09632f16e7</sum>
        </package>
        <package arch="amd64" name="binutils-multiarch-dev" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-multiarch-dev_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">07d4d6a3fa6f869da7350843ce824ffbded162fa</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc-linux-gnu" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-powerpc-linux-gnu_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">22d79b6fe669517c7a23d4fbefe643c99e5cd848</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc-linux-gnuspe" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-powerpc-linux-gnuspe_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">67ec66fa3c74e836a21c4e857dbe1c2b25bd2b19</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc64-linux-gnu" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-powerpc64-linux-gnu_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">7d537f0da3204056f2d1941d1618e5538bea2ff1</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc64le-linux-gnu" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-powerpc64le-linux-gnu_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">2f19b0d95eeaf4e3e46853ccb350a84eac09d090</sum>
        </package>
        <package arch="amd64" name="binutils-riscv64-linux-gnu" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-riscv64-linux-gnu_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">bc36186c6c54217c8710d812be37952965b97346</sum>
        </package>
        <package arch="amd64" name="binutils-s390x-linux-gnu" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-s390x-linux-gnu_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">7b1dc5bd9a873605ba4bfc3f842371d504ec12d3</sum>
        </package>
        <package arch="amd64" name="binutils-sh4-linux-gnu" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-sh4-linux-gnu_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">e88bf3fc798017bb36ca5f1fd1b23def662d016b</sum>
        </package>
        <package arch="all" name="binutils-source" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-source_2.31.1-16+tuxcare.els11_all.deb</filename>
          <sum type="sha">c1096bd47536c2308a4dad1f3002301d1e428d18</sum>
        </package>
        <package arch="amd64" name="binutils-sparc64-linux-gnu" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-sparc64-linux-gnu_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">4ac59efe804644de0353e77e9ee94e641910caac</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-kfreebsd-gnu" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-x86-64-kfreebsd-gnu_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">8bdcb5476a1f976243353a04c07c862e27047509</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-linux-gnu" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-x86-64-linux-gnu_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">9d7664d99b0ba778d969d12dacb657ba6e20376d</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-linux-gnux32" version="2.31.1-16+tuxcare.els11">
          <filename>binutils-x86-64-linux-gnux32_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">cf7e1b16e9746985d4d565ea1aab554c1054b751</sum>
        </package>
        <package arch="amd64" name="libbinutils" version="2.31.1-16+tuxcare.els11">
          <filename>libbinutils_2.31.1-16+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">0294284b16de576c174638ed78f6a28cad0a74ad</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1777542570</id>
    <title>Fix of 5 CVEs</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix heap-based buffer overflow in VIFF coder
     - debian/patches/CVE-2026-33900.patch: fix heap-based buffer overflow in VIFF coder
     - CVE-2026-33900
   * SECURITY UPDATE: fix heap-based buffer overflow in SampleImage
     - debian/patches/CVE-2026-33905.patch: fix heap-based buffer overflow in SampleImage
     - CVE-2026-33905
   * SECURITY UPDATE: fix integer overflow in DespeckleImage
     - debian/patches/CVE-2026-34238.patch: fix integer overflow in DespeckleImage
     - CVE-2026-34238
   * SECURITY UPDATE: fix heap out-of-bounds write in JP2 coder
     - debian/patches/CVE-2026-40310.patch: fix heap out-of-bounds write in JP2 coder
     - CVE-2026-40310
   * SECURITY UPDATE: fix vulnerability in GetXMPProperty
     - debian/patches/CVE-2026-40311.patch: fix vulnerability in GetXMPProperty
     - CVE-2026-40311</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix heap-based buffer overflow in VIFF coder
     - debian/patches/CVE-2026-33900.patch: fix heap-based buffer overflow in VIFF coder
     - CVE-2026-33900
   * SECURITY UPDATE: fix heap-based buffer overflow in SampleImage
     - debian/patches/CVE-2026-33905.patch: fix heap-based buffer overflow in SampleImage
     - CVE-2026-33905
   * SECURITY UPDATE: fix integer overflow in DespeckleImage
     - debian/patches/CVE-2026-34238.patch: fix integer overflow in DespeckleImage
     - CVE-2026-34238
   * SECURITY UPDATE: fix heap out-of-bounds write in JP2 coder
     - debian/patches/CVE-2026-40310.patch: fix heap out-of-bounds write in JP2 coder
     - CVE-2026-40310
   * SECURITY UPDATE: fix vulnerability in GetXMPProperty
     - debian/patches/CVE-2026-40311.patch: fix vulnerability in GetXMPProperty
     - CVE-2026-40311</summary>
    <pushcount>0</pushcount>
    <issued date="2026-04-30 09:49:34 UTC" />
    <updated date="2026-04-30 09:49:34 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1777542570.html" id="CLSA-2026:1777542570" title="CLSA-2026:1777542570" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="imagemagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>imagemagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">a1205351b6a61df989ff73a1c925efdf6021bf3a</sum>
        </package>
        <package arch="all" name="imagemagick-6-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>imagemagick-6-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_all.deb</filename>
          <sum type="sha">07bb55fd582b02300775186d8daaddfa89ff9c7a</sum>
        </package>
        <package arch="all" name="imagemagick-6-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>imagemagick-6-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_all.deb</filename>
          <sum type="sha">e830fe68f7c2191c018243b515684b7772f19ff0</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>imagemagick-6.q16_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">4e72f5af075ea77bd84fd5f4e49233c11feabed8</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16hdri" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>imagemagick-6.q16hdri_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">d1ea61f8ef868483625cf227f79735ae50eb403c</sum>
        </package>
        <package arch="all" name="imagemagick-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>imagemagick-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_all.deb</filename>
          <sum type="sha">0076cfdc68d07d5feb7a786bd678aacf2b78bc6e</sum>
        </package>
        <package arch="all" name="imagemagick-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>imagemagick-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_all.deb</filename>
          <sum type="sha">94532c5375538a891b94fa653f2aa6859cf2b2ab</sum>
        </package>
        <package arch="all" name="libimage-magick-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libimage-magick-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_all.deb</filename>
          <sum type="sha">f52787f0498938582372969eea041a080146378a</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libimage-magick-q16-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">8d2c450682e14bf218169877ff762febc27a5a17</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16hdri-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libimage-magick-q16hdri-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">399946aacbb299ca78649652ba0f1785a738eece</sum>
        </package>
        <package arch="all" name="libmagick++-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libmagick++-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_all.deb</filename>
          <sum type="sha">aa82333b14b78a85b7e852e5c91dc60920d99939</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libmagick++-6.q16-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">49da32b2f6db0b085fa0e6c0819d6056a1c6a05e</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libmagick++-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">8b85301e51db5d675128715d92c3f401ca61a8fd</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libmagick++-6.q16hdri-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">6b6bb06a7f2a209f11cdd7de81f8a956f0a53f35</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libmagick++-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">c90a9d2540358e6366c50fa8d9c6b16db5ca910f</sum>
        </package>
        <package arch="all" name="libmagick++-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libmagick++-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_all.deb</filename>
          <sum type="sha">4bc3ce4a83bbe8366d43f97311cfb0afa55cafec</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6-arch-config" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libmagickcore-6-arch-config_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">bc5c84c52d7f01c47748efa24edb3bc64dc4ea8e</sum>
        </package>
        <package arch="all" name="libmagickcore-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libmagickcore-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_all.deb</filename>
          <sum type="sha">ddb7229a010f15afb97ef87f278a44735244a8f8</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libmagickcore-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">28c1600e20684f44fb4321f470fd6288f9acb220</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libmagickcore-6.q16-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">292617fd9cd8b1cc6857fe4e0721779c05b4570a</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libmagickcore-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">620a1b24927e2f1e28d8ae4bdf1875df8db70226</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libmagickcore-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">55aedded9e344b6547ee706a9b239f2d064b07db</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libmagickcore-6.q16hdri-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">0f5c2910f46161037036e49c78f7cf8bdd195c99</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libmagickcore-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">e07f41e2cca3c6a0a79566c830cc48536f7eb9d3</sum>
        </package>
        <package arch="all" name="libmagickcore-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libmagickcore-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_all.deb</filename>
          <sum type="sha">6ad2a1ccd82c68dd9a8a2dff658157bb64f68862</sum>
        </package>
        <package arch="all" name="libmagickwand-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libmagickwand-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_all.deb</filename>
          <sum type="sha">803a5aa1bc3f4f4074073851b2ec64238842175d</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libmagickwand-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">c870a8647b8ba00ecd796cf46e689e3d796a6c71</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libmagickwand-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">fefc74afa705c6cec6253db3254f4c1f16e9f93c</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libmagickwand-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">8c0180fb1144fcf307a5acca826912a7a532f714</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libmagickwand-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">d4fb59d87abeba0eb944cd61619dc59e2410293d</sum>
        </package>
        <package arch="all" name="libmagickwand-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>libmagickwand-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_all.deb</filename>
          <sum type="sha">bf6b2582f62529f16ea94cad47b1b764d4cd4289</sum>
        </package>
        <package arch="all" name="perlmagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6">
          <filename>perlmagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els6_all.deb</filename>
          <sum type="sha">f6b8dfd0e8500dbaf7074297eb1dfca5b8d4eb84</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1777545539</id>
    <title>Fix of 6 CVEs</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix quadratic complexity in http cookie parsing with backslash escapes
     - debian/patches/CVE-2024-7592.patch: fix quadratic complexity in http cookie parsing with backslash escapes
     - CVE-2024-7592
   * SECURITY UPDATE: reject leading dashes in webbrowser URLs and %action substitution bypass
     - debian/patches/CVE-2026-4519.patch: reject leading dashes in webbrowser URLs and %action substitution bypass
     - CVE-2026-4519
   * SECURITY UPDATE: fix quadratic complexity in os.path.expandvars()
     - debian/patches/CVE-2025-6075.patch: fix quadratic complexity in os.path.expandvars()
     - CVE-2025-6075
   * SECURITY UPDATE: remove quadratic behavior in xml.dom.minidom node id-cache clearing
     - debian/patches/CVE-2025-12084.patch: remove quadratic behavior in xml.dom.minidom node id-cache clearing
     - CVE-2025-12084
   * SECURITY UPDATE: remove backtracking when parsing tarfile PAX headers
     - debian/patches/CVE-2024-6232.patch: remove backtracking when parsing tarfile PAX headers
     - CVE-2024-6232
   * SECURITY UPDATE: reject malformed addresses in email.utils.parseaddr / getaddresses
     - debian/patches/CVE-2023-27043.patch: reject malformed addresses in email.utils.parseaddr / getaddresses
     - CVE-2023-27043</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix quadratic complexity in http cookie parsing with backslash escapes
     - debian/patches/CVE-2024-7592.patch: fix quadratic complexity in http cookie parsing with backslash escapes
     - CVE-2024-7592
   * SECURITY UPDATE: reject leading dashes in webbrowser URLs and %action substitution bypass
     - debian/patches/CVE-2026-4519.patch: reject leading dashes in webbrowser URLs and %action substitution bypass
     - CVE-2026-4519
   * SECURITY UPDATE: fix quadratic complexity in os.path.expandvars()
     - debian/patches/CVE-2025-6075.patch: fix quadratic complexity in os.path.expandvars()
     - CVE-2025-6075
   * SECURITY UPDATE: remove quadratic behavior in xml.dom.minidom node id-cache clearing
     - debian/patches/CVE-2025-12084.patch: remove quadratic behavior in xml.dom.minidom node id-cache clearing
     - CVE-2025-12084
   * SECURITY UPDATE: remove backtracking when parsing tarfile PAX headers
     - debian/patches/CVE-2024-6232.patch: remove backtracking when parsing tarfile PAX headers
     - CVE-2024-6232
   * SECURITY UPDATE: reject malformed addresses in email.utils.parseaddr / getaddresses
     - debian/patches/CVE-2023-27043.patch: reject malformed addresses in email.utils.parseaddr / getaddresses
     - CVE-2023-27043</summary>
    <pushcount>0</pushcount>
    <issued date="2026-04-30 10:39:04 UTC" />
    <updated date="2026-04-30 10:39:04 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1777545539.html" id="CLSA-2026:1777545539" title="CLSA-2026:1777545539" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="all" name="idle-python2.7" version="2.7.16-2+deb10u4+tuxcare.els1">
          <filename>idle-python2.7_2.7.16-2+deb10u4+tuxcare.els1_all.deb</filename>
          <sum type="sha">a8bae23e0b15efc835c27e1b7b72d4d7f2c8e643</sum>
        </package>
        <package arch="amd64" name="libpython2.7" version="2.7.16-2+deb10u4+tuxcare.els1">
          <filename>libpython2.7_2.7.16-2+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">ccddbe25c23706a9ff4fc981554e0494882a3ad9</sum>
        </package>
        <package arch="amd64" name="libpython2.7-dev" version="2.7.16-2+deb10u4+tuxcare.els1">
          <filename>libpython2.7-dev_2.7.16-2+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">43edc154a2a975f80f4beadec7195551d149d388</sum>
        </package>
        <package arch="amd64" name="libpython2.7-minimal" version="2.7.16-2+deb10u4+tuxcare.els1">
          <filename>libpython2.7-minimal_2.7.16-2+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">35cc20f1e5741ed73a674f9a4221a97400b326c4</sum>
        </package>
        <package arch="amd64" name="libpython2.7-stdlib" version="2.7.16-2+deb10u4+tuxcare.els1">
          <filename>libpython2.7-stdlib_2.7.16-2+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">2c14c6f02c61816ad14801820f94854abdedb357</sum>
        </package>
        <package arch="all" name="libpython2.7-testsuite" version="2.7.16-2+deb10u4+tuxcare.els1">
          <filename>libpython2.7-testsuite_2.7.16-2+deb10u4+tuxcare.els1_all.deb</filename>
          <sum type="sha">c0c178d86978fe2063fa35fa8b273124a00680fd</sum>
        </package>
        <package arch="amd64" name="python2.7" version="2.7.16-2+deb10u4+tuxcare.els1">
          <filename>python2.7_2.7.16-2+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">269fad094eb34c9f0a124aebd18a19db7b11b939</sum>
        </package>
        <package arch="amd64" name="python2.7-dev" version="2.7.16-2+deb10u4+tuxcare.els1">
          <filename>python2.7-dev_2.7.16-2+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">05a35e9375e97bda84bf00eba279da867841c315</sum>
        </package>
        <package arch="all" name="python2.7-doc" version="2.7.16-2+deb10u4+tuxcare.els1">
          <filename>python2.7-doc_2.7.16-2+deb10u4+tuxcare.els1_all.deb</filename>
          <sum type="sha">500b1b9201cd6012e10c6eae6b5420da86d47508</sum>
        </package>
        <package arch="all" name="python2.7-examples" version="2.7.16-2+deb10u4+tuxcare.els1">
          <filename>python2.7-examples_2.7.16-2+deb10u4+tuxcare.els1_all.deb</filename>
          <sum type="sha">dae7d3f5ec4a4fbe2dc1d08aa3ee8ce47b56b5a4</sum>
        </package>
        <package arch="amd64" name="python2.7-minimal" version="2.7.16-2+deb10u4+tuxcare.els1">
          <filename>python2.7-minimal_2.7.16-2+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">fa9416c4a4a8e2e65d3dd278c41ade5246a8a5d3</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1777586245</id>
    <title>Fix CVE(s): CVE-2026-35385</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: scp(1) downloading as root in legacy mode without -p
     did not clear setuid/setgid bits on downloaded files.
     - debian/patches/CVE-2026-35385.patch: clear setuid/setgid bits from
       umask in sink() when -p is not set
     - CVE-2026-35385</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: scp(1) downloading as root in legacy mode without -p
     did not clear setuid/setgid bits on downloaded files.
     - debian/patches/CVE-2026-35385.patch: clear setuid/setgid bits from
       umask in sink() when -p is not set
     - CVE-2026-35385</summary>
    <pushcount>0</pushcount>
    <issued date="2026-04-30 21:57:30 UTC" />
    <updated date="2026-04-30 21:57:30 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1777586245.html" id="CLSA-2026:1777586245" title="CLSA-2026:1777586245" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="openssh-client" version="1:7.9p1-10+deb10u4+tuxcare.els3">
          <filename>openssh-client_7.9p1-10+deb10u4+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">c6ea4da595402d5dc17a07750b61000c0fd39acf</sum>
        </package>
        <package arch="amd64" name="openssh-server" version="1:7.9p1-10+deb10u4+tuxcare.els3">
          <filename>openssh-server_7.9p1-10+deb10u4+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">e05ca345de386401865c97f55a36dbccc476d7cf</sum>
        </package>
        <package arch="amd64" name="openssh-sftp-server" version="1:7.9p1-10+deb10u4+tuxcare.els3">
          <filename>openssh-sftp-server_7.9p1-10+deb10u4+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">08bed9560d0db98c241e34e4d4296ce3e4deab8f</sum>
        </package>
        <package arch="amd64" name="openssh-tests" version="1:7.9p1-10+deb10u4+tuxcare.els3">
          <filename>openssh-tests_7.9p1-10+deb10u4+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">211377b425bf7f922397a551c0d222d1e42604bf</sum>
        </package>
        <package arch="all" name="ssh" version="1:7.9p1-10+deb10u4+tuxcare.els3">
          <filename>ssh_7.9p1-10+deb10u4+tuxcare.els3_all.deb</filename>
          <sum type="sha">65c3e406e9f5962247ee066b11fff177fa8ce180</sum>
        </package>
        <package arch="amd64" name="ssh-askpass-gnome" version="1:7.9p1-10+deb10u4+tuxcare.els3">
          <filename>ssh-askpass-gnome_7.9p1-10+deb10u4+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">71674ed17c1b7cfcf9c343c4483848bba34336c4</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1776179858</id>
    <title>Fix of 5 CVEs</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix vulnerability in MSL coder
     - debian/patches/CVE-2026-25988.patch: fix vulnerability in MSL coder
     - CVE-2026-25988
   * SECURITY UPDATE: fix path traversal via policy bypass
     - debian/patches/CVE-2026-25965.patch: fix path traversal via policy bypass
     - CVE-2026-25965
   * SECURITY UPDATE: fix vulnerability in PNG coder
     - debian/patches/CVE-2026-30883.patch: fix vulnerability in PNG coder
     - CVE-2026-30883
   * SECURITY UPDATE: fix NULL pointer dereference in MSL parser
     - debian/patches/CVE-2026-23952.patch: fix NULL pointer dereference in MSL parser
     - CVE-2026-23952
   * SECURITY UPDATE: fix vulnerability in sixel coder
     - debian/patches/CVE-2026-25970.patch: fix vulnerability in sixel coder
     - CVE-2026-25970</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix vulnerability in MSL coder
     - debian/patches/CVE-2026-25988.patch: fix vulnerability in MSL coder
     - CVE-2026-25988
   * SECURITY UPDATE: fix path traversal via policy bypass
     - debian/patches/CVE-2026-25965.patch: fix path traversal via policy bypass
     - CVE-2026-25965
   * SECURITY UPDATE: fix vulnerability in PNG coder
     - debian/patches/CVE-2026-30883.patch: fix vulnerability in PNG coder
     - CVE-2026-30883
   * SECURITY UPDATE: fix NULL pointer dereference in MSL parser
     - debian/patches/CVE-2026-23952.patch: fix NULL pointer dereference in MSL parser
     - CVE-2026-23952
   * SECURITY UPDATE: fix vulnerability in sixel coder
     - debian/patches/CVE-2026-25970.patch: fix vulnerability in sixel coder
     - CVE-2026-25970</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-01 08:01:50 UTC" />
    <updated date="2026-05-01 08:01:50 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1776179858.html" id="CLSA-2026:1776179858" title="CLSA-2026:1776179858" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="imagemagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>imagemagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">b2d4de062f13d4cedb680c3dc749929f84ebbfba</sum>
        </package>
        <package arch="all" name="imagemagick-6-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>imagemagick-6-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_all.deb</filename>
          <sum type="sha">0186f235afad0b7104044af969be0ef0b5d37522</sum>
        </package>
        <package arch="all" name="imagemagick-6-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>imagemagick-6-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_all.deb</filename>
          <sum type="sha">f6e2121dea6f13aaaa7c5c39de1f7bb44ea868b9</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>imagemagick-6.q16_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">38d4c9e253e4f35f8455a8b3619da5a47d02f9e5</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16hdri" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>imagemagick-6.q16hdri_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">8806f61d10dc7ae975d0cd54d55eee4c797f79a8</sum>
        </package>
        <package arch="all" name="imagemagick-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>imagemagick-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_all.deb</filename>
          <sum type="sha">6cb97fe996c5a6d9010c6cd0cf29c8770be0c109</sum>
        </package>
        <package arch="all" name="imagemagick-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>imagemagick-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_all.deb</filename>
          <sum type="sha">13a7f5040418bfc030a9e7ecc598551b3a76b149</sum>
        </package>
        <package arch="all" name="libimage-magick-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libimage-magick-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_all.deb</filename>
          <sum type="sha">e6714d18ac19579436e97fbaa99ae7d90f475ddc</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libimage-magick-q16-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">cf04f3d47c7bc17320b488ec8cbb9696f075cd1f</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16hdri-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libimage-magick-q16hdri-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">927eead59a135943fd4114d2267872732da2db75</sum>
        </package>
        <package arch="all" name="libmagick++-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libmagick++-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_all.deb</filename>
          <sum type="sha">c5a29bd533ca8ca607a76d5f4919925d8e798c8e</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libmagick++-6.q16-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">aa73c7d261792d70c8a4a8e055562c6e2b7b134e</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libmagick++-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">23e75cbe6d1c20b47e9a3b829e27d83146f5b9de</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libmagick++-6.q16hdri-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">9a3349daac1171cf892c21ba1dc663cbddcc44b0</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libmagick++-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">3286b1e0d4798b8cad667bcb3a80731621e5a856</sum>
        </package>
        <package arch="all" name="libmagick++-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libmagick++-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_all.deb</filename>
          <sum type="sha">e078c5d646930ab4760be91a5bba5d946edf5af9</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6-arch-config" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libmagickcore-6-arch-config_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">3e554c3ecc93e04b6bf0e2428df6c6276c4d01fc</sum>
        </package>
        <package arch="all" name="libmagickcore-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libmagickcore-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_all.deb</filename>
          <sum type="sha">4e85f50c55a46a429b767479db7ea50d29a5b30f</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libmagickcore-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">3548c32efeba6ede5fc623a252b505064e5c50e6</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libmagickcore-6.q16-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">4cddab54fd7aef79729df8fe4ac827d7dfa783e4</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libmagickcore-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">793ca913afd7a5b02bbf77cd82b002962f134930</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libmagickcore-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">6f4b4d0e86e4550afeabc2651b93b89deea8a10f</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libmagickcore-6.q16hdri-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">4e51cc130c9b6df7e5b77c57642b0313d3f68e42</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libmagickcore-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">04e54abbf7035dc45193c900c454d357e1269f72</sum>
        </package>
        <package arch="all" name="libmagickcore-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libmagickcore-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_all.deb</filename>
          <sum type="sha">764bdd4ee4b92185092758f7128ae26065daa9e3</sum>
        </package>
        <package arch="all" name="libmagickwand-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libmagickwand-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_all.deb</filename>
          <sum type="sha">e74ccfb2d5b97abc3cd2d320d8d8e5eda5d20081</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libmagickwand-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">f1c96e48eead510ce8ff20ca2237ffb64b5cefe6</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libmagickwand-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">b90ef1923bb418e64a127d24945af76f96de8c28</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libmagickwand-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">65569d86a33e8f663174c3233969ea8fc954029a</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libmagickwand-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">e2b1eb7ed7168095db8d501b4e7bbfdf9c3c75fb</sum>
        </package>
        <package arch="all" name="libmagickwand-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>libmagickwand-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_all.deb</filename>
          <sum type="sha">9ea70c6352a237bb9a3b93136eaaf96638004391</sum>
        </package>
        <package arch="all" name="perlmagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4">
          <filename>perlmagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els4_all.deb</filename>
          <sum type="sha">48144a0ee7d5b97acb9d38953fada41d0db4a141</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1777942049</id>
    <title>Fix CVE(s): CVE-2026-39881</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix command injection in netbeans interface via defineAnnoType (validate typeName/fg/bg/specialKeys)
     - debian/patches/CVE-2026-39881.patch: fix command injection in netbeans interface via defineAnnoType (validate typeName/fg/bg/specialKeys)
     - CVE-2026-39881</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix command injection in netbeans interface via defineAnnoType (validate typeName/fg/bg/specialKeys)
     - debian/patches/CVE-2026-39881.patch: fix command injection in netbeans interface via defineAnnoType (validate typeName/fg/bg/specialKeys)
     - CVE-2026-39881</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-05 00:47:38 UTC" />
    <updated date="2026-05-05 00:47:38 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1777942049.html" id="CLSA-2026:1777942049" title="CLSA-2026:1777942049" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="vim" version="2:8.1.0875-5+deb10u6+tuxcare.els18">
          <filename>vim_8.1.0875-5+deb10u6+tuxcare.els18_amd64.deb</filename>
          <sum type="sha">8c299ce9abee19ccc6a3d4e6e6a92f315d5f48fe</sum>
        </package>
        <package arch="amd64" name="vim-athena" version="2:8.1.0875-5+deb10u6+tuxcare.els18">
          <filename>vim-athena_8.1.0875-5+deb10u6+tuxcare.els18_amd64.deb</filename>
          <sum type="sha">add1e782cea42689274ab5bc60c300b96278cec4</sum>
        </package>
        <package arch="all" name="vim-common" version="2:8.1.0875-5+deb10u6+tuxcare.els18">
          <filename>vim-common_8.1.0875-5+deb10u6+tuxcare.els18_all.deb</filename>
          <sum type="sha">78ef595785fe33f1672b6e963c269a5696c787d3</sum>
        </package>
        <package arch="all" name="vim-doc" version="2:8.1.0875-5+deb10u6+tuxcare.els18">
          <filename>vim-doc_8.1.0875-5+deb10u6+tuxcare.els18_all.deb</filename>
          <sum type="sha">af986edcadc1bb44feaa9eb6a4cbaa120a40a6b2</sum>
        </package>
        <package arch="amd64" name="vim-gtk" version="2:8.1.0875-5+deb10u6+tuxcare.els18">
          <filename>vim-gtk_8.1.0875-5+deb10u6+tuxcare.els18_amd64.deb</filename>
          <sum type="sha">0b8d268e72cd0d5452d7ea35592ea3244772aea9</sum>
        </package>
        <package arch="amd64" name="vim-gtk3" version="2:8.1.0875-5+deb10u6+tuxcare.els18">
          <filename>vim-gtk3_8.1.0875-5+deb10u6+tuxcare.els18_amd64.deb</filename>
          <sum type="sha">97872efec2121405a2c27c8ac0d0ab42847bb738</sum>
        </package>
        <package arch="all" name="vim-gui-common" version="2:8.1.0875-5+deb10u6+tuxcare.els18">
          <filename>vim-gui-common_8.1.0875-5+deb10u6+tuxcare.els18_all.deb</filename>
          <sum type="sha">d9cd3cee57baacaeb83db1d4ece6c2db0c1a2a82</sum>
        </package>
        <package arch="amd64" name="vim-nox" version="2:8.1.0875-5+deb10u6+tuxcare.els18">
          <filename>vim-nox_8.1.0875-5+deb10u6+tuxcare.els18_amd64.deb</filename>
          <sum type="sha">23482bc2c6fd387085a8b7cd22a1ae9bd44c4901</sum>
        </package>
        <package arch="all" name="vim-runtime" version="2:8.1.0875-5+deb10u6+tuxcare.els18">
          <filename>vim-runtime_8.1.0875-5+deb10u6+tuxcare.els18_all.deb</filename>
          <sum type="sha">415c6f9d27e1f2c940bb80fd0ae6df6761011d92</sum>
        </package>
        <package arch="amd64" name="vim-tiny" version="2:8.1.0875-5+deb10u6+tuxcare.els18">
          <filename>vim-tiny_8.1.0875-5+deb10u6+tuxcare.els18_amd64.deb</filename>
          <sum type="sha">d96ba51071a3ab0766e9a59852ce2d5e46b43555</sum>
        </package>
        <package arch="amd64" name="xxd" version="2:8.1.0875-5+deb10u6+tuxcare.els18">
          <filename>xxd_8.1.0875-5+deb10u6+tuxcare.els18_amd64.deb</filename>
          <sum type="sha">ec59b0a2cd44028722fc02104f621eeac13cb8cf</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1777947165</id>
    <title>Fix CVE(s): CVE-2026-35414</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: authorized_keys principals="" option mismatches
     certificate principals containing comma characters.
     - debian/patches/CVE-2026-35414.patch: rewrite match_principals_option
       to split principal_list with strsep() and compare with strcmp().
     - CVE-2026-35414</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: authorized_keys principals="" option mismatches
     certificate principals containing comma characters.
     - debian/patches/CVE-2026-35414.patch: rewrite match_principals_option
       to split principal_list with strsep() and compare with strcmp().
     - CVE-2026-35414</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-05 02:12:52 UTC" />
    <updated date="2026-05-05 02:12:52 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1777947165.html" id="CLSA-2026:1777947165" title="CLSA-2026:1777947165" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="openssh-client" version="1:7.9p1-10+deb10u4+tuxcare.els4">
          <filename>openssh-client_7.9p1-10+deb10u4+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">ee1f3ed0a89c30d418fd6448d8797bd0bc37707b</sum>
        </package>
        <package arch="amd64" name="openssh-server" version="1:7.9p1-10+deb10u4+tuxcare.els4">
          <filename>openssh-server_7.9p1-10+deb10u4+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">389c2da8b68379dfcbd6280e5096bfbd75d9ac6a</sum>
        </package>
        <package arch="amd64" name="openssh-sftp-server" version="1:7.9p1-10+deb10u4+tuxcare.els4">
          <filename>openssh-sftp-server_7.9p1-10+deb10u4+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">e21f9d817630955ff509889c49a202cf64a21e7a</sum>
        </package>
        <package arch="amd64" name="openssh-tests" version="1:7.9p1-10+deb10u4+tuxcare.els4">
          <filename>openssh-tests_7.9p1-10+deb10u4+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">e08346cada0697cddc27484f02ef8ea1fbdf88ee</sum>
        </package>
        <package arch="all" name="ssh" version="1:7.9p1-10+deb10u4+tuxcare.els4">
          <filename>ssh_7.9p1-10+deb10u4+tuxcare.els4_all.deb</filename>
          <sum type="sha">99e17951c297433bff05b83a04b4704aab248839</sum>
        </package>
        <package arch="amd64" name="ssh-askpass-gnome" version="1:7.9p1-10+deb10u4+tuxcare.els4">
          <filename>ssh-askpass-gnome_7.9p1-10+deb10u4+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">8f4ac84f812d18476f601d52cd57855ed45362d7</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1777947331</id>
    <title>Fix CVE(s): CVE-2023-35945</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: HTTP/2 memory leak in nghttp2 codec
     - debian/patches/CVE-2023-35945.patch: fix memory leak in
       nghttp2_session_mem_send_internal when stream close callback fails
       with a fatal error
     - CVE-2023-35945</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: HTTP/2 memory leak in nghttp2 codec
     - debian/patches/CVE-2023-35945.patch: fix memory leak in
       nghttp2_session_mem_send_internal when stream close callback fails
       with a fatal error
     - CVE-2023-35945</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-05 02:15:38 UTC" />
    <updated date="2026-05-05 02:15:38 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1777947331.html" id="CLSA-2026:1777947331" title="CLSA-2026:1777947331" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libnghttp2-14" version="1.36.0-2+deb10u3+tuxcare.els1">
          <filename>libnghttp2-14_1.36.0-2+deb10u3+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">26165acb17ad208146a15de73aa6598a63307b3d</sum>
        </package>
        <package arch="amd64" name="libnghttp2-dev" version="1.36.0-2+deb10u3+tuxcare.els1">
          <filename>libnghttp2-dev_1.36.0-2+deb10u3+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">7c24af79ba3021ed634c36ec12cda26acb768721</sum>
        </package>
        <package arch="all" name="libnghttp2-doc" version="1.36.0-2+deb10u3+tuxcare.els1">
          <filename>libnghttp2-doc_1.36.0-2+deb10u3+tuxcare.els1_all.deb</filename>
          <sum type="sha">4aba50494955c658ff882ad6ae506d2d5221f355</sum>
        </package>
        <package arch="all" name="nghttp2" version="1.36.0-2+deb10u3+tuxcare.els1">
          <filename>nghttp2_1.36.0-2+deb10u3+tuxcare.els1_all.deb</filename>
          <sum type="sha">8fb39b8797198f307ea30b53f8c74c874182116a</sum>
        </package>
        <package arch="amd64" name="nghttp2-client" version="1.36.0-2+deb10u3+tuxcare.els1">
          <filename>nghttp2-client_1.36.0-2+deb10u3+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">8985c12ca40f903c034812dcea1ed0662deb00a1</sum>
        </package>
        <package arch="amd64" name="nghttp2-proxy" version="1.36.0-2+deb10u3+tuxcare.els1">
          <filename>nghttp2-proxy_1.36.0-2+deb10u3+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">dd83d5cbdbba81ff02a340d2cb55efc8d5c16a82</sum>
        </package>
        <package arch="amd64" name="nghttp2-server" version="1.36.0-2+deb10u3+tuxcare.els1">
          <filename>nghttp2-server_1.36.0-2+deb10u3+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">0ac875effd276d1be49074ea8f0eef333d0ed095</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1777999127</id>
    <title>Fix CVE(s): CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix UAF/double-free in DANE client by using X509_free() for dane-&gt;mcert
     - debian/patches/CVE-2026-28387.patch: fix UAF/double-free in DANE client by using X509_free() for dane-&gt;mcert
     - CVE-2026-28387
   * SECURITY UPDATE: NULL check delta-&gt;crl_number before ASN1_INTEGER_cmp() in check_delta_base()
     - debian/patches/CVE-2026-28388.patch: NULL check delta-&gt;crl_number before ASN1_INTEGER_cmp() in check_delta_base()
     - CVE-2026-28388
   * SECURITY UPDATE: NULL check alg-&gt;parameter in [ec]dh_cms_set_shared_info() before deref
     - debian/patches/CVE-2026-28389.patch: NULL check alg-&gt;parameter in [ec]dh_cms_set_shared_info() before deref
     - CVE-2026-28389
   * SECURITY UPDATE: NULL check plab-&gt;parameter in rsa_cms_decrypt() before deref
     - debian/patches/CVE-2026-28390.patch: NULL check plab-&gt;parameter in rsa_cms_decrypt() before deref
     - CVE-2026-28390</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix UAF/double-free in DANE client by using X509_free() for dane-&gt;mcert
     - debian/patches/CVE-2026-28387.patch: fix UAF/double-free in DANE client by using X509_free() for dane-&gt;mcert
     - CVE-2026-28387
   * SECURITY UPDATE: NULL check delta-&gt;crl_number before ASN1_INTEGER_cmp() in check_delta_base()
     - debian/patches/CVE-2026-28388.patch: NULL check delta-&gt;crl_number before ASN1_INTEGER_cmp() in check_delta_base()
     - CVE-2026-28388
   * SECURITY UPDATE: NULL check alg-&gt;parameter in [ec]dh_cms_set_shared_info() before deref
     - debian/patches/CVE-2026-28389.patch: NULL check alg-&gt;parameter in [ec]dh_cms_set_shared_info() before deref
     - CVE-2026-28389
   * SECURITY UPDATE: NULL check plab-&gt;parameter in rsa_cms_decrypt() before deref
     - debian/patches/CVE-2026-28390.patch: NULL check plab-&gt;parameter in rsa_cms_decrypt() before deref
     - CVE-2026-28390</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-05 16:38:52 UTC" />
    <updated date="2026-05-05 16:38:52 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1777999127.html" id="CLSA-2026:1777999127" title="CLSA-2026:1777999127" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libssl-dev" version="1.1.1n-0+deb10u6+tuxcare.els3">
          <filename>libssl-dev_1.1.1n-0+deb10u6+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">db86c301f154350458561e025b2748b55be67966</sum>
        </package>
        <package arch="all" name="libssl-doc" version="1.1.1n-0+deb10u6+tuxcare.els3">
          <filename>libssl-doc_1.1.1n-0+deb10u6+tuxcare.els3_all.deb</filename>
          <sum type="sha">71414008f001048a82aee2aa5c3260e942d6d7f8</sum>
        </package>
        <package arch="amd64" name="libssl1.1" version="1.1.1n-0+deb10u6+tuxcare.els3">
          <filename>libssl1.1_1.1.1n-0+deb10u6+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">4ac9ecda82651fcdb00983c30e490aa9346393a1</sum>
        </package>
        <package arch="amd64" name="openssl" version="1.1.1n-0+deb10u6+tuxcare.els3">
          <filename>openssl_1.1.1n-0+deb10u6+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">95a673dfdc836df7c8f5c611e77f352b8b6d8af2</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1778107205</id>
    <title>Fix CVE(s): CVE-2026-23918</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: double free / possible RCE in mod_http2 stream purge
     - debian/patches/CVE-2026-23918.patch: deduplicate inserts into the
       spurge array in modules/http2/h2_mplx.c via a new add_for_purge()
       helper to prevent the same h2_stream from being freed twice.
     - CVE-2026-23918</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: double free / possible RCE in mod_http2 stream purge
     - debian/patches/CVE-2026-23918.patch: deduplicate inserts into the
       spurge array in modules/http2/h2_mplx.c via a new add_for_purge()
       helper to prevent the same h2_stream from being freed twice.
     - CVE-2026-23918</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-06 22:40:15 UTC" />
    <updated date="2026-05-06 22:40:15 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1778107205.html" id="CLSA-2026:1778107205" title="CLSA-2026:1778107205" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="apache2" version="2.4.59-1~deb10u1+tuxcare.els4">
          <filename>apache2_2.4.59-1~deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">7cc3c377a164f7878812b88069f0f601d2b8d466</sum>
        </package>
        <package arch="amd64" name="apache2-bin" version="2.4.59-1~deb10u1+tuxcare.els4">
          <filename>apache2-bin_2.4.59-1~deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">db3fd8266ee32f605432e751469633db2138b8e3</sum>
        </package>
        <package arch="all" name="apache2-data" version="2.4.59-1~deb10u1+tuxcare.els4">
          <filename>apache2-data_2.4.59-1~deb10u1+tuxcare.els4_all.deb</filename>
          <sum type="sha">80d46bbbfac67926ec0eca290b9e1df12789dc37</sum>
        </package>
        <package arch="amd64" name="apache2-dev" version="2.4.59-1~deb10u1+tuxcare.els4">
          <filename>apache2-dev_2.4.59-1~deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">6d2992163a21ec040124f9f72ee9c4f822ba7344</sum>
        </package>
        <package arch="all" name="apache2-doc" version="2.4.59-1~deb10u1+tuxcare.els4">
          <filename>apache2-doc_2.4.59-1~deb10u1+tuxcare.els4_all.deb</filename>
          <sum type="sha">745f9b8718a3e058bbdea73ceae586f700925568</sum>
        </package>
        <package arch="amd64" name="apache2-ssl-dev" version="2.4.59-1~deb10u1+tuxcare.els4">
          <filename>apache2-ssl-dev_2.4.59-1~deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">b7f648377007a74759d2ffa0ad8ef8214ed94324</sum>
        </package>
        <package arch="amd64" name="apache2-suexec-custom" version="2.4.59-1~deb10u1+tuxcare.els4">
          <filename>apache2-suexec-custom_2.4.59-1~deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">b7b185ad2f8f7ef5f805c9e8dbcd6b0dcbc96821</sum>
        </package>
        <package arch="amd64" name="apache2-suexec-pristine" version="2.4.59-1~deb10u1+tuxcare.els4">
          <filename>apache2-suexec-pristine_2.4.59-1~deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">cc9fefd9ce7e7439befeff8692bdd9ffb830fdfd</sum>
        </package>
        <package arch="amd64" name="apache2-utils" version="2.4.59-1~deb10u1+tuxcare.els4">
          <filename>apache2-utils_2.4.59-1~deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">161e6bd9b19c04f323fa41a5ce84452496796e11</sum>
        </package>
        <package arch="amd64" name="libapache2-mod-md" version="2.4.59-1~deb10u1+tuxcare.els4">
          <filename>libapache2-mod-md_2.4.59-1~deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">4f88154f5bae41d9a20a43f5e2ed59bab0b25cb3</sum>
        </package>
        <package arch="amd64" name="libapache2-mod-proxy-uwsgi" version="2.4.59-1~deb10u1+tuxcare.els4">
          <filename>libapache2-mod-proxy-uwsgi_2.4.59-1~deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">4e62c8f2fc9f3fe74a6d3b2b58cd9c4ba890e6a6</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1778253061</id>
    <title>Fix CVE(s): CVE-2026-27447</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix authorization bypass in cupsd caused by
     case-insensitive comparison of local user and group names.
     - debian/patches/CVE-2026-27447.patch: compare usernames against the
       canonical pw_name from getpwnam() with strcmp() in
       cupsdCheckGroup() and cupsdIsAuthorized() in scheduler/auth.c;
       include the upstream follow-up "Fix unauthenticated print policies"
       (Issue #1557) so CUPSD_AUTH_NONE policies still match users that
       do not have a local account.
     - CVE-2026-27447.</description>
    <severity>Moderate</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix authorization bypass in cupsd caused by
     case-insensitive comparison of local user and group names.
     - debian/patches/CVE-2026-27447.patch: compare usernames against the
       canonical pw_name from getpwnam() with strcmp() in
       cupsdCheckGroup() and cupsdIsAuthorized() in scheduler/auth.c;
       include the upstream follow-up "Fix unauthenticated print policies"
       (Issue #1557) so CUPSD_AUTH_NONE policies still match users that
       do not have a local account.
     - CVE-2026-27447.</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-08 15:13:47 UTC" />
    <updated date="2026-05-08 15:13:47 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1778253061.html" id="CLSA-2026:1778253061" title="CLSA-2026:1778253061" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="cups" version="2.2.10-6+deb10u10+tuxcare.els3">
          <filename>cups_2.2.10-6+deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">860ba24feee1b5fb6858d973a027e001e1ee6a55</sum>
        </package>
        <package arch="amd64" name="cups-bsd" version="2.2.10-6+deb10u10+tuxcare.els3">
          <filename>cups-bsd_2.2.10-6+deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">ddd456f8c5438a422069a6367f05b45ed1d91a18</sum>
        </package>
        <package arch="amd64" name="cups-client" version="2.2.10-6+deb10u10+tuxcare.els3">
          <filename>cups-client_2.2.10-6+deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">c5e956d283b7ac7cb0addd70f0987cc3d706ccf6</sum>
        </package>
        <package arch="all" name="cups-common" version="2.2.10-6+deb10u10+tuxcare.els3">
          <filename>cups-common_2.2.10-6+deb10u10+tuxcare.els3_all.deb</filename>
          <sum type="sha">1e7689d85222554f396a3b68766fb708a25e6e8f</sum>
        </package>
        <package arch="amd64" name="cups-core-drivers" version="2.2.10-6+deb10u10+tuxcare.els3">
          <filename>cups-core-drivers_2.2.10-6+deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">ee26e6536f87bde0ef8efbd195fae1c2250fef7e</sum>
        </package>
        <package arch="amd64" name="cups-daemon" version="2.2.10-6+deb10u10+tuxcare.els3">
          <filename>cups-daemon_2.2.10-6+deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">c9307f48019c7f94f7aa973cda9f4b149727e681</sum>
        </package>
        <package arch="amd64" name="cups-ipp-utils" version="2.2.10-6+deb10u10+tuxcare.els3">
          <filename>cups-ipp-utils_2.2.10-6+deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">d466b0bab207034c4cb612c7297a3d0d9a2d2419</sum>
        </package>
        <package arch="amd64" name="cups-ppdc" version="2.2.10-6+deb10u10+tuxcare.els3">
          <filename>cups-ppdc_2.2.10-6+deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">d47f3b940e930e7a83540e312ecc8fe7462b9031</sum>
        </package>
        <package arch="all" name="cups-server-common" version="2.2.10-6+deb10u10+tuxcare.els3">
          <filename>cups-server-common_2.2.10-6+deb10u10+tuxcare.els3_all.deb</filename>
          <sum type="sha">0ec2f6411d8ee177a30ce60f3377cf40c3548835</sum>
        </package>
        <package arch="amd64" name="libcups2" version="2.2.10-6+deb10u10+tuxcare.els3">
          <filename>libcups2_2.2.10-6+deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">17a43ddc83b35f07cbd4f73379845db4a53c4e95</sum>
        </package>
        <package arch="amd64" name="libcups2-dev" version="2.2.10-6+deb10u10+tuxcare.els3">
          <filename>libcups2-dev_2.2.10-6+deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">9027023c857c0712512db280e68f9e3d46487d83</sum>
        </package>
        <package arch="amd64" name="libcupsimage2" version="2.2.10-6+deb10u10+tuxcare.els3">
          <filename>libcupsimage2_2.2.10-6+deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">eba45c5b36d2ec56472c364fe6e13676c05d64aa</sum>
        </package>
        <package arch="amd64" name="libcupsimage2-dev" version="2.2.10-6+deb10u10+tuxcare.els3">
          <filename>libcupsimage2-dev_2.2.10-6+deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">3eab3fa0e345c95e53815f2093bfc9429f734d36</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1778674192</id>
    <title>Fix CVE(s): CVE-2026-3441, CVE-2026-3442</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: heap-based OOB read in xcoff_link_add_symbols
     (bfd/xcofflink.c) triggered by a crafted XCOFF object file
     - debian/patches/binutils-CVE-2026-3441-3442.patch: bounds-check
       XTY_LD x_scnlen csect index and sanity-check r_symndx before
       indexing sym_hashes
     - CVE-2026-3441
     - CVE-2026-3442</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: heap-based OOB read in xcoff_link_add_symbols
     (bfd/xcofflink.c) triggered by a crafted XCOFF object file
     - debian/patches/binutils-CVE-2026-3441-3442.patch: bounds-check
       XTY_LD x_scnlen csect index and sanity-check r_symndx before
       indexing sym_hashes
     - CVE-2026-3441
     - CVE-2026-3442</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-13 12:09:58 UTC" />
    <updated date="2026-05-13 12:09:58 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1778674192.html" id="CLSA-2026:1778674192" title="CLSA-2026:1778674192" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="binutils" version="2.31.1-16+tuxcare.els12">
          <filename>binutils_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">0e20b75b7df17e723f99582a9021f204b75f52c4</sum>
        </package>
        <package arch="amd64" name="binutils-aarch64-linux-gnu" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-aarch64-linux-gnu_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">e0dab955dac425f9e3e720e8b7356556165d5eae</sum>
        </package>
        <package arch="amd64" name="binutils-alpha-linux-gnu" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-alpha-linux-gnu_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">16e889df59bf53d2e03b43a5a4e9d0b4520de77c</sum>
        </package>
        <package arch="amd64" name="binutils-arm-linux-gnueabi" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-arm-linux-gnueabi_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">5d26653b72ff820d98b3bdd129c604b7ff3ab610</sum>
        </package>
        <package arch="amd64" name="binutils-arm-linux-gnueabihf" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-arm-linux-gnueabihf_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">5737184de6c9617c4b2cd7ab285729e987ef3958</sum>
        </package>
        <package arch="amd64" name="binutils-common" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-common_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">8452e41adcd24ef3cb69af64bb1f47e64edaf0b9</sum>
        </package>
        <package arch="amd64" name="binutils-dev" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-dev_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">e5cf3954ab64ded33f0e37c1ea6a12670dd78494</sum>
        </package>
        <package arch="all" name="binutils-doc" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-doc_2.31.1-16+tuxcare.els12_all.deb</filename>
          <sum type="sha">8b287105e2946503bb341ce09c18ba020c2083fb</sum>
        </package>
        <package arch="all" name="binutils-for-build" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-for-build_2.31.1-16+tuxcare.els12_all.deb</filename>
          <sum type="sha">c47b16cb2d7d26a5ea7eae177c4fb4ac69990d44</sum>
        </package>
        <package arch="amd64" name="binutils-for-host" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-for-host_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">6d93417966cd5b98e31140db87cb325ca5bbadc6</sum>
        </package>
        <package arch="amd64" name="binutils-hppa-linux-gnu" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-hppa-linux-gnu_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">70f4c9635327faaa23f94239af9df95b05af0dcf</sum>
        </package>
        <package arch="amd64" name="binutils-hppa64-linux-gnu" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-hppa64-linux-gnu_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">067b7ea775b78d71ab59ed94dbcb4fc5751523f2</sum>
        </package>
        <package arch="amd64" name="binutils-i686-gnu" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-i686-gnu_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">5fc3b484b407009fb1e5e221162150dae9d8b758</sum>
        </package>
        <package arch="amd64" name="binutils-i686-kfreebsd-gnu" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-i686-kfreebsd-gnu_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">f80cbae78baba32ade4f4b48ee6d3ef771a63b7d</sum>
        </package>
        <package arch="amd64" name="binutils-i686-linux-gnu" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-i686-linux-gnu_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">c97c01b52ae72ccc86fdb51b58ea5520dde3808f</sum>
        </package>
        <package arch="amd64" name="binutils-ia64-linux-gnu" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-ia64-linux-gnu_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">d1032e5f7247389991c37247c406d28e9271d93c</sum>
        </package>
        <package arch="amd64" name="binutils-m68k-linux-gnu" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-m68k-linux-gnu_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">1426c2dc6e153454d2b8de9cf4a26603fe098475</sum>
        </package>
        <package arch="amd64" name="binutils-mips-linux-gnu" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-mips-linux-gnu_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">606b4d4e06d91ce325e618ffa03d26005db91813</sum>
        </package>
        <package arch="amd64" name="binutils-mips64el-linux-gnuabi64" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-mips64el-linux-gnuabi64_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">35868841d2e8e9884d9f48195acd4fcd0ed47b44</sum>
        </package>
        <package arch="amd64" name="binutils-mipsel-linux-gnu" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-mipsel-linux-gnu_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">7bae4383d668bc2bf7fa8dee182e732239a451dd</sum>
        </package>
        <package arch="amd64" name="binutils-multiarch" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-multiarch_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">928454ba23848f7b9069e1f62920365d4460b5d3</sum>
        </package>
        <package arch="amd64" name="binutils-multiarch-dev" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-multiarch-dev_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">0ed62b1830b28b990f196df4eedb532dc89388e0</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc-linux-gnu" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-powerpc-linux-gnu_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">28a9cc04ec5d49e9c48fdbd7de4787b6fdc5706a</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc-linux-gnuspe" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-powerpc-linux-gnuspe_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">ab4835d59cdd2661ed03b920dce613722e7db71c</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc64-linux-gnu" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-powerpc64-linux-gnu_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">fe3ddfe088425303acd40303637ab64586be5df2</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc64le-linux-gnu" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-powerpc64le-linux-gnu_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">050b51d9e13d8607e4b9cf14d93583bdab44abe0</sum>
        </package>
        <package arch="amd64" name="binutils-riscv64-linux-gnu" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-riscv64-linux-gnu_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">69d1ec2dc9ce87d6e8324b4e2bc8af12bf22eaa2</sum>
        </package>
        <package arch="amd64" name="binutils-s390x-linux-gnu" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-s390x-linux-gnu_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">5bb58a2226c5bd076c68cc907a8eae2e0d9fe123</sum>
        </package>
        <package arch="amd64" name="binutils-sh4-linux-gnu" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-sh4-linux-gnu_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">176e1ac3335ebb1b02454d4ff08076dcfaa600e8</sum>
        </package>
        <package arch="all" name="binutils-source" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-source_2.31.1-16+tuxcare.els12_all.deb</filename>
          <sum type="sha">f2eb6a2bf60fcb48d8ce1aa54efb151e34196ede</sum>
        </package>
        <package arch="amd64" name="binutils-sparc64-linux-gnu" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-sparc64-linux-gnu_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">8de049de5572811ce1ecdd31e0a3186ebdbd113b</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-kfreebsd-gnu" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-x86-64-kfreebsd-gnu_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">ca807661f5ab50c15c340f393a50e07303087719</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-linux-gnu" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-x86-64-linux-gnu_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">db217610efda27be403cb8ba8a2934ab58d01730</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-linux-gnux32" version="2.31.1-16+tuxcare.els12">
          <filename>binutils-x86-64-linux-gnux32_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">cea2fea44c6dacc9528ed9b6bc5bfcd10e9c0a3d</sum>
        </package>
        <package arch="amd64" name="libbinutils" version="2.31.1-16+tuxcare.els12">
          <filename>libbinutils_2.31.1-16+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">8689350ddd566588d0b76ee46cc46701fa17272f</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1778869454</id>
    <title>Fix CVE(s): CVE-2026-42945</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Heap buffer overflow in ngx_http_rewrite_module via
     PCRE unnamed captures with question mark in replacement strings
     - debian/patches/CVE-2026-42945.patch: clear e-&gt;is_args in
       ngx_http_script_regex_end_code to prevent buffer overrun when
       rewrite directive is followed by set or if with PCRE captures
     - CVE-2026-42945</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Heap buffer overflow in ngx_http_rewrite_module via
     PCRE unnamed captures with question mark in replacement strings
     - debian/patches/CVE-2026-42945.patch: clear e-&gt;is_args in
       ngx_http_script_regex_end_code to prevent buffer overrun when
       rewrite directive is followed by set or if with PCRE captures
     - CVE-2026-42945</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-15 18:24:19 UTC" />
    <updated date="2026-05-15 18:24:19 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1778869454.html" id="CLSA-2026:1778869454" title="CLSA-2026:1778869454" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libnginx-mod-http-auth-pam" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>libnginx-mod-http-auth-pam_1.14.2-2+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">8ab8029281e1a14b560a74641fe0519f3fdb600b</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-cache-purge" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>libnginx-mod-http-cache-purge_1.14.2-2+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">14b40450d8eef77cad3417e06bd6e1fe9fe6a252</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-dav-ext" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>libnginx-mod-http-dav-ext_1.14.2-2+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">3a005db180a59da0fe44b976bf3be00bb4cac40d</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-echo" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>libnginx-mod-http-echo_1.14.2-2+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">09da7e6601227cba90b7a19ebc8b5bf014cf7841</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-fancyindex" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>libnginx-mod-http-fancyindex_1.14.2-2+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">bbabc97dd17f458616885de443e3c9a92eec07be</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-geoip" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>libnginx-mod-http-geoip_1.14.2-2+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">faa860136951e3f62b79764c77a8c9490175a4bb</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-headers-more-filter" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>libnginx-mod-http-headers-more-filter_1.14.2-2+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">19335db88900b439c45319c2b4b45a771ff00d4a</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-image-filter" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>libnginx-mod-http-image-filter_1.14.2-2+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">a28eae7aaef117ebfb2871271d32b17ab496c6f3</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-lua" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>libnginx-mod-http-lua_1.14.2-2+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">1159c25dec7e25a098e2cab3ff8fe1e085b52278</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-ndk" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>libnginx-mod-http-ndk_1.14.2-2+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">1ebaead18f43dbe0d642d2af782f7b13880d85a0</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-perl" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>libnginx-mod-http-perl_1.14.2-2+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">eedbe33174e681ac807ed73c861a89b9d4bc2161</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-subs-filter" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>libnginx-mod-http-subs-filter_1.14.2-2+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">561a6c42004fee0344e6ea8bb6c6ef6207c1f903</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-uploadprogress" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>libnginx-mod-http-uploadprogress_1.14.2-2+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">3af0d7d824475913437eaff3ae318fa60fe3cdd3</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-upstream-fair" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>libnginx-mod-http-upstream-fair_1.14.2-2+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">dc4f74ef6670c9c5d63c731a2e63960e7c36d429</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-xslt-filter" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>libnginx-mod-http-xslt-filter_1.14.2-2+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">c22948650f186b914669e8fd4d8c6a3da63ef902</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-mail" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>libnginx-mod-mail_1.14.2-2+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">a32a0b8dbee43319013fb75caacd5644adfeb1ce</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-nchan" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>libnginx-mod-nchan_1.14.2-2+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">91eac31b40e73c94665f6efa18275aef0ba8bf9b</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-rtmp" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>libnginx-mod-rtmp_1.14.2-2+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">9a77e2113cb8fcd7a5c0d555cc6c27945cb24710</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-stream" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>libnginx-mod-stream_1.14.2-2+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">be9defaef87b06c041c8f111326b0615e76c6d9b</sum>
        </package>
        <package arch="all" name="nginx" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>nginx_1.14.2-2+deb10u5+tuxcare.els2_all.deb</filename>
          <sum type="sha">c19342b33f359c8396c3ca2d1c8564c7db0433b6</sum>
        </package>
        <package arch="all" name="nginx-common" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>nginx-common_1.14.2-2+deb10u5+tuxcare.els2_all.deb</filename>
          <sum type="sha">eeb6e7c65416d84a544ccdb56b139395a8e97e84</sum>
        </package>
        <package arch="all" name="nginx-doc" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>nginx-doc_1.14.2-2+deb10u5+tuxcare.els2_all.deb</filename>
          <sum type="sha">239af36148d6b04fc9314814591afdbb04fe9e1a</sum>
        </package>
        <package arch="amd64" name="nginx-extras" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>nginx-extras_1.14.2-2+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">a098faf263568857b1541215d5a170a2be7d9616</sum>
        </package>
        <package arch="amd64" name="nginx-full" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>nginx-full_1.14.2-2+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">fbd199c317b494945d3a6d06083a589691864645</sum>
        </package>
        <package arch="amd64" name="nginx-light" version="1.14.2-2+deb10u5+tuxcare.els2">
          <filename>nginx-light_1.14.2-2+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">b97038dc083428d94ea685b8edf7e4dd0774e43d</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1778895199</id>
    <title>Fix CVE(s): CVE-2024-50602</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Crash in XML_ResumeParser because XML_StopParser
     can stop/suspend an unstarted parser
     - debian/patches/CVE-2024-50602.patch: make XML_StopParser refuse
       to stop/suspend an unstarted parser
     - CVE-2024-50602</description>
    <severity>Moderate</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Crash in XML_ResumeParser because XML_StopParser
     can stop/suspend an unstarted parser
     - debian/patches/CVE-2024-50602.patch: make XML_StopParser refuse
       to stop/suspend an unstarted parser
     - CVE-2024-50602</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-16 01:33:24 UTC" />
    <updated date="2026-05-16 01:33:24 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1778895199.html" id="CLSA-2026:1778895199" title="CLSA-2026:1778895199" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="expat" version="2.2.6-2+deb10u7+tuxcare.els4">
          <filename>expat_2.2.6-2+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">65630011908a3b567f136a512ddb2dfde37bda23</sum>
        </package>
        <package arch="amd64" name="libexpat1" version="2.2.6-2+deb10u7+tuxcare.els4">
          <filename>libexpat1_2.2.6-2+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">84a82fc1028935e52e3db8ffd6e6ad2908392112</sum>
        </package>
        <package arch="amd64" name="libexpat1-dev" version="2.2.6-2+deb10u7+tuxcare.els4">
          <filename>libexpat1-dev_2.2.6-2+deb10u7+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">b9ccd946e536c0f318fdd1d0f07ee77b86a998a7</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1778895374</id>
    <title>Fix CVE(s): CVE-2026-7598</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Fix integer overflow in userauth_password username_len/password_len bounds checks
     - debian/patches/CVE-2026-7598.patch: Fix integer overflow in userauth_password username_len/password_len bounds checks
     - CVE-2026-7598</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Fix integer overflow in userauth_password username_len/password_len bounds checks
     - debian/patches/CVE-2026-7598.patch: Fix integer overflow in userauth_password username_len/password_len bounds checks
     - CVE-2026-7598</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-16 01:36:18 UTC" />
    <updated date="2026-05-16 01:36:18 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1778895374.html" id="CLSA-2026:1778895374" title="CLSA-2026:1778895374" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libssh2-1" version="1.8.0-2.1+deb10u1+tuxcare.els1">
          <filename>libssh2-1_1.8.0-2.1+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">da43273c92ed1b33b183b0346f8b74175a7a9d89</sum>
        </package>
        <package arch="amd64" name="libssh2-1-dev" version="1.8.0-2.1+deb10u1+tuxcare.els1">
          <filename>libssh2-1-dev_1.8.0-2.1+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">fd7be5c3e7d3285c4fb6086e544c7aae970a5627</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1778938383</id>
    <title>Fix CVE(s): CVE-2026-43964</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Fix buffer over-read in DSN code parsing (dsn_split)
     - debian/patches/CVE-2026-43964.patch: Fix buffer over-read in DSN code parsing (dsn_split)
     - CVE-2026-43964</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Fix buffer over-read in DSN code parsing (dsn_split)
     - debian/patches/CVE-2026-43964.patch: Fix buffer over-read in DSN code parsing (dsn_split)
     - CVE-2026-43964</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-16 14:47:27 UTC" />
    <updated date="2026-05-16 14:47:27 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1778938383.html" id="CLSA-2026:1778938383" title="CLSA-2026:1778938383" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="postfix" version="3.4.23-0+deb10u2+tuxcare.els1">
          <filename>postfix_3.4.23-0+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">3e5397536508e3514bfe220dbf45d06e267b2ecb</sum>
        </package>
        <package arch="amd64" name="postfix-cdb" version="3.4.23-0+deb10u2+tuxcare.els1">
          <filename>postfix-cdb_3.4.23-0+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">fdb53f71a649480d7cdb72528c4bf81bc933c4d7</sum>
        </package>
        <package arch="all" name="postfix-doc" version="3.4.23-0+deb10u2+tuxcare.els1">
          <filename>postfix-doc_3.4.23-0+deb10u2+tuxcare.els1_all.deb</filename>
          <sum type="sha">654f55c4d1485a88c9995253435ae3a7a635e664</sum>
        </package>
        <package arch="amd64" name="postfix-ldap" version="3.4.23-0+deb10u2+tuxcare.els1">
          <filename>postfix-ldap_3.4.23-0+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">912c69928fdb328998f2e625f08e5076e4fc2bac</sum>
        </package>
        <package arch="amd64" name="postfix-lmdb" version="3.4.23-0+deb10u2+tuxcare.els1">
          <filename>postfix-lmdb_3.4.23-0+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">b92a8b6bbad916803c10a7f85ec1cc9ac7f00ab5</sum>
        </package>
        <package arch="amd64" name="postfix-mysql" version="3.4.23-0+deb10u2+tuxcare.els1">
          <filename>postfix-mysql_3.4.23-0+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">e2de83827d469a2f082b25ae32e08be712276da4</sum>
        </package>
        <package arch="amd64" name="postfix-pcre" version="3.4.23-0+deb10u2+tuxcare.els1">
          <filename>postfix-pcre_3.4.23-0+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">7f3b0ea60591c7587640f5f39ee2cf63a04872d6</sum>
        </package>
        <package arch="amd64" name="postfix-pgsql" version="3.4.23-0+deb10u2+tuxcare.els1">
          <filename>postfix-pgsql_3.4.23-0+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">ad3887327068d125767bcc10b2c55cb1aee515de</sum>
        </package>
        <package arch="amd64" name="postfix-sqlite" version="3.4.23-0+deb10u2+tuxcare.els1">
          <filename>postfix-sqlite_3.4.23-0+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">b62164af451e56d2bd2456d93899c27541649cfb</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1778943258</id>
    <title>Fix CVE(s): CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: SOAP use-after-free with SOAP_PERSISTENCE_SESSION
     - debian/patches/CVE-2026-7261.patch: skip zval_ptr_dtor on the persisted
       soap_obj after header parsing failure when persistence is
       SOAP_PERSISTENCE_SESSION
     - CVE-2026-7261
   * SECURITY UPDATE: SOAP use-after-free via Apache Map with duplicate keys
     - debian/patches/CVE-2026-6722.patch: do not store stale pointers in
       SOAP_GLOBAL(ref_map) when the encoded zval is freed during Apache Map
       decoding with duplicate keys
     - CVE-2026-6722
   * SECURITY UPDATE: signed integer overflow of char array offset in metaphone()
     - debian/patches/CVE-2026-7568.patch: switch metaphone position tracker to
       size_t and bound character-offset arithmetic to prevent signed overflow
       on inputs larger than INT_MAX bytes
     - CVE-2026-7568
   * SECURITY UPDATE: SOAP NULL pointer dereference in Apache Map decoding
     - debian/patches/CVE-2026-7262.patch: check the value element before
       dereferencing it when decoding Apache Map entries
     - CVE-2026-7262</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: SOAP use-after-free with SOAP_PERSISTENCE_SESSION
     - debian/patches/CVE-2026-7261.patch: skip zval_ptr_dtor on the persisted
       soap_obj after header parsing failure when persistence is
       SOAP_PERSISTENCE_SESSION
     - CVE-2026-7261
   * SECURITY UPDATE: SOAP use-after-free via Apache Map with duplicate keys
     - debian/patches/CVE-2026-6722.patch: do not store stale pointers in
       SOAP_GLOBAL(ref_map) when the encoded zval is freed during Apache Map
       decoding with duplicate keys
     - CVE-2026-6722
   * SECURITY UPDATE: signed integer overflow of char array offset in metaphone()
     - debian/patches/CVE-2026-7568.patch: switch metaphone position tracker to
       size_t and bound character-offset arithmetic to prevent signed overflow
       on inputs larger than INT_MAX bytes
     - CVE-2026-7568
   * SECURITY UPDATE: SOAP NULL pointer dereference in Apache Map decoding
     - debian/patches/CVE-2026-7262.patch: check the value element before
       dereferencing it when decoding Apache Map entries
     - CVE-2026-7262</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-16 14:54:23 UTC" />
    <updated date="2026-05-16 14:54:23 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1778943258.html" id="CLSA-2026:1778943258" title="CLSA-2026:1778943258" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libapache2-mod-php7.3" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>libapache2-mod-php7.3_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">cf87912822a6ad4e3e076835028ae34ce4ec25e7</sum>
        </package>
        <package arch="amd64" name="libphp7.3-embed" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>libphp7.3-embed_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">b69542667ee0ea4983cc44d44272c82dac7ffcf8</sum>
        </package>
        <package arch="all" name="php7.3" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3_7.3.31-1~deb10u7+tuxcare.els5_all.deb</filename>
          <sum type="sha">e7acae936e0225b9a8a52071f180b732e4b85cd5</sum>
        </package>
        <package arch="amd64" name="php7.3-bcmath" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-bcmath_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">a97e915e5431e38399688bc2c27c50c0886886fb</sum>
        </package>
        <package arch="amd64" name="php7.3-bz2" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-bz2_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">bf63ddbd81fa25cf63c20e2d9d19b61766767067</sum>
        </package>
        <package arch="amd64" name="php7.3-cgi" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-cgi_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">0492d4282191036d67ca7a55a6e04fef4d3e162a</sum>
        </package>
        <package arch="amd64" name="php7.3-cli" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-cli_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">3b81179e3e0e45e03d9deacaece5bf7fd7cc44bb</sum>
        </package>
        <package arch="amd64" name="php7.3-common" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-common_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">92bda80075b45b7878e6418df3671232e4635100</sum>
        </package>
        <package arch="amd64" name="php7.3-curl" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-curl_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">488dd9ee6720cd7c7cb33de3fde4641300a0b467</sum>
        </package>
        <package arch="amd64" name="php7.3-dba" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-dba_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">c1106b744fc839379561106906b702e8bda101f8</sum>
        </package>
        <package arch="amd64" name="php7.3-dev" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-dev_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">91ca5bc3b14d94109dc61ba0d3360d686513ee77</sum>
        </package>
        <package arch="amd64" name="php7.3-enchant" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-enchant_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">035fb10052515ea107fd3da6fcb0562fe31529a0</sum>
        </package>
        <package arch="amd64" name="php7.3-fpm" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-fpm_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">d01f7f053000072c60ca0fbd400eb274d00a41a0</sum>
        </package>
        <package arch="amd64" name="php7.3-gd" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-gd_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">77e83bc76f2fa66b9021185118e2adfda3767736</sum>
        </package>
        <package arch="amd64" name="php7.3-gmp" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-gmp_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">e19450e343e0d8f61747e4e6817ca8102421577b</sum>
        </package>
        <package arch="amd64" name="php7.3-imap" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-imap_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">0fa583a8a57f3c0e10c87c8916a803f89c1f7044</sum>
        </package>
        <package arch="amd64" name="php7.3-interbase" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-interbase_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">341bdf28bdf512d8495c2a6b59cfaac2228b9256</sum>
        </package>
        <package arch="amd64" name="php7.3-intl" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-intl_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">27fcf5b11b074576e63e30a962c868daa3ec60f2</sum>
        </package>
        <package arch="amd64" name="php7.3-json" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-json_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">3b19d5545795fd7d9f63144ecf34a3f621777f14</sum>
        </package>
        <package arch="amd64" name="php7.3-ldap" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-ldap_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">9964024242f4a35f1395eaf8c4012e8832421d9a</sum>
        </package>
        <package arch="amd64" name="php7.3-mbstring" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-mbstring_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">ce5575661ba8d247ba8a6cb2896f227009762acc</sum>
        </package>
        <package arch="amd64" name="php7.3-mysql" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-mysql_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">4b70a2081666cf9e742bb41c41af4844828b0373</sum>
        </package>
        <package arch="amd64" name="php7.3-odbc" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-odbc_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">b413a8a4063cea7d385430c9731559eba66c9499</sum>
        </package>
        <package arch="amd64" name="php7.3-opcache" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-opcache_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">467615850b38b21768600dabc31f13a4e0da8c45</sum>
        </package>
        <package arch="amd64" name="php7.3-pgsql" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-pgsql_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">ccae3cae3c9518e6944b080c86a1dc72b0486978</sum>
        </package>
        <package arch="amd64" name="php7.3-phpdbg" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-phpdbg_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">b3005ea64ae4f3902a27386d79e03a4d160414e5</sum>
        </package>
        <package arch="amd64" name="php7.3-pspell" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-pspell_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">b952938d4143e07dfcd9ec09af11a1ad39675207</sum>
        </package>
        <package arch="amd64" name="php7.3-readline" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-readline_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">879a6f17f19768adf94badac8bc0db7504e53ecf</sum>
        </package>
        <package arch="amd64" name="php7.3-recode" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-recode_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">2a91c751ca3461e9552120ad814edf21bcc4ffb0</sum>
        </package>
        <package arch="amd64" name="php7.3-snmp" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-snmp_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">c4ccd523a129dd85454e2a316ae5f4984ae6dc9b</sum>
        </package>
        <package arch="amd64" name="php7.3-soap" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-soap_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">add2b42b5ecd7f3077626d3b25cc7cf26f836f10</sum>
        </package>
        <package arch="amd64" name="php7.3-sqlite3" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-sqlite3_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">db592dc89b180bfe1c2a8c38d807bba74db3da41</sum>
        </package>
        <package arch="amd64" name="php7.3-sybase" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-sybase_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">26b3b005a689bd7968cda62459543fa19fbf6ac9</sum>
        </package>
        <package arch="amd64" name="php7.3-tidy" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-tidy_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">9c5b229e69d2846ba0a45db918f5e9d82d5ec510</sum>
        </package>
        <package arch="amd64" name="php7.3-xml" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-xml_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">7b34ff2f92c048f8b0743762c41e0c478e93b043</sum>
        </package>
        <package arch="amd64" name="php7.3-xmlrpc" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-xmlrpc_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">dc3b6bb807ac2dd1662c622ecabb36fcccebc021</sum>
        </package>
        <package arch="all" name="php7.3-xsl" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-xsl_7.3.31-1~deb10u7+tuxcare.els5_all.deb</filename>
          <sum type="sha">5e61f97ceb78bb7eb4c637b30a47022880537256</sum>
        </package>
        <package arch="amd64" name="php7.3-zip" version="7.3.31-1~deb10u7+tuxcare.els5">
          <filename>php7.3-zip_7.3.31-1~deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">0d8d6a1d8ef95026bc2630777d9e60213a5072b8</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1778979189</id>
    <title>Fix CVE(s): CVE-2024-6232, CVE-2024-7592, CVE-2024-9287</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: ReDoS in tarfile PAX header parsing
     - debian/patches/CVE-2024-6232.patch: rewrite Lib/tarfile.py PAX-record parser to scan length-prefixed records via a bounded regex (_header_length_prefix_re) plus direct slicing, eliminating quadratic backtracking in three pre-existing regexes. Adapted from upstream commit 7d1f50cd (3.8 backport); walrus operator rewritten as assign-then-test for Python 3.7.
     - CVE-2024-6232
   * SECURITY UPDATE: quadratic complexity in http.cookies._unquote
     - debian/patches/CVE-2024-7592.patch: replace the O(n^2) _OctalPatt/_QuotePatt while-loop in Lib/http/cookies.py with a single linear re.sub() driven by an alternation pattern and _unquote_replace callback. Verbatim from upstream commit 44e45835 / 3.8 backport a77ab244.
     - CVE-2024-7592
   * SECURITY UPDATE: shell injection via venv activation script substitutions
     - debian/patches/CVE-2024-9287.patch: shell-quote __VENV_*__ placeholder substitutions in Lib/venv/__init__.py via shlex.quote (sh/csh/fish) and remove surrounding double-quotes from activate/activate.csh/activate.fish templates so the now-pre-quoted values splice safely. Adapted from upstream 3.9 backport 633555735a; Lib/venv/scripts/nt/Activate.ps1 deliberately untouched (matches upstream 3.9-3.12 backport scope).
     - CVE-2024-9287</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: ReDoS in tarfile PAX header parsing
     - debian/patches/CVE-2024-6232.patch: rewrite Lib/tarfile.py PAX-record parser to scan length-prefixed records via a bounded regex (_header_length_prefix_re) plus direct slicing, eliminating quadratic backtracking in three pre-existing regexes. Adapted from upstream commit 7d1f50cd (3.8 backport); walrus operator rewritten as assign-then-test for Python 3.7.
     - CVE-2024-6232
   * SECURITY UPDATE: quadratic complexity in http.cookies._unquote
     - debian/patches/CVE-2024-7592.patch: replace the O(n^2) _OctalPatt/_QuotePatt while-loop in Lib/http/cookies.py with a single linear re.sub() driven by an alternation pattern and _unquote_replace callback. Verbatim from upstream commit 44e45835 / 3.8 backport a77ab244.
     - CVE-2024-7592
   * SECURITY UPDATE: shell injection via venv activation script substitutions
     - debian/patches/CVE-2024-9287.patch: shell-quote __VENV_*__ placeholder substitutions in Lib/venv/__init__.py via shlex.quote (sh/csh/fish) and remove surrounding double-quotes from activate/activate.csh/activate.fish templates so the now-pre-quoted values splice safely. Adapted from upstream 3.9 backport 633555735a; Lib/venv/scripts/nt/Activate.ps1 deliberately untouched (matches upstream 3.9-3.12 backport scope).
     - CVE-2024-9287</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-17 00:53:13 UTC" />
    <updated date="2026-05-17 00:53:13 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1778979189.html" id="CLSA-2026:1778979189" title="CLSA-2026:1778979189" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="all" name="idle-python3.7" version="3.7.3-2+deb10u7+tuxcare.els2">
          <filename>idle-python3.7_3.7.3-2+deb10u7+tuxcare.els2_all.deb</filename>
          <sum type="sha">0f3b5e7c90ed01a89e6af6a759e455a2bdabde2b</sum>
        </package>
        <package arch="amd64" name="libpython3.7" version="3.7.3-2+deb10u7+tuxcare.els2">
          <filename>libpython3.7_3.7.3-2+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">e6af5993d13125c2a9057b555d6ef95e4deb0b80</sum>
        </package>
        <package arch="amd64" name="libpython3.7-dev" version="3.7.3-2+deb10u7+tuxcare.els2">
          <filename>libpython3.7-dev_3.7.3-2+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">a23a5bd4b2d2e9039839a8c0e2c55f2104224323</sum>
        </package>
        <package arch="amd64" name="libpython3.7-minimal" version="3.7.3-2+deb10u7+tuxcare.els2">
          <filename>libpython3.7-minimal_3.7.3-2+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">ff38a45c9035909b1f1ec600ce7382fb9384ece0</sum>
        </package>
        <package arch="amd64" name="libpython3.7-stdlib" version="3.7.3-2+deb10u7+tuxcare.els2">
          <filename>libpython3.7-stdlib_3.7.3-2+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">ed4a2415c89ab273d634c52d4c8dc6cf129a7204</sum>
        </package>
        <package arch="all" name="libpython3.7-testsuite" version="3.7.3-2+deb10u7+tuxcare.els2">
          <filename>libpython3.7-testsuite_3.7.3-2+deb10u7+tuxcare.els2_all.deb</filename>
          <sum type="sha">56016eede93ffa27639e26155fca012d68431151</sum>
        </package>
        <package arch="amd64" name="python3.7" version="3.7.3-2+deb10u7+tuxcare.els2">
          <filename>python3.7_3.7.3-2+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">9f09eac537b0b0873327b8cb6edf85963cef3925</sum>
        </package>
        <package arch="amd64" name="python3.7-dev" version="3.7.3-2+deb10u7+tuxcare.els2">
          <filename>python3.7-dev_3.7.3-2+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">7e323fe0970875e07658afdf5e9bec20ece9f103</sum>
        </package>
        <package arch="all" name="python3.7-doc" version="3.7.3-2+deb10u7+tuxcare.els2">
          <filename>python3.7-doc_3.7.3-2+deb10u7+tuxcare.els2_all.deb</filename>
          <sum type="sha">f2bce9cd64f5a02d39c78a5d1d94cfbe9fcc20ee</sum>
        </package>
        <package arch="all" name="python3.7-examples" version="3.7.3-2+deb10u7+tuxcare.els2">
          <filename>python3.7-examples_3.7.3-2+deb10u7+tuxcare.els2_all.deb</filename>
          <sum type="sha">f0623579b12aa40114879e967cb8490ccc3c1eff</sum>
        </package>
        <package arch="amd64" name="python3.7-minimal" version="3.7.3-2+deb10u7+tuxcare.els2">
          <filename>python3.7-minimal_3.7.3-2+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">221496bbfd7c9c407cb9752edc544d88714048a3</sum>
        </package>
        <package arch="amd64" name="python3.7-venv" version="3.7.3-2+deb10u7+tuxcare.els2">
          <filename>python3.7-venv_3.7.3-2+deb10u7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">62bf5bbebab0f97023f7c1c6ad4075432009dd2a</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1779096552</id>
    <title>Fix CVE(s): CVE-2025-13836, CVE-2026-4519</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: memory denial of service via attacker-controlled Content-Length in http.client
     - debian/patches/CVE-2025-13836.patch: rewrite Lib/http/client.py _safe_read to read large
       responses in geometrically-growing chunks bounded by _MIN_READ_BUF_SIZE (1 MiB), preventing
       OOM when a malicious server advertises a large Content-Length without sending matching data.
       Adapted from cpython 3.10 backport 5dc101675fd
     - CVE-2025-13836
   * SECURITY UPDATE: command injection in webbrowser.open() via leading dash in URL
     - debian/patches/CVE-2026-4519.patch: add BaseBrowser._check_url static method that rejects
       URLs whose lstripped form starts with a dash, and call it at the start of every open()
       method in GenericBrowser, BackgroundBrowser, UnixBrowser, Konqueror, Grail, WindowsDefault,
       MacOSX, and MacOSXOSAScript. Adapted from cpython 3.10 backports ad4d5ba32af and 591ed890270;
       sys.audit() context lines absent in 3.7 (added in 3.8) so the check is inserted as the first
       statement of each open()
     - CVE-2026-4519</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: memory denial of service via attacker-controlled Content-Length in http.client
     - debian/patches/CVE-2025-13836.patch: rewrite Lib/http/client.py _safe_read to read large
       responses in geometrically-growing chunks bounded by _MIN_READ_BUF_SIZE (1 MiB), preventing
       OOM when a malicious server advertises a large Content-Length without sending matching data.
       Adapted from cpython 3.10 backport 5dc101675fd
     - CVE-2025-13836
   * SECURITY UPDATE: command injection in webbrowser.open() via leading dash in URL
     - debian/patches/CVE-2026-4519.patch: add BaseBrowser._check_url static method that rejects
       URLs whose lstripped form starts with a dash, and call it at the start of every open()
       method in GenericBrowser, BackgroundBrowser, UnixBrowser, Konqueror, Grail, WindowsDefault,
       MacOSX, and MacOSXOSAScript. Adapted from cpython 3.10 backports ad4d5ba32af and 591ed890270;
       sys.audit() context lines absent in 3.7 (added in 3.8) so the check is inserted as the first
       statement of each open()
     - CVE-2026-4519</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-18 09:29:16 UTC" />
    <updated date="2026-05-18 09:29:16 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1779096552.html" id="CLSA-2026:1779096552" title="CLSA-2026:1779096552" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="all" name="idle-python3.7" version="3.7.3-2+deb10u7+tuxcare.els3">
          <filename>idle-python3.7_3.7.3-2+deb10u7+tuxcare.els3_all.deb</filename>
          <sum type="sha">41f2d148e0613aa50c617ca86f0d2cc61221a604</sum>
        </package>
        <package arch="amd64" name="libpython3.7" version="3.7.3-2+deb10u7+tuxcare.els3">
          <filename>libpython3.7_3.7.3-2+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">7a7f8db21d8409227ff91b49521b9d626cceceec</sum>
        </package>
        <package arch="amd64" name="libpython3.7-dev" version="3.7.3-2+deb10u7+tuxcare.els3">
          <filename>libpython3.7-dev_3.7.3-2+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">cba8b88ab4744864b05b467bf567f0e2a903c20d</sum>
        </package>
        <package arch="amd64" name="libpython3.7-minimal" version="3.7.3-2+deb10u7+tuxcare.els3">
          <filename>libpython3.7-minimal_3.7.3-2+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">2e3598cba303afeb6bfabaa9608fc8b1a27b68e2</sum>
        </package>
        <package arch="amd64" name="libpython3.7-stdlib" version="3.7.3-2+deb10u7+tuxcare.els3">
          <filename>libpython3.7-stdlib_3.7.3-2+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">788b1afab579e2cebfeeb5a33545c0505d895561</sum>
        </package>
        <package arch="all" name="libpython3.7-testsuite" version="3.7.3-2+deb10u7+tuxcare.els3">
          <filename>libpython3.7-testsuite_3.7.3-2+deb10u7+tuxcare.els3_all.deb</filename>
          <sum type="sha">9997603a9d3fc9f710457e214bf310329607ebf5</sum>
        </package>
        <package arch="amd64" name="python3.7" version="3.7.3-2+deb10u7+tuxcare.els3">
          <filename>python3.7_3.7.3-2+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">caae2e2c47aed0938a24e181f8cd5a0a45f4b49f</sum>
        </package>
        <package arch="amd64" name="python3.7-dev" version="3.7.3-2+deb10u7+tuxcare.els3">
          <filename>python3.7-dev_3.7.3-2+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">cd30e1fd9f8960c28fe7c15d7e319c6328e7e75c</sum>
        </package>
        <package arch="all" name="python3.7-doc" version="3.7.3-2+deb10u7+tuxcare.els3">
          <filename>python3.7-doc_3.7.3-2+deb10u7+tuxcare.els3_all.deb</filename>
          <sum type="sha">3da6182a83b1d2708d30caa537370160a5cb93ce</sum>
        </package>
        <package arch="all" name="python3.7-examples" version="3.7.3-2+deb10u7+tuxcare.els3">
          <filename>python3.7-examples_3.7.3-2+deb10u7+tuxcare.els3_all.deb</filename>
          <sum type="sha">9aa191335655200d1a477bf263dba6e74fde06d2</sum>
        </package>
        <package arch="amd64" name="python3.7-minimal" version="3.7.3-2+deb10u7+tuxcare.els3">
          <filename>python3.7-minimal_3.7.3-2+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">1238717c39d2ed22d2e31b680bb461242aedae2d</sum>
        </package>
        <package arch="amd64" name="python3.7-venv" version="3.7.3-2+deb10u7+tuxcare.els3">
          <filename>python3.7-venv_3.7.3-2+deb10u7+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">5a80b92a9b0333fed5b09cfbca8bca16aa7bca29</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1779118869</id>
    <title>Fix of 8 CVEs</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix off-by-one out-of-bounds read in mod_proxy_ajp message getter functions
     - debian/patches/CVE-2026-33857-prereq.patch: prerequisite fix for
       ajp_msg_check_header bounds check to keep msg-&gt;len within buffer
     - debian/patches/CVE-2026-33857.patch: fix off-by-one out-of-bounds read in mod_proxy_ajp message getter functions
     - CVE-2026-33857
   * SECURITY UPDATE: fix improper null termination and out-of-bounds read in ajp_msg_get_string
     - debian/patches/CVE-2026-34032.patch: fix improper null termination and out-of-bounds read in ajp_msg_get_string
     - CVE-2026-34032
   * SECURITY UPDATE: fix heap buffer over-read in mod_proxy_ajp ajp_parse_data
     - debian/patches/CVE-2026-34059.patch: fix heap buffer over-read in mod_proxy_ajp ajp_parse_data
     - CVE-2026-34059
   * SECURITY UPDATE: use restricted ap_expr parser in htaccess context to prevent local privilege escalation
     - debian/patches/CVE-2026-24072.patch: use restricted ap_expr parser in htaccess context to prevent local privilege escalation
     - CVE-2026-24072
   * SECURITY UPDATE: fix NULL pointer dereference crash in mod_dav_lock dav_generic_refresh_locks
     - debian/patches/CVE-2026-29169.patch: fix NULL pointer dereference crash in mod_dav_lock dav_generic_refresh_locks
     - CVE-2026-29169
   * SECURITY UPDATE: fix timing attack allowing Digest authentication bypass in mod_auth_digest
     - debian/patches/CVE-2026-33006.patch: fix timing attack allowing Digest authentication bypass in mod_auth_digest
     - CVE-2026-33006
   * SECURITY UPDATE: fix NULL pointer dereference crash in mod_authn_socache
     - debian/patches/CVE-2026-33007.patch: fix NULL pointer dereference crash in mod_authn_socache
     - CVE-2026-33007
   * SECURITY UPDATE: fix HTTP response splitting via newlines/controls in outgoing status line
     - debian/patches/CVE-2026-33523.patch: fix HTTP response splitting via newlines/controls in outgoing status line
     - CVE-2026-33523</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix off-by-one out-of-bounds read in mod_proxy_ajp message getter functions
     - debian/patches/CVE-2026-33857-prereq.patch: prerequisite fix for
       ajp_msg_check_header bounds check to keep msg-&gt;len within buffer
     - debian/patches/CVE-2026-33857.patch: fix off-by-one out-of-bounds read in mod_proxy_ajp message getter functions
     - CVE-2026-33857
   * SECURITY UPDATE: fix improper null termination and out-of-bounds read in ajp_msg_get_string
     - debian/patches/CVE-2026-34032.patch: fix improper null termination and out-of-bounds read in ajp_msg_get_string
     - CVE-2026-34032
   * SECURITY UPDATE: fix heap buffer over-read in mod_proxy_ajp ajp_parse_data
     - debian/patches/CVE-2026-34059.patch: fix heap buffer over-read in mod_proxy_ajp ajp_parse_data
     - CVE-2026-34059
   * SECURITY UPDATE: use restricted ap_expr parser in htaccess context to prevent local privilege escalation
     - debian/patches/CVE-2026-24072.patch: use restricted ap_expr parser in htaccess context to prevent local privilege escalation
     - CVE-2026-24072
   * SECURITY UPDATE: fix NULL pointer dereference crash in mod_dav_lock dav_generic_refresh_locks
     - debian/patches/CVE-2026-29169.patch: fix NULL pointer dereference crash in mod_dav_lock dav_generic_refresh_locks
     - CVE-2026-29169
   * SECURITY UPDATE: fix timing attack allowing Digest authentication bypass in mod_auth_digest
     - debian/patches/CVE-2026-33006.patch: fix timing attack allowing Digest authentication bypass in mod_auth_digest
     - CVE-2026-33006
   * SECURITY UPDATE: fix NULL pointer dereference crash in mod_authn_socache
     - debian/patches/CVE-2026-33007.patch: fix NULL pointer dereference crash in mod_authn_socache
     - CVE-2026-33007
   * SECURITY UPDATE: fix HTTP response splitting via newlines/controls in outgoing status line
     - debian/patches/CVE-2026-33523.patch: fix HTTP response splitting via newlines/controls in outgoing status line
     - CVE-2026-33523</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-19 00:19:25 UTC" />
    <updated date="2026-05-19 00:19:25 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1779118869.html" id="CLSA-2026:1779118869" title="CLSA-2026:1779118869" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="apache2" version="2.4.59-1~deb10u1+tuxcare.els5">
          <filename>apache2_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">096e680c9fb0f06d07808bfb093729ea048b74e7</sum>
        </package>
        <package arch="amd64" name="apache2-bin" version="2.4.59-1~deb10u1+tuxcare.els5">
          <filename>apache2-bin_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">14694b51a73f634338270c8c20f52eda1894dbf7</sum>
        </package>
        <package arch="all" name="apache2-data" version="2.4.59-1~deb10u1+tuxcare.els5">
          <filename>apache2-data_2.4.59-1~deb10u1+tuxcare.els5_all.deb</filename>
          <sum type="sha">be315eaabeaea983d88361c0037e489cc709211c</sum>
        </package>
        <package arch="amd64" name="apache2-dev" version="2.4.59-1~deb10u1+tuxcare.els5">
          <filename>apache2-dev_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">386099f3b4ec8626905f8dc6fa3da27e0b88aa67</sum>
        </package>
        <package arch="all" name="apache2-doc" version="2.4.59-1~deb10u1+tuxcare.els5">
          <filename>apache2-doc_2.4.59-1~deb10u1+tuxcare.els5_all.deb</filename>
          <sum type="sha">fd530b4b62eebe797b3be48883b0ee1ec2336e81</sum>
        </package>
        <package arch="amd64" name="apache2-ssl-dev" version="2.4.59-1~deb10u1+tuxcare.els5">
          <filename>apache2-ssl-dev_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">7be3c0093dffe41498387470579422833f688b68</sum>
        </package>
        <package arch="amd64" name="apache2-suexec-custom" version="2.4.59-1~deb10u1+tuxcare.els5">
          <filename>apache2-suexec-custom_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">43b7f479118a9b49e41cb02a4c89e0c0aa7d5257</sum>
        </package>
        <package arch="amd64" name="apache2-suexec-pristine" version="2.4.59-1~deb10u1+tuxcare.els5">
          <filename>apache2-suexec-pristine_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">0ae1d5bea5071cb87f6773f456de4143eabb4fee</sum>
        </package>
        <package arch="amd64" name="apache2-utils" version="2.4.59-1~deb10u1+tuxcare.els5">
          <filename>apache2-utils_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">ea411b94e385613ef702d20823a9e0b9fc6d26fb</sum>
        </package>
        <package arch="amd64" name="libapache2-mod-md" version="2.4.59-1~deb10u1+tuxcare.els5">
          <filename>libapache2-mod-md_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">5683fa9c4b7c71c4fcf0fa95a1fc9017b183012d</sum>
        </package>
        <package arch="amd64" name="libapache2-mod-proxy-uwsgi" version="2.4.59-1~deb10u1+tuxcare.els5">
          <filename>libapache2-mod-proxy-uwsgi_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">a23a6cd779adb834c73c1bb7e23766eb26c30713</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1777976277</id>
    <title>Fix CVE(s): CVE-2022-24834</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Integer overflow in Lua cmsgpack library
     - debian/patches/CVE-2022-24834.patch: partial backport hardening
       deps/lua/src/lua_cmsgpack.c against integer overflows in mp_buf_append
       and the encode/decode helpers (cmsgpack-only; the cjson half of the
       upstream fix is dead code under USE_SYSTEM_LUA=yes and is tracked via
       the lua-cjson source package)
     - CVE-2022-24834</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Integer overflow in Lua cmsgpack library
     - debian/patches/CVE-2022-24834.patch: partial backport hardening
       deps/lua/src/lua_cmsgpack.c against integer overflows in mp_buf_append
       and the encode/decode helpers (cmsgpack-only; the cjson half of the
       upstream fix is dead code under USE_SYSTEM_LUA=yes and is tracked via
       the lua-cjson source package)
     - CVE-2022-24834</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-20 10:32:56 UTC" />
    <updated date="2026-05-20 10:32:56 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1777976277.html" id="CLSA-2026:1777976277" title="CLSA-2026:1777976277" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="all" name="redis" version="5:5.0.14-1+deb10u5+tuxcare.els2">
          <filename>redis_5.0.14-1+deb10u5+tuxcare.els2_all.deb</filename>
          <sum type="sha">3d414a33a9448f7dcd04d2111dd90d033f2fda8b</sum>
        </package>
        <package arch="amd64" name="redis-sentinel" version="5:5.0.14-1+deb10u5+tuxcare.els2">
          <filename>redis-sentinel_5.0.14-1+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">2bf31d2893d764d1156aa90970846679532bfbe6</sum>
        </package>
        <package arch="amd64" name="redis-server" version="5:5.0.14-1+deb10u5+tuxcare.els2">
          <filename>redis-server_5.0.14-1+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">bc09494cb766e09fe3fb2663bdbb8fdd3fc96a62</sum>
        </package>
        <package arch="amd64" name="redis-tools" version="5:5.0.14-1+deb10u5+tuxcare.els2">
          <filename>redis-tools_5.0.14-1+deb10u5+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">8265e6fdf63f5b7d7f55cefdf8e49b5a57aefd02</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1779351595</id>
    <title>Fix CVE(s): CVE-2026-23631</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Use-after-free in readSyncBulkPayload during fullsync
     - debian/patches/0015-CVE-2026-23631.patch: guard readSyncBulkPayload
       in src/replication.c with an early return when server.lua_timedout is
       set, so a fullsync cannot free the Lua scripting engine while a
       timed-out script is still running on the replica. Backport of upstream
       redis commit 80c2b5a0a (7.2 branch), adapted to 5.0 by using
       server.lua_timedout in place of isInsideYieldingLongCommand().
     - CVE-2026-23631</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Use-after-free in readSyncBulkPayload during fullsync
     - debian/patches/0015-CVE-2026-23631.patch: guard readSyncBulkPayload
       in src/replication.c with an early return when server.lua_timedout is
       set, so a fullsync cannot free the Lua scripting engine while a
       timed-out script is still running on the replica. Backport of upstream
       redis commit 80c2b5a0a (7.2 branch), adapted to 5.0 by using
       server.lua_timedout in place of isInsideYieldingLongCommand().
     - CVE-2026-23631</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-21 09:28:51 UTC" />
    <updated date="2026-05-21 09:28:51 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1779351595.html" id="CLSA-2026:1779351595" title="CLSA-2026:1779351595" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="all" name="redis" version="5:5.0.14-1+deb10u5+tuxcare.els3">
          <filename>redis_5.0.14-1+deb10u5+tuxcare.els3_all.deb</filename>
          <sum type="sha">60f1e2ec076db6c491542ecf697b559c05737d55</sum>
        </package>
        <package arch="amd64" name="redis-sentinel" version="5:5.0.14-1+deb10u5+tuxcare.els3">
          <filename>redis-sentinel_5.0.14-1+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">0145fec1d539643aa3b31c977cec7944e7f9adef</sum>
        </package>
        <package arch="amd64" name="redis-server" version="5:5.0.14-1+deb10u5+tuxcare.els3">
          <filename>redis-server_5.0.14-1+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">46b44e77e9d3fd25ab682eb8f52b727b60ace312</sum>
        </package>
        <package arch="amd64" name="redis-tools" version="5:5.0.14-1+deb10u5+tuxcare.els3">
          <filename>redis-tools_5.0.14-1+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">03e49c72ec6eb876f9751ec3ea2068835240b962</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1779358120</id>
    <title>Fix CVE(s): CVE-2026-5773</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: wrong reuse of SMB connection
     - debian/patches/CVE-2026-5773.patch: disable connection reuse for
       SMB(S) in lib/smb.c.
     - CVE-2026-5773</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: wrong reuse of SMB connection
     - debian/patches/CVE-2026-5773.patch: disable connection reuse for
       SMB(S) in lib/smb.c.
     - CVE-2026-5773</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-21 10:08:45 UTC" />
    <updated date="2026-05-21 10:08:45 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1779358120.html" id="CLSA-2026:1779358120" title="CLSA-2026:1779358120" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="curl" version="7.64.0-4+deb10u9+tuxcare.els4">
          <filename>curl_7.64.0-4+deb10u9+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">524aa54e21f0b126ce37ec2154f03439071015de</sum>
        </package>
        <package arch="amd64" name="libcurl3-gnutls" version="7.64.0-4+deb10u9+tuxcare.els4">
          <filename>libcurl3-gnutls_7.64.0-4+deb10u9+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">aa1631a9cfce2a5a70ad3fdd41129d423e574808</sum>
        </package>
        <package arch="amd64" name="libcurl3-nss" version="7.64.0-4+deb10u9+tuxcare.els4">
          <filename>libcurl3-nss_7.64.0-4+deb10u9+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">dfcb315057db6f176a22e43dff72fe54350dcb70</sum>
        </package>
        <package arch="amd64" name="libcurl4" version="7.64.0-4+deb10u9+tuxcare.els4">
          <filename>libcurl4_7.64.0-4+deb10u9+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">3cf6fe1f6c240fded76ccfcd6c54ec9ddccbf571</sum>
        </package>
        <package arch="all" name="libcurl4-doc" version="7.64.0-4+deb10u9+tuxcare.els4">
          <filename>libcurl4-doc_7.64.0-4+deb10u9+tuxcare.els4_all.deb</filename>
          <sum type="sha">4a1a77030849576623a033ccecf12da67680985f</sum>
        </package>
        <package arch="amd64" name="libcurl4-gnutls-dev" version="7.64.0-4+deb10u9+tuxcare.els4">
          <filename>libcurl4-gnutls-dev_7.64.0-4+deb10u9+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">67fd8614006b87fbbf35b16981849e215da7b0cd</sum>
        </package>
        <package arch="amd64" name="libcurl4-nss-dev" version="7.64.0-4+deb10u9+tuxcare.els4">
          <filename>libcurl4-nss-dev_7.64.0-4+deb10u9+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">ea78d4f7ad3331e22c0723bbc875d77cbfd5b70e</sum>
        </package>
        <package arch="amd64" name="libcurl4-openssl-dev" version="7.64.0-4+deb10u9+tuxcare.els4">
          <filename>libcurl4-openssl-dev_7.64.0-4+deb10u9+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">43f499e8dc2a8597fcf9c961a6df333604ba7b57</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1779359157</id>
    <title>Fix CVE(s): CVE-2026-45186</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Denial of service via quadratic attribute-name
     collision check in libexpat before 2.8.1
     - debian/patches/CVE-2026-45186.patch: introduce per-element
       defaultAttsNames hash table and use it for O(1) attribute
       collision detection in defineAttribute
     - CVE-2026-45186</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Denial of service via quadratic attribute-name
     collision check in libexpat before 2.8.1
     - debian/patches/CVE-2026-45186.patch: introduce per-element
       defaultAttsNames hash table and use it for O(1) attribute
       collision detection in defineAttribute
     - CVE-2026-45186</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-21 10:26:02 UTC" />
    <updated date="2026-05-21 10:26:02 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1779359157.html" id="CLSA-2026:1779359157" title="CLSA-2026:1779359157" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="expat" version="2.2.6-2+deb10u7+tuxcare.els5">
          <filename>expat_2.2.6-2+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">d6348f696f0730960412ffeeab9eccc16ceb9568</sum>
        </package>
        <package arch="amd64" name="libexpat1" version="2.2.6-2+deb10u7+tuxcare.els5">
          <filename>libexpat1_2.2.6-2+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">718599568d86568d496cad48b544991ee16f0f1e</sum>
        </package>
        <package arch="amd64" name="libexpat1-dev" version="2.2.6-2+deb10u7+tuxcare.els5">
          <filename>libexpat1-dev_2.2.6-2+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">41dbc649f7234aff56b3fcefe717dba6a689316d</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1779389543</id>
    <title>Fix of 6 CVEs</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: integer wraparound on 32-bit systems in palloc() callers
     - debian/patches/CVE-2026-6473.patch: integer wraparound on 32-bit systems in palloc() callers
     - CVE-2026-6473
   * SECURITY UPDATE: format-string memory disclosure in timeofday() via crafted timezones
     - debian/patches/CVE-2026-6474.patch: format-string memory disclosure in timeofday() via crafted timezones
     - CVE-2026-6474
   * SECURITY UPDATE: path traversal in pg_rewind allows origin superuser to overwrite local files
     - debian/patches/CVE-2026-6475.patch: path traversal in pg_rewind allows origin superuser to overwrite local files
     - CVE-2026-6475
   * SECURITY UPDATE: stack buffer overrun in libpq PQfn() (lo_read/lo_lseek64/lo_tell64)
     - debian/patches/CVE-2026-6477.patch: stack buffer overrun in libpq PQfn() (lo_read/lo_lseek64/lo_tell64)
     - CVE-2026-6477
   * SECURITY UPDATE: covert timing channel in MD5 password comparison
     - debian/patches/CVE-2026-6478.patch: covert timing channel in MD5 password comparison
     - CVE-2026-6478
   * SECURITY UPDATE: SQL injection and stack buffer overruns in refint contrib module
     - debian/patches/CVE-2026-6637.patch: SQL injection and stack buffer overruns in refint contrib module
     - CVE-2026-6637</description>
    <severity>Low</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: integer wraparound on 32-bit systems in palloc() callers
     - debian/patches/CVE-2026-6473.patch: integer wraparound on 32-bit systems in palloc() callers
     - CVE-2026-6473
   * SECURITY UPDATE: format-string memory disclosure in timeofday() via crafted timezones
     - debian/patches/CVE-2026-6474.patch: format-string memory disclosure in timeofday() via crafted timezones
     - CVE-2026-6474
   * SECURITY UPDATE: path traversal in pg_rewind allows origin superuser to overwrite local files
     - debian/patches/CVE-2026-6475.patch: path traversal in pg_rewind allows origin superuser to overwrite local files
     - CVE-2026-6475
   * SECURITY UPDATE: stack buffer overrun in libpq PQfn() (lo_read/lo_lseek64/lo_tell64)
     - debian/patches/CVE-2026-6477.patch: stack buffer overrun in libpq PQfn() (lo_read/lo_lseek64/lo_tell64)
     - CVE-2026-6477
   * SECURITY UPDATE: covert timing channel in MD5 password comparison
     - debian/patches/CVE-2026-6478.patch: covert timing channel in MD5 password comparison
     - CVE-2026-6478
   * SECURITY UPDATE: SQL injection and stack buffer overruns in refint contrib module
     - debian/patches/CVE-2026-6637.patch: SQL injection and stack buffer overruns in refint contrib module
     - CVE-2026-6637</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-21 18:52:27 UTC" />
    <updated date="2026-05-21 18:52:27 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1779389543.html" id="CLSA-2026:1779389543" title="CLSA-2026:1779389543" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libecpg-compat3" version="11.22-0+deb10u2+tuxcare.els2">
          <filename>libecpg-compat3_11.22-0+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">e239e6fb09d55f54c071bc3a0a6311c4c7fd8b8f</sum>
        </package>
        <package arch="amd64" name="libecpg-dev" version="11.22-0+deb10u2+tuxcare.els2">
          <filename>libecpg-dev_11.22-0+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">195d3deae4f878402fd46f1013bcbdcd7c3aad62</sum>
        </package>
        <package arch="amd64" name="libecpg6" version="11.22-0+deb10u2+tuxcare.els2">
          <filename>libecpg6_11.22-0+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">e2cac60094dd119b66a036e9ea6e5eb326fd62c7</sum>
        </package>
        <package arch="amd64" name="libpgtypes3" version="11.22-0+deb10u2+tuxcare.els2">
          <filename>libpgtypes3_11.22-0+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">df3c47d835935a860052a44624736e9e76c09f3e</sum>
        </package>
        <package arch="amd64" name="libpq-dev" version="11.22-0+deb10u2+tuxcare.els2">
          <filename>libpq-dev_11.22-0+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">da2fa9ac89f532d6e63659351a5f465fef4519a9</sum>
        </package>
        <package arch="amd64" name="libpq5" version="11.22-0+deb10u2+tuxcare.els2">
          <filename>libpq5_11.22-0+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">b9608aa5e7e605e9a20c7945c7dbb3ba617a25b1</sum>
        </package>
        <package arch="amd64" name="postgresql-11" version="11.22-0+deb10u2+tuxcare.els2">
          <filename>postgresql-11_11.22-0+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">bf2b231a2a260e5211f0a6cb7f60bc7dbbfee55f</sum>
        </package>
        <package arch="amd64" name="postgresql-client-11" version="11.22-0+deb10u2+tuxcare.els2">
          <filename>postgresql-client-11_11.22-0+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">e58a06eab93c96ac2b21d9aefb41937a49a1efdd</sum>
        </package>
        <package arch="all" name="postgresql-doc-11" version="11.22-0+deb10u2+tuxcare.els2">
          <filename>postgresql-doc-11_11.22-0+deb10u2+tuxcare.els2_all.deb</filename>
          <sum type="sha">51273866bca4902bd3aebe1583bb315bc5a93922</sum>
        </package>
        <package arch="amd64" name="postgresql-plperl-11" version="11.22-0+deb10u2+tuxcare.els2">
          <filename>postgresql-plperl-11_11.22-0+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">33bdb8f3a016b5b1392f5c93ffb8b7a211b43459</sum>
        </package>
        <package arch="amd64" name="postgresql-plpython-11" version="11.22-0+deb10u2+tuxcare.els2">
          <filename>postgresql-plpython-11_11.22-0+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">9726bec48e375ef8133c58ce2c6961392264749e</sum>
        </package>
        <package arch="amd64" name="postgresql-plpython3-11" version="11.22-0+deb10u2+tuxcare.els2">
          <filename>postgresql-plpython3-11_11.22-0+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">8167ddc8357de06eded4c2ea23bcb51e3047c2c0</sum>
        </package>
        <package arch="amd64" name="postgresql-pltcl-11" version="11.22-0+deb10u2+tuxcare.els2">
          <filename>postgresql-pltcl-11_11.22-0+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">32de004e3784a7798a835f2fed92f7a960bbe0ff</sum>
        </package>
        <package arch="amd64" name="postgresql-server-dev-11" version="11.22-0+deb10u2+tuxcare.els2">
          <filename>postgresql-server-dev-11_11.22-0+deb10u2+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">b69c034f3d52854d8af7009f4b5a75ca8dad26ae</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1779371632</id>
    <title>Fix CVE(s): CVE-2021-46848</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * CVE-2021-46848: Fix ETYPE_OK off by one array size check.</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * CVE-2021-46848: Fix ETYPE_OK off by one array size check.</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-22 22:59:46 UTC" />
    <updated date="2026-05-22 22:59:46 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1779371632.html" id="CLSA-2026:1779371632" title="CLSA-2026:1779371632" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libtasn1-6" version="4.13-3+tuxcare.els1">
          <filename>libtasn1-6_4.13-3+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">df291c9ccd13720abe2965b8e95a247021eaa023</sum>
        </package>
        <package arch="amd64" name="libtasn1-6-dev" version="4.13-3+tuxcare.els1">
          <filename>libtasn1-6-dev_4.13-3+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">da59390fdfaa8b0f1050e46b946031edc3f437f3</sum>
        </package>
        <package arch="amd64" name="libtasn1-bin" version="4.13-3+tuxcare.els1">
          <filename>libtasn1-bin_4.13-3+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">f9bc8c649be01c23baee97c4eb1a816d4017c7bf</sum>
        </package>
        <package arch="all" name="libtasn1-doc" version="4.13-3+tuxcare.els1">
          <filename>libtasn1-doc_4.13-3+tuxcare.els1_all.deb</filename>
          <sum type="sha">46b0f5b1547fbe111a6c075a57afffeb8e2ce476</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1779292803</id>
    <title>Fix CVE(s): CVE-2026-6735</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: XSS within status endpoint in PHP-FPM
     - debian/patches/CVE-2026-6735.patch: XSS within status endpoint in PHP-FPM
     - CVE-2026-6735</description>
    <severity>Moderate</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: XSS within status endpoint in PHP-FPM
     - debian/patches/CVE-2026-6735.patch: XSS within status endpoint in PHP-FPM
     - CVE-2026-6735</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-25 13:11:13 UTC" />
    <updated date="2026-05-25 13:11:13 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1779292803.html" id="CLSA-2026:1779292803" title="CLSA-2026:1779292803" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libapache2-mod-php7.3" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>libapache2-mod-php7.3_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">0310f657e340224e08df489d5c6039b2556b4a3b</sum>
        </package>
        <package arch="amd64" name="libphp7.3-embed" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>libphp7.3-embed_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">833a8989405d54700670bf65909b2e5cdc133f68</sum>
        </package>
        <package arch="all" name="php7.3" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3_7.3.31-1~deb10u7+tuxcare.els6_all.deb</filename>
          <sum type="sha">721e4bab1b994a7e2855566e1518adf9f37f36c8</sum>
        </package>
        <package arch="amd64" name="php7.3-bcmath" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-bcmath_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">900d6293e93aa784eee9e5b76b016ec8df2b3975</sum>
        </package>
        <package arch="amd64" name="php7.3-bz2" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-bz2_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">c6d1b36dfb7eb1177e389430a0eed65f72f1cffb</sum>
        </package>
        <package arch="amd64" name="php7.3-cgi" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-cgi_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">952ca7ecc6733d9b989ff0ff8017f0a2a6ff52eb</sum>
        </package>
        <package arch="amd64" name="php7.3-cli" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-cli_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">be3dfb4a5ec440ba2abc039b3e3414ef3889d591</sum>
        </package>
        <package arch="amd64" name="php7.3-common" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-common_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">ed522f6e71da2c41705588a038e1bc8b6ef9a665</sum>
        </package>
        <package arch="amd64" name="php7.3-curl" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-curl_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">521efa06a4eaf87b50f6e3c92398436b41cc306e</sum>
        </package>
        <package arch="amd64" name="php7.3-dba" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-dba_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">b546a8e00877f176fac0a8cbf03bafc9ea54175c</sum>
        </package>
        <package arch="amd64" name="php7.3-dev" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-dev_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">8826c665653326328043a7cb20894f22dfcc4064</sum>
        </package>
        <package arch="amd64" name="php7.3-enchant" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-enchant_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">4de169540eb4952930f550414520f4f31bc9e765</sum>
        </package>
        <package arch="amd64" name="php7.3-fpm" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-fpm_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">d6aeb34304883a03e727d44acef8ec0eb32ccb5d</sum>
        </package>
        <package arch="amd64" name="php7.3-gd" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-gd_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">9cb5da21199f6a8bfd2d59801ad5dc736070e4ee</sum>
        </package>
        <package arch="amd64" name="php7.3-gmp" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-gmp_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">e42418ff5af8d197c69f88945911143d4900c805</sum>
        </package>
        <package arch="amd64" name="php7.3-imap" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-imap_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">98d07a48b7d3050229510cc832a08ba24ce00487</sum>
        </package>
        <package arch="amd64" name="php7.3-interbase" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-interbase_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">6f6b4c9365cf71cf9214ce9ee5e7d530abc8652a</sum>
        </package>
        <package arch="amd64" name="php7.3-intl" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-intl_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">f3a359d57d7238e5223ee6dbb8aa7341bc7fcdef</sum>
        </package>
        <package arch="amd64" name="php7.3-json" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-json_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">e52e546b147256db3d0114dd2bf28536e7b6451f</sum>
        </package>
        <package arch="amd64" name="php7.3-ldap" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-ldap_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">6f04caaf2e8a79130b8b1de794351fbcae2587ae</sum>
        </package>
        <package arch="amd64" name="php7.3-mbstring" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-mbstring_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">59c4fd83d38921ec65dbfeee48612ac299899c48</sum>
        </package>
        <package arch="amd64" name="php7.3-mysql" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-mysql_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">e3529f59aca9c6cda830da25ef84372aa3968dcc</sum>
        </package>
        <package arch="amd64" name="php7.3-odbc" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-odbc_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">359991bb6422c8bd48c7c3522b0b84e1a2fa4f23</sum>
        </package>
        <package arch="amd64" name="php7.3-opcache" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-opcache_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">657592fa56115e176e6548ca744af0925ccbb576</sum>
        </package>
        <package arch="amd64" name="php7.3-pgsql" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-pgsql_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">489d0ee1ce5bb22b47a1151129d19e54681139fe</sum>
        </package>
        <package arch="amd64" name="php7.3-phpdbg" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-phpdbg_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">436e9ae73b0b654716541055b4fa91a878be25c6</sum>
        </package>
        <package arch="amd64" name="php7.3-pspell" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-pspell_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">ce27023fa303dfe36203a96761d8f428db7c7d01</sum>
        </package>
        <package arch="amd64" name="php7.3-readline" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-readline_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">a2425a8bec17ebaeed8834f3b56531741d2f6d15</sum>
        </package>
        <package arch="amd64" name="php7.3-recode" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-recode_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">1537c19cf0da5b29c7d878f127411192c237ce11</sum>
        </package>
        <package arch="amd64" name="php7.3-snmp" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-snmp_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">dfbcaf63def47f24c3f530c3a6a1608858acfadb</sum>
        </package>
        <package arch="amd64" name="php7.3-soap" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-soap_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">eb9eafd3a08fdf755f23f71f46219ebc023166e0</sum>
        </package>
        <package arch="amd64" name="php7.3-sqlite3" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-sqlite3_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">94bcc04b1f147330089261cf2b8bf02ac4debc02</sum>
        </package>
        <package arch="amd64" name="php7.3-sybase" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-sybase_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">4de0fc878f2944b57e0b12de0378e3850fa39256</sum>
        </package>
        <package arch="amd64" name="php7.3-tidy" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-tidy_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">cd069e623f00614abeb21a0300796de8f84e95b5</sum>
        </package>
        <package arch="amd64" name="php7.3-xml" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-xml_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">d333fce63a38c334e1cec42d317e01254ef39983</sum>
        </package>
        <package arch="amd64" name="php7.3-xmlrpc" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-xmlrpc_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">224fb31af8f9f9aadf80fb98e757a933a5692ef0</sum>
        </package>
        <package arch="all" name="php7.3-xsl" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-xsl_7.3.31-1~deb10u7+tuxcare.els6_all.deb</filename>
          <sum type="sha">5fc98afc008b890e0472db069987f0953aca5e2b</sum>
        </package>
        <package arch="amd64" name="php7.3-zip" version="7.3.31-1~deb10u7+tuxcare.els6">
          <filename>php7.3-zip_7.3.31-1~deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">fb7ea94ee24a9708c99c94326d8f92236d3c78d8</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1779797547</id>
    <title>Fix CVE(s): CVE-2026-29168</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix denial of service in mod_md OCSP response handling by enforcing size limit and timeouts
     - debian/patches/CVE-2026-29168.patch: fix denial of service in mod_md OCSP response handling by enforcing size limit and timeouts
     - CVE-2026-29168</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix denial of service in mod_md OCSP response handling by enforcing size limit and timeouts
     - debian/patches/CVE-2026-29168.patch: fix denial of service in mod_md OCSP response handling by enforcing size limit and timeouts
     - CVE-2026-29168</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-26 12:12:31 UTC" />
    <updated date="2026-05-26 12:12:31 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1779797547.html" id="CLSA-2026:1779797547" title="CLSA-2026:1779797547" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="apache2" version="2.4.59-1~deb10u1+tuxcare.els6">
          <filename>apache2_2.4.59-1~deb10u1+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">df2024a377e101a88d65da3e0556695176cf67a5</sum>
        </package>
        <package arch="amd64" name="apache2-bin" version="2.4.59-1~deb10u1+tuxcare.els6">
          <filename>apache2-bin_2.4.59-1~deb10u1+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">0ff9b25e2438d23911a33696cc5cb8d5cb0e1805</sum>
        </package>
        <package arch="all" name="apache2-data" version="2.4.59-1~deb10u1+tuxcare.els6">
          <filename>apache2-data_2.4.59-1~deb10u1+tuxcare.els6_all.deb</filename>
          <sum type="sha">e3356bb406e9799896e0c38f3426642bc3b0b535</sum>
        </package>
        <package arch="amd64" name="apache2-dev" version="2.4.59-1~deb10u1+tuxcare.els6">
          <filename>apache2-dev_2.4.59-1~deb10u1+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">9764efbb6a48f4c8590d2f7b02b19764f528254a</sum>
        </package>
        <package arch="all" name="apache2-doc" version="2.4.59-1~deb10u1+tuxcare.els6">
          <filename>apache2-doc_2.4.59-1~deb10u1+tuxcare.els6_all.deb</filename>
          <sum type="sha">0f73fa2fd3bc342aa293fa930aa30d7c5dfd9207</sum>
        </package>
        <package arch="amd64" name="apache2-ssl-dev" version="2.4.59-1~deb10u1+tuxcare.els6">
          <filename>apache2-ssl-dev_2.4.59-1~deb10u1+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">7fdbbd51ad12f7ecef7885003c0120388c59f995</sum>
        </package>
        <package arch="amd64" name="apache2-suexec-custom" version="2.4.59-1~deb10u1+tuxcare.els6">
          <filename>apache2-suexec-custom_2.4.59-1~deb10u1+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">39392e9df17cf6b5debff6c5e17b94fee29f156b</sum>
        </package>
        <package arch="amd64" name="apache2-suexec-pristine" version="2.4.59-1~deb10u1+tuxcare.els6">
          <filename>apache2-suexec-pristine_2.4.59-1~deb10u1+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">dcd1d2131b897719facc7c4d2231d3b578d189cc</sum>
        </package>
        <package arch="amd64" name="apache2-utils" version="2.4.59-1~deb10u1+tuxcare.els6">
          <filename>apache2-utils_2.4.59-1~deb10u1+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">2f8723a5dfcb7c22f218737b688337bc518abb32</sum>
        </package>
        <package arch="amd64" name="libapache2-mod-md" version="2.4.59-1~deb10u1+tuxcare.els6">
          <filename>libapache2-mod-md_2.4.59-1~deb10u1+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">96b0b80f93af4555ff635d4e35f9d970365054c4</sum>
        </package>
        <package arch="amd64" name="libapache2-mod-proxy-uwsgi" version="2.4.59-1~deb10u1+tuxcare.els6">
          <filename>libapache2-mod-proxy-uwsgi_2.4.59-1~deb10u1+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">2e6cf9aacda9f951a3942361246e62d900229349</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1779804603</id>
    <title>Fix CVE(s): CVE-2026-9256</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Heap buffer overflow in ngx_http_rewrite_module via
     overlapping PCRE captures in replacement strings
     - debian/patches/CVE-2026-9256.patch: recompute buffer length per
       capture (including escaping) in ngx_http_script_regex_start_code
       to prevent buffer overrun when redirect parameter is used or
       arguments appear in the rewrite replacement string
     - CVE-2026-9256</description>
    <severity>Low</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Heap buffer overflow in ngx_http_rewrite_module via
     overlapping PCRE captures in replacement strings
     - debian/patches/CVE-2026-9256.patch: recompute buffer length per
       capture (including escaping) in ngx_http_script_regex_start_code
       to prevent buffer overrun when redirect parameter is used or
       arguments appear in the rewrite replacement string
     - CVE-2026-9256</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-26 14:10:17 UTC" />
    <updated date="2026-05-26 14:10:17 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1779804603.html" id="CLSA-2026:1779804603" title="CLSA-2026:1779804603" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libnginx-mod-http-auth-pam" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>libnginx-mod-http-auth-pam_1.14.2-2+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">db01a435985144418c4579c4190f642d31295b6e</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-cache-purge" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>libnginx-mod-http-cache-purge_1.14.2-2+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">4fc609b0a0952e2ce19da031cd3c98d2ede80029</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-dav-ext" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>libnginx-mod-http-dav-ext_1.14.2-2+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">5bec9c8e60ccf8e3548dec61ac66b676dee8f3a6</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-echo" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>libnginx-mod-http-echo_1.14.2-2+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">e157654bb32f1262d3b84c409921e1ef4516616d</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-fancyindex" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>libnginx-mod-http-fancyindex_1.14.2-2+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">e987977241ecf23f7023af77acaae26a580eef88</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-geoip" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>libnginx-mod-http-geoip_1.14.2-2+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">7c4686927c55705cabf4a0debfef3302ad913a66</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-headers-more-filter" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>libnginx-mod-http-headers-more-filter_1.14.2-2+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">e7b9b8676ad43cc3098fdd081fa92b3abe372526</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-image-filter" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>libnginx-mod-http-image-filter_1.14.2-2+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">1bbcc0277a8e564a8a89cedd8cec434359fb1961</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-lua" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>libnginx-mod-http-lua_1.14.2-2+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">fece6d2ecef1c71b0dcf789be8cde63332a1a6f2</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-ndk" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>libnginx-mod-http-ndk_1.14.2-2+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">9056d26ddc94e046b0077162b28429deaf1c5c7d</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-perl" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>libnginx-mod-http-perl_1.14.2-2+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">728f0c8583cf5fc779a887097dea79d5fd91096b</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-subs-filter" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>libnginx-mod-http-subs-filter_1.14.2-2+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">36761bba136e33ba75cca80c151055ca41881b6d</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-uploadprogress" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>libnginx-mod-http-uploadprogress_1.14.2-2+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">eadc447108a3a8efb24555b5faaacca319beb5fc</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-upstream-fair" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>libnginx-mod-http-upstream-fair_1.14.2-2+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">e85754c14f6282d96af442eaf605e92e072fd9f8</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-xslt-filter" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>libnginx-mod-http-xslt-filter_1.14.2-2+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">579e0334292ddaf6ef0c9549cd37fc0ee52c48eb</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-mail" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>libnginx-mod-mail_1.14.2-2+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">d29226aab16183d9c66162bbb8bcab109a9624c2</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-nchan" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>libnginx-mod-nchan_1.14.2-2+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">44f0e62699395e1838f195eeea8a504e3d348e1f</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-rtmp" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>libnginx-mod-rtmp_1.14.2-2+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">d1f1497fd55ab1c4ac56871ac1655c13848c0570</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-stream" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>libnginx-mod-stream_1.14.2-2+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">8849d43b962c5a57647414ee4d4ede48228f68af</sum>
        </package>
        <package arch="all" name="nginx" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>nginx_1.14.2-2+deb10u5+tuxcare.els3_all.deb</filename>
          <sum type="sha">78a5e0a8b0cd3b8a25e705baae8341bc8950cbd0</sum>
        </package>
        <package arch="all" name="nginx-common" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>nginx-common_1.14.2-2+deb10u5+tuxcare.els3_all.deb</filename>
          <sum type="sha">725ba3cc6fec727b6a1673ee80aef51af91492ac</sum>
        </package>
        <package arch="all" name="nginx-doc" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>nginx-doc_1.14.2-2+deb10u5+tuxcare.els3_all.deb</filename>
          <sum type="sha">4b0412cd530d4c98ebe58d5fa3bba504c3a0ab67</sum>
        </package>
        <package arch="amd64" name="nginx-extras" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>nginx-extras_1.14.2-2+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">b466475da090f639ff18125990bc899e8cad018e</sum>
        </package>
        <package arch="amd64" name="nginx-full" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>nginx-full_1.14.2-2+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">d5777db69561193d32aa1049b8f7cde8a13e921d</sum>
        </package>
        <package arch="amd64" name="nginx-light" version="1.14.2-2+deb10u5+tuxcare.els3">
          <filename>nginx-light_1.14.2-2+deb10u5+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">4ad2b8f879c3994293e8caceab5876391ad8b8da</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1779869103</id>
    <title>Fix CVE(s): CVE-2024-12086, CVE-2026-29518, CVE-2026-43618</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: receiver process memory disclosure via compressed-token
     integer overflow:
     - debian/patches/els/0004-CVE-2026-43618.patch: cap rx_token at
       MAX_TOKEN_INDEX; reject out-of-range token values.
     - CVE-2026-43618.
   * SECURITY UPDATE: malicious server can enumerate arbitrary client files
     via crafted checksum responses:
     - debian/patches/els/0005-CVE-2024-12086.patch: add secure_relative_open()
       and route the receiver's basis-file open through it.
     - CVE-2024-12086.
   * SECURITY UPDATE: daemon TOCTOU symlink race on parent path components
     when "use chroot = no":
     - debian/patches/els/0006-CVE-2026-29518.patch: gate sender/receiver
       opens and chmods through secure_relative_open() / do_chmod_at().
     - CVE-2026-29518.</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: receiver process memory disclosure via compressed-token
     integer overflow:
     - debian/patches/els/0004-CVE-2026-43618.patch: cap rx_token at
       MAX_TOKEN_INDEX; reject out-of-range token values.
     - CVE-2026-43618.
   * SECURITY UPDATE: malicious server can enumerate arbitrary client files
     via crafted checksum responses:
     - debian/patches/els/0005-CVE-2024-12086.patch: add secure_relative_open()
       and route the receiver's basis-file open through it.
     - CVE-2024-12086.
   * SECURITY UPDATE: daemon TOCTOU symlink race on parent path components
     when "use chroot = no":
     - debian/patches/els/0006-CVE-2026-29518.patch: gate sender/receiver
       opens and chmods through secure_relative_open() / do_chmod_at().
     - CVE-2026-29518.</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-27 08:05:13 UTC" />
    <updated date="2026-05-27 08:05:13 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1779869103.html" id="CLSA-2026:1779869103" title="CLSA-2026:1779869103" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="rsync" version="3.1.3-6+tuxcare.els2">
          <filename>rsync_3.1.3-6+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">bdfe919ceda334a7a9bcabc02a6ba87ba2d8f58f</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1779887887</id>
    <title>Fix CVE(s): CVE-2026-7258</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix out-of-bounds read in urldecode() via signed-char to ctype.h (GHSA-m8rr-4c36-8gq4)
     - debian/patches/CVE-2026-7258.patch: fix out-of-bounds read in urldecode() via signed-char to ctype.h (GHSA-m8rr-4c36-8gq4)
     - CVE-2026-7258</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix out-of-bounds read in urldecode() via signed-char to ctype.h (GHSA-m8rr-4c36-8gq4)
     - debian/patches/CVE-2026-7258.patch: fix out-of-bounds read in urldecode() via signed-char to ctype.h (GHSA-m8rr-4c36-8gq4)
     - CVE-2026-7258</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-27 13:18:18 UTC" />
    <updated date="2026-05-27 13:18:18 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1779887887.html" id="CLSA-2026:1779887887" title="CLSA-2026:1779887887" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libapache2-mod-php7.3" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>libapache2-mod-php7.3_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">b6b3125da9b9c268de63df2519bf54fb7d22c5f2</sum>
        </package>
        <package arch="amd64" name="libphp7.3-embed" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>libphp7.3-embed_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">3a48be6bac96cdef8b55fb3fea35c17674e041df</sum>
        </package>
        <package arch="all" name="php7.3" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3_7.3.31-1~deb10u7+tuxcare.els7_all.deb</filename>
          <sum type="sha">13e895519f65d28e283c4bd0ecd837b86a802b67</sum>
        </package>
        <package arch="amd64" name="php7.3-bcmath" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-bcmath_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">cc06524c36955a77f9b78c4303efc6837b5a99cf</sum>
        </package>
        <package arch="amd64" name="php7.3-bz2" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-bz2_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">c906ec2eccadb81bcb1b04a782a0cb0ccb27ce64</sum>
        </package>
        <package arch="amd64" name="php7.3-cgi" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-cgi_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">edb6889e6010a06019f3b51c41fdffa730a74035</sum>
        </package>
        <package arch="amd64" name="php7.3-cli" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-cli_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">6682d1f654450baab7097864b3bd3e32eb815c47</sum>
        </package>
        <package arch="amd64" name="php7.3-common" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-common_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">3f88c65b9a392f5eaf41ff9938d1fe026a6a52a5</sum>
        </package>
        <package arch="amd64" name="php7.3-curl" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-curl_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">d3a3fa51a0875457671be4efcfb87bdfedc61668</sum>
        </package>
        <package arch="amd64" name="php7.3-dba" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-dba_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">aff17c2eddcd2d0be4921e292419148233be2f16</sum>
        </package>
        <package arch="amd64" name="php7.3-dev" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-dev_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">cd0fecb6c6b0c7a9e2097f57a8e288ccafade26d</sum>
        </package>
        <package arch="amd64" name="php7.3-enchant" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-enchant_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">010af65aa4ef00a003ebe9afd8fc7e34bb9ebf04</sum>
        </package>
        <package arch="amd64" name="php7.3-fpm" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-fpm_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">04eae1707aea1de56289200ad77e04111287b9d9</sum>
        </package>
        <package arch="amd64" name="php7.3-gd" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-gd_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">b92eab32e944d9b56a4800fbc97a2421195c92f3</sum>
        </package>
        <package arch="amd64" name="php7.3-gmp" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-gmp_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">f2bb9c9718a88188d4f49e3d854bf5ead376d6b7</sum>
        </package>
        <package arch="amd64" name="php7.3-imap" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-imap_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">76c50b06850eef77f17f61b9cd1f9d3a786af273</sum>
        </package>
        <package arch="amd64" name="php7.3-interbase" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-interbase_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">586ea117c965d9c8d104de269d218a3c0ea77822</sum>
        </package>
        <package arch="amd64" name="php7.3-intl" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-intl_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">e8769ba0bffabc8621dd2f39f1b3016e8fda21b8</sum>
        </package>
        <package arch="amd64" name="php7.3-json" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-json_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">0ff7f230c9af9b5749234ef8627c084a54111462</sum>
        </package>
        <package arch="amd64" name="php7.3-ldap" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-ldap_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">2d3a8efa563421a5840200e622cacf11cbf27529</sum>
        </package>
        <package arch="amd64" name="php7.3-mbstring" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-mbstring_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">31aa9cc19672e4abaca5e8123f16190668cb3c20</sum>
        </package>
        <package arch="amd64" name="php7.3-mysql" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-mysql_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">54851a1f9157f671ce7790d53f7ab4dcbd7f3b4e</sum>
        </package>
        <package arch="amd64" name="php7.3-odbc" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-odbc_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">40267b8bb72c2fb7f4dd1f6b83ec18c87495dbac</sum>
        </package>
        <package arch="amd64" name="php7.3-opcache" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-opcache_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">5bd9558b2e89a57a3709cda68f831f43a59cc4df</sum>
        </package>
        <package arch="amd64" name="php7.3-pgsql" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-pgsql_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">92b969f5a55ec328bb0bad5934fee4750d8d456e</sum>
        </package>
        <package arch="amd64" name="php7.3-phpdbg" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-phpdbg_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">ee2dadb1101995cb2a507bd38fb0e82fc10d646a</sum>
        </package>
        <package arch="amd64" name="php7.3-pspell" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-pspell_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">790afcd7011383acdc299f102fc1cab57b6f54ff</sum>
        </package>
        <package arch="amd64" name="php7.3-readline" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-readline_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">1b2443433db73dd176becf86d4f7b3549700adf7</sum>
        </package>
        <package arch="amd64" name="php7.3-recode" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-recode_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">d1c257e48ba971e65a0fde5fd5e913642a469389</sum>
        </package>
        <package arch="amd64" name="php7.3-snmp" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-snmp_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">06b45d71728e4c9042e005dfcdfb97e8ffd98309</sum>
        </package>
        <package arch="amd64" name="php7.3-soap" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-soap_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">a6a8840b04665e93baf8d2f4c5ba5f8efbe80038</sum>
        </package>
        <package arch="amd64" name="php7.3-sqlite3" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-sqlite3_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">900d93fe55c8cd08414d3a885ec6d1be52115f33</sum>
        </package>
        <package arch="amd64" name="php7.3-sybase" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-sybase_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">59b2ae8fdc84a74770a8cd27536e2622633dcd38</sum>
        </package>
        <package arch="amd64" name="php7.3-tidy" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-tidy_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">0fb8585538afc2d5e2066f7e5e1d2bd870391942</sum>
        </package>
        <package arch="amd64" name="php7.3-xml" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-xml_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">313e9100967740bdfc029af4a720c6cbdf96feb9</sum>
        </package>
        <package arch="amd64" name="php7.3-xmlrpc" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-xmlrpc_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">9c87efc3189df38edc01ab714a19c4185654cda3</sum>
        </package>
        <package arch="all" name="php7.3-xsl" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-xsl_7.3.31-1~deb10u7+tuxcare.els7_all.deb</filename>
          <sum type="sha">0717a0109e4c37f5c1b457e0b3b0ef4177e6edfb</sum>
        </package>
        <package arch="amd64" name="php7.3-zip" version="7.3.31-1~deb10u7+tuxcare.els7">
          <filename>php7.3-zip_7.3.31-1~deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">8751227929369fe8fbef2b2197e02ca27d9f0cfd</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1779912818</id>
    <title>Fix CVE(s): CVE-2026-42307</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: OS command injection in the netrw plugin via crafted sftp:// or file:// URLs
     - debian/patches/CVE-2026-42307.patch: OS command injection in the netrw plugin via crafted sftp:// or file:// URLs
     - CVE-2026-42307</description>
    <severity>Low</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: OS command injection in the netrw plugin via crafted sftp:// or file:// URLs
     - debian/patches/CVE-2026-42307.patch: OS command injection in the netrw plugin via crafted sftp:// or file:// URLs
     - CVE-2026-42307</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-27 20:13:49 UTC" />
    <updated date="2026-05-27 20:13:49 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1779912818.html" id="CLSA-2026:1779912818" title="CLSA-2026:1779912818" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="vim" version="2:8.1.0875-5+deb10u6+tuxcare.els19">
          <filename>vim_8.1.0875-5+deb10u6+tuxcare.els19_amd64.deb</filename>
          <sum type="sha">f473cf20bc5da294e3684b901490fe426fa8de27</sum>
        </package>
        <package arch="amd64" name="vim-athena" version="2:8.1.0875-5+deb10u6+tuxcare.els19">
          <filename>vim-athena_8.1.0875-5+deb10u6+tuxcare.els19_amd64.deb</filename>
          <sum type="sha">f43cd59d47b9999f620951fb58fb5baf0567487a</sum>
        </package>
        <package arch="all" name="vim-common" version="2:8.1.0875-5+deb10u6+tuxcare.els19">
          <filename>vim-common_8.1.0875-5+deb10u6+tuxcare.els19_all.deb</filename>
          <sum type="sha">4784e8d4c8ddb82c62ff593813d599612dd112dc</sum>
        </package>
        <package arch="all" name="vim-doc" version="2:8.1.0875-5+deb10u6+tuxcare.els19">
          <filename>vim-doc_8.1.0875-5+deb10u6+tuxcare.els19_all.deb</filename>
          <sum type="sha">593fa79018698c47548aa6c58c411318a1c17a76</sum>
        </package>
        <package arch="amd64" name="vim-gtk" version="2:8.1.0875-5+deb10u6+tuxcare.els19">
          <filename>vim-gtk_8.1.0875-5+deb10u6+tuxcare.els19_amd64.deb</filename>
          <sum type="sha">e94c1000bbb00caff8f300d121d577ee33131020</sum>
        </package>
        <package arch="amd64" name="vim-gtk3" version="2:8.1.0875-5+deb10u6+tuxcare.els19">
          <filename>vim-gtk3_8.1.0875-5+deb10u6+tuxcare.els19_amd64.deb</filename>
          <sum type="sha">1f4f3025446f4d90bddcb1f828b5c8a5adbb329b</sum>
        </package>
        <package arch="all" name="vim-gui-common" version="2:8.1.0875-5+deb10u6+tuxcare.els19">
          <filename>vim-gui-common_8.1.0875-5+deb10u6+tuxcare.els19_all.deb</filename>
          <sum type="sha">10ffe3c3f69ef6c8db71b612e605897c56f8e424</sum>
        </package>
        <package arch="amd64" name="vim-nox" version="2:8.1.0875-5+deb10u6+tuxcare.els19">
          <filename>vim-nox_8.1.0875-5+deb10u6+tuxcare.els19_amd64.deb</filename>
          <sum type="sha">0f514cda037985ca83e2a29ff5bfe4f9ed490930</sum>
        </package>
        <package arch="all" name="vim-runtime" version="2:8.1.0875-5+deb10u6+tuxcare.els19">
          <filename>vim-runtime_8.1.0875-5+deb10u6+tuxcare.els19_all.deb</filename>
          <sum type="sha">177aa1cdfae646a284c46450fcfb0b238b2aaa5f</sum>
        </package>
        <package arch="amd64" name="vim-tiny" version="2:8.1.0875-5+deb10u6+tuxcare.els19">
          <filename>vim-tiny_8.1.0875-5+deb10u6+tuxcare.els19_amd64.deb</filename>
          <sum type="sha">ce6db427490cccca18864d58a3d81c5565d9a712</sum>
        </package>
        <package arch="amd64" name="xxd" version="2:8.1.0875-5+deb10u6+tuxcare.els19">
          <filename>xxd_8.1.0875-5+deb10u6+tuxcare.els19_amd64.deb</filename>
          <sum type="sha">fa631ef539b82cd965481ba11364f6f6d247532a</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1779968889</id>
    <title>Fix of 7 CVEs</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Authentication Bypass in digest authentication
     - debian/patches/CVE-2026-43512.patch: reject digest authentication
       attempts for unknown users in getDigest()
     - CVE-2026-43512
   * SECURITY UPDATE: Account lockout bypass in LockOutRealm via case
     variation of user names
     - debian/patches/CVE-2026-43513.patch: add a caseSensitive attribute
       to LockOutRealm and treat user names case-insensitively by default
     - CVE-2026-43513
   * SECURITY UPDATE: Observable timing discrepancy in AJP secret comparison
     - debian/patches/CVE-2026-43514.patch: add ConstantTime helper and
       switch the AJP secret comparison to a constant time algorithm
     - CVE-2026-43514
   * SECURITY UPDATE: Improper authorisation when multiple method
     constraints define an HTTP method for the same extension
     - debian/patches/CVE-2026-43515.patch: evaluate findMethod() against
       every matching SecurityCollection rather than only the last one
     - CVE-2026-43515
   * SECURITY UPDATE: Exposure of HTTP authorisation header to unexpected
     hosts during WebSocket authentication
     - debian/patches/CVE-2026-42498.patch: drop the cached Authorization
       header from userProperties before following a WebSocket upgrade
       redirect so it is not sent to the host named in Location
     - CVE-2026-42498
   * SECURITY UPDATE: HTTP/2 header values were not validated for control
     characters and other illegal bytes
     - debian/patches/CVE-2026-41293.patch: validate field names and values
       in HpackDecoder and HPackHuffman using the new HttpParser
       isFieldVChar / isFieldContent tables
     - CVE-2026-41293
   * SECURITY UPDATE: Allocation of resources without limits in WebDAV
     LOCK and PROPFIND request bodies
     - debian/patches/CVE-2026-41284.patch: read PROPFIND and LOCK bodies
       through a new BoundedByteArrayOutputStream limited by the new
       maxRequestBodySize init parameter (default 4096 bytes)
     - CVE-2026-41284</description>
    <severity>Low</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Authentication Bypass in digest authentication
     - debian/patches/CVE-2026-43512.patch: reject digest authentication
       attempts for unknown users in getDigest()
     - CVE-2026-43512
   * SECURITY UPDATE: Account lockout bypass in LockOutRealm via case
     variation of user names
     - debian/patches/CVE-2026-43513.patch: add a caseSensitive attribute
       to LockOutRealm and treat user names case-insensitively by default
     - CVE-2026-43513
   * SECURITY UPDATE: Observable timing discrepancy in AJP secret comparison
     - debian/patches/CVE-2026-43514.patch: add ConstantTime helper and
       switch the AJP secret comparison to a constant time algorithm
     - CVE-2026-43514
   * SECURITY UPDATE: Improper authorisation when multiple method
     constraints define an HTTP method for the same extension
     - debian/patches/CVE-2026-43515.patch: evaluate findMethod() against
       every matching SecurityCollection rather than only the last one
     - CVE-2026-43515
   * SECURITY UPDATE: Exposure of HTTP authorisation header to unexpected
     hosts during WebSocket authentication
     - debian/patches/CVE-2026-42498.patch: drop the cached Authorization
       header from userProperties before following a WebSocket upgrade
       redirect so it is not sent to the host named in Location
     - CVE-2026-42498
   * SECURITY UPDATE: HTTP/2 header values were not validated for control
     characters and other illegal bytes
     - debian/patches/CVE-2026-41293.patch: validate field names and values
       in HpackDecoder and HPackHuffman using the new HttpParser
       isFieldVChar / isFieldContent tables
     - CVE-2026-41293
   * SECURITY UPDATE: Allocation of resources without limits in WebDAV
     LOCK and PROPFIND request bodies
     - debian/patches/CVE-2026-41284.patch: read PROPFIND and LOCK bodies
       through a new BoundedByteArrayOutputStream limited by the new
       maxRequestBodySize init parameter (default 4096 bytes)
     - CVE-2026-41284</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-28 14:02:01 UTC" />
    <updated date="2026-05-28 14:02:01 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1779968889.html" id="CLSA-2026:1779968889" title="CLSA-2026:1779968889" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="all" name="libtomcat9-embed-java" version="9.0.31-1~deb10u12+tuxcare.els5">
          <filename>libtomcat9-embed-java_9.0.31-1~deb10u12+tuxcare.els5_all.deb</filename>
          <sum type="sha">2d969cfeb8f2d2e05570b2277745b4f528506ddf</sum>
        </package>
        <package arch="all" name="libtomcat9-java" version="9.0.31-1~deb10u12+tuxcare.els5">
          <filename>libtomcat9-java_9.0.31-1~deb10u12+tuxcare.els5_all.deb</filename>
          <sum type="sha">8921f592921fc6989ead896f320808351b82d94d</sum>
        </package>
        <package arch="all" name="tomcat9" version="9.0.31-1~deb10u12+tuxcare.els5">
          <filename>tomcat9_9.0.31-1~deb10u12+tuxcare.els5_all.deb</filename>
          <sum type="sha">17c9d875467153bd39659c057cd07fc2ec12e910</sum>
        </package>
        <package arch="all" name="tomcat9-admin" version="9.0.31-1~deb10u12+tuxcare.els5">
          <filename>tomcat9-admin_9.0.31-1~deb10u12+tuxcare.els5_all.deb</filename>
          <sum type="sha">64215f5453cf59ad05b471bf461e7acf2875daba</sum>
        </package>
        <package arch="all" name="tomcat9-common" version="9.0.31-1~deb10u12+tuxcare.els5">
          <filename>tomcat9-common_9.0.31-1~deb10u12+tuxcare.els5_all.deb</filename>
          <sum type="sha">6d9917abfeab96706638de832758695267f82680</sum>
        </package>
        <package arch="all" name="tomcat9-docs" version="9.0.31-1~deb10u12+tuxcare.els5">
          <filename>tomcat9-docs_9.0.31-1~deb10u12+tuxcare.els5_all.deb</filename>
          <sum type="sha">534c50c9e65fa0780933dfdd383bfac2da1a92a1</sum>
        </package>
        <package arch="all" name="tomcat9-examples" version="9.0.31-1~deb10u12+tuxcare.els5">
          <filename>tomcat9-examples_9.0.31-1~deb10u12+tuxcare.els5_all.deb</filename>
          <sum type="sha">27e3bed5a471944c00717a5bf5111630bb9d456f</sum>
        </package>
        <package arch="all" name="tomcat9-user" version="9.0.31-1~deb10u12+tuxcare.els5">
          <filename>tomcat9-user_9.0.31-1~deb10u12+tuxcare.els5_all.deb</filename>
          <sum type="sha">e8971b06aad709739d776baa73d42a6146545535</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1780061802</id>
    <title>Fix CVE(s): CVE-2026-42050</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix stack-based buffer overflow in XTileImage() triggered by a malicious MIFF file when right-clicking a tile to invoke the Load / Update menu item
     - debian/patches/CVE-2026-42050.patch: fix stack-based buffer overflow in XTileImage() triggered by a malicious MIFF file when right-clicking a tile to invoke the Load / Update menu item
     - CVE-2026-42050</description>
    <severity>Low</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix stack-based buffer overflow in XTileImage() triggered by a malicious MIFF file when right-clicking a tile to invoke the Load / Update menu item
     - debian/patches/CVE-2026-42050.patch: fix stack-based buffer overflow in XTileImage() triggered by a malicious MIFF file when right-clicking a tile to invoke the Load / Update menu item
     - CVE-2026-42050</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-29 14:22:27 UTC" />
    <updated date="2026-05-29 14:22:27 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1780061802.html" id="CLSA-2026:1780061802" title="CLSA-2026:1780061802" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="imagemagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>imagemagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">6227e8081fbc2b0e2ecc3e3290283c1ce919bffc</sum>
        </package>
        <package arch="all" name="imagemagick-6-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>imagemagick-6-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_all.deb</filename>
          <sum type="sha">374e039a5839fea06a9058c93178571990129c81</sum>
        </package>
        <package arch="all" name="imagemagick-6-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>imagemagick-6-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_all.deb</filename>
          <sum type="sha">5336944fab147f755d048a13cbba8ec3d8f2a5db</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>imagemagick-6.q16_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">7240323ff6dfe87bf8cfdb085f81c9f6108c46de</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16hdri" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>imagemagick-6.q16hdri_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">f6596d4ae9c830c24f92f005b21ff3472e65ee69</sum>
        </package>
        <package arch="all" name="imagemagick-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>imagemagick-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_all.deb</filename>
          <sum type="sha">530e75ecd379e7afd19d441186a9cd39bd142ad4</sum>
        </package>
        <package arch="all" name="imagemagick-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>imagemagick-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_all.deb</filename>
          <sum type="sha">932692ee8e1f95b40f04e746fb86b3dc45261077</sum>
        </package>
        <package arch="all" name="libimage-magick-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libimage-magick-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_all.deb</filename>
          <sum type="sha">f3d0b872763a4be16d2b53f37a95420855b150ce</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libimage-magick-q16-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">e396e32ae9239263830fdee4d510c66ad624108f</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16hdri-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libimage-magick-q16hdri-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">a515470ecea9154403ee7d8104fee7ca7627de3b</sum>
        </package>
        <package arch="all" name="libmagick++-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libmagick++-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_all.deb</filename>
          <sum type="sha">2a0712e0d6fb66063bbbdd6dbbb15de535f0563a</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libmagick++-6.q16-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">7a4b037aa16fdb9dc3611cd6020d1671b2ac4a9a</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libmagick++-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">b4d1f3bb416b2a878afae63ccc7f4da261ae06d9</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libmagick++-6.q16hdri-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">2ae5ccf1329539112231168f52d8748e75277623</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libmagick++-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">58cca27400666b64b878db9930b0ddedeaab3f0b</sum>
        </package>
        <package arch="all" name="libmagick++-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libmagick++-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_all.deb</filename>
          <sum type="sha">e2b8714791c053167089f152dac0e2b98a9e6d6c</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6-arch-config" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libmagickcore-6-arch-config_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">022720c8c2c06c320691b3686dce847ba0894812</sum>
        </package>
        <package arch="all" name="libmagickcore-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libmagickcore-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_all.deb</filename>
          <sum type="sha">06e45ceca9826267000897d37b33a3880728d6b3</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libmagickcore-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">e9d6c1a64491c79e4ab36b345490e6a63856f190</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libmagickcore-6.q16-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">6495a73fdbd19c764c260d98c9759282d2ed31e9</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libmagickcore-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">45f396ac6b4c9bb1db4275679f97c3ee4c1c047e</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libmagickcore-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">373fa683a6bc7bdc024e492181f116707f8009b1</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libmagickcore-6.q16hdri-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">3365ae5e021481691d909bb7c2ba9405d2a3a73a</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libmagickcore-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">ac0634cd2b801d08d22bb5672365ab0bd218a27e</sum>
        </package>
        <package arch="all" name="libmagickcore-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libmagickcore-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_all.deb</filename>
          <sum type="sha">e6e9d33f8245b63dcb70758d4d96e72cea858232</sum>
        </package>
        <package arch="all" name="libmagickwand-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libmagickwand-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_all.deb</filename>
          <sum type="sha">dc24a8f8f063720ff568116627ebef0af11562ab</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libmagickwand-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">a7cbfa99e4dbc9a72c7d099d6930136ddeb13439</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libmagickwand-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">c4095aa2552d736953cefc500415e7b428f62aa5</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libmagickwand-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">7e4d820842ec089b4c81c4ccff344925a344304e</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libmagickwand-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">4704869a9bab451e2693bcfc2691dbc61b4338bb</sum>
        </package>
        <package arch="all" name="libmagickwand-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>libmagickwand-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_all.deb</filename>
          <sum type="sha">9cbf82e1b0b33bbe39970ca50f8ad5df4c508602</sum>
        </package>
        <package arch="all" name="perlmagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7">
          <filename>perlmagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els7_all.deb</filename>
          <sum type="sha">9e04161b0406ab71c81430123cb425c3dd43f854</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1780062671</id>
    <title>Fix CVE(s): CVE-2026-41035</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: receiver use-after-free in receive_xattr() via a
     wire-supplied xattr count passed to qsort():
     - debian/patches/els/0007-CVE-2026-41035.patch: sort temp_xattr.count
       stored items instead of the untrusted wire count.
     - CVE-2026-41035.</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: receiver use-after-free in receive_xattr() via a
     wire-supplied xattr count passed to qsort():
     - debian/patches/els/0007-CVE-2026-41035.patch: sort temp_xattr.count
       stored items instead of the untrusted wire count.
     - CVE-2026-41035.</summary>
    <pushcount>0</pushcount>
    <issued date="2026-05-29 14:28:14 UTC" />
    <updated date="2026-05-29 14:28:14 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1780062671.html" id="CLSA-2026:1780062671" title="CLSA-2026:1780062671" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="rsync" version="3.1.3-6+tuxcare.els3">
          <filename>rsync_3.1.3-6+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">42ab8aeedd50715c5d3988e065c67092e6a58950</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1780388996</id>
    <title>Fix CVE(s): CVE-2026-46483</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: OS command injection in tar#Vimuntar() in runtime/autoload/tar.vim via crafted .tgz filename (use shellescape(tartail, 1) for :! commands)
     - debian/patches/CVE-2026-46483.patch: OS command injection in tar#Vimuntar() in runtime/autoload/tar.vim via crafted .tgz filename (use shellescape(tartail, 1) for :! commands)
     - CVE-2026-46483</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: OS command injection in tar#Vimuntar() in runtime/autoload/tar.vim via crafted .tgz filename (use shellescape(tartail, 1) for :! commands)
     - debian/patches/CVE-2026-46483.patch: OS command injection in tar#Vimuntar() in runtime/autoload/tar.vim via crafted .tgz filename (use shellescape(tartail, 1) for :! commands)
     - CVE-2026-46483</summary>
    <pushcount>0</pushcount>
    <issued date="2026-06-02 08:30:09 UTC" />
    <updated date="2026-06-02 08:30:09 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1780388996.html" id="CLSA-2026:1780388996" title="CLSA-2026:1780388996" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-46483" id="CVE-2026-46483" title="CVE-2026-46483" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="vim" version="2:8.1.0875-5+deb10u6+tuxcare.els20">
          <filename>vim_8.1.0875-5+deb10u6+tuxcare.els20_amd64.deb</filename>
          <sum type="sha">440fab1f2dfeec2434028148dd4870b7847453cb</sum>
        </package>
        <package arch="amd64" name="vim-athena" version="2:8.1.0875-5+deb10u6+tuxcare.els20">
          <filename>vim-athena_8.1.0875-5+deb10u6+tuxcare.els20_amd64.deb</filename>
          <sum type="sha">93b91e8cc6e639840f0894e61362ee975e86e242</sum>
        </package>
        <package arch="all" name="vim-common" version="2:8.1.0875-5+deb10u6+tuxcare.els20">
          <filename>vim-common_8.1.0875-5+deb10u6+tuxcare.els20_all.deb</filename>
          <sum type="sha">bc0c4c08e72cf08b41e3bc132d09839ecd379c9d</sum>
        </package>
        <package arch="all" name="vim-doc" version="2:8.1.0875-5+deb10u6+tuxcare.els20">
          <filename>vim-doc_8.1.0875-5+deb10u6+tuxcare.els20_all.deb</filename>
          <sum type="sha">9a970380d1980d8a0064324dc83224c026a02931</sum>
        </package>
        <package arch="amd64" name="vim-gtk" version="2:8.1.0875-5+deb10u6+tuxcare.els20">
          <filename>vim-gtk_8.1.0875-5+deb10u6+tuxcare.els20_amd64.deb</filename>
          <sum type="sha">cd3feb99609735a047e4509a429503214ba0cead</sum>
        </package>
        <package arch="amd64" name="vim-gtk3" version="2:8.1.0875-5+deb10u6+tuxcare.els20">
          <filename>vim-gtk3_8.1.0875-5+deb10u6+tuxcare.els20_amd64.deb</filename>
          <sum type="sha">7fb80fe74aac720fb7dee16f4ced3ddcaad0bea2</sum>
        </package>
        <package arch="all" name="vim-gui-common" version="2:8.1.0875-5+deb10u6+tuxcare.els20">
          <filename>vim-gui-common_8.1.0875-5+deb10u6+tuxcare.els20_all.deb</filename>
          <sum type="sha">acfc4945d5cf280730e0dd28749048d88143f1fb</sum>
        </package>
        <package arch="amd64" name="vim-nox" version="2:8.1.0875-5+deb10u6+tuxcare.els20">
          <filename>vim-nox_8.1.0875-5+deb10u6+tuxcare.els20_amd64.deb</filename>
          <sum type="sha">c026ef6333a18557c11e562f72cbe25165c8606c</sum>
        </package>
        <package arch="all" name="vim-runtime" version="2:8.1.0875-5+deb10u6+tuxcare.els20">
          <filename>vim-runtime_8.1.0875-5+deb10u6+tuxcare.els20_all.deb</filename>
          <sum type="sha">ee79044b2f783faad1a0b0f2cc71737f2c964ef2</sum>
        </package>
        <package arch="amd64" name="vim-tiny" version="2:8.1.0875-5+deb10u6+tuxcare.els20">
          <filename>vim-tiny_8.1.0875-5+deb10u6+tuxcare.els20_amd64.deb</filename>
          <sum type="sha">bd1105990ad2b0b604f669e23b87c970c74f175b</sum>
        </package>
        <package arch="amd64" name="xxd" version="2:8.1.0875-5+deb10u6+tuxcare.els20">
          <filename>xxd_8.1.0875-5+deb10u6+tuxcare.els20_amd64.deb</filename>
          <sum type="sha">83b425a544b87f3bbd42450b161de6fc9e3e1fda</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1780476189</id>
    <title>Fix CVE(s): CVE-2026-5946</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: restrict DNS operations (recursion, UPDATE, NOTIFY) to class IN only
     - debian/patches/CVE-2026-5946.patch: restrict DNS operations (recursion, UPDATE, NOTIFY) to class IN only
     - CVE-2026-5946</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: restrict DNS operations (recursion, UPDATE, NOTIFY) to class IN only
     - debian/patches/CVE-2026-5946.patch: restrict DNS operations (recursion, UPDATE, NOTIFY) to class IN only
     - CVE-2026-5946</summary>
    <pushcount>0</pushcount>
    <issued date="2026-06-03 08:43:21 UTC" />
    <updated date="2026-06-03 08:43:21 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1780476189.html" id="CLSA-2026:1780476189" title="CLSA-2026:1780476189" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-5946" id="CVE-2026-5946" title="CVE-2026-5946" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="bind9" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2">
          <filename>bind9_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">40af1d6bfc8d1aac032f18327f4747928813da1a</sum>
        </package>
        <package arch="all" name="bind9-doc" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2">
          <filename>bind9-doc_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2_all.deb</filename>
          <sum type="sha">dfdaa8f30786b3617db3ed986d478750d73b6764</sum>
        </package>
        <package arch="amd64" name="bind9-host" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2">
          <filename>bind9-host_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">bc072fe836960f4340eb2e6d871aa3d8fae30240</sum>
        </package>
        <package arch="amd64" name="bind9utils" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2">
          <filename>bind9utils_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">96453b97645c919f8b628dc5c1c3858fc4282958</sum>
        </package>
        <package arch="amd64" name="dnsutils" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2">
          <filename>dnsutils_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">3cb5c3c890897c7bf5efb0fe1909bdd6f8c03f17</sum>
        </package>
        <package arch="amd64" name="libbind-dev" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2">
          <filename>libbind-dev_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">a7011385b83fc50880c6c3c025810d597e9f04f9</sum>
        </package>
        <package arch="amd64" name="libbind-export-dev" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2">
          <filename>libbind-export-dev_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">689c12fa3363397ffd9d5c6cbd372f3753b0c501</sum>
        </package>
        <package arch="amd64" name="libbind9-161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2">
          <filename>libbind9-161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">2823351a40f7040d64160b204174a75e7b1f32ff</sum>
        </package>
        <package arch="amd64" name="libdns-export1104" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2">
          <filename>libdns-export1104_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">6a32ede381fc18f38ced2ccaca54f4c0352b2f69</sum>
        </package>
        <package arch="amd64" name="libdns1104" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2">
          <filename>libdns1104_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">4a22b2befb267ccdb7a3a8974070f179f7614e62</sum>
        </package>
        <package arch="amd64" name="libirs-export161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2">
          <filename>libirs-export161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">b8c82834efab2c56ad09815247f08fb57f0d7f34</sum>
        </package>
        <package arch="amd64" name="libirs161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2">
          <filename>libirs161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">4233bd93b4809921defef2de32304263dfd4018a</sum>
        </package>
        <package arch="amd64" name="libisc-export1100" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2">
          <filename>libisc-export1100_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">1f89e9ed88d0f0106ab55d7829b9cb591d5c5079</sum>
        </package>
        <package arch="amd64" name="libisc1100" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2">
          <filename>libisc1100_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">26e9de6cbc22f49e04998fb91c559252d10e3383</sum>
        </package>
        <package arch="amd64" name="libisccc-export161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2">
          <filename>libisccc-export161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">c17c4106056debbbc58169923976e307390e1b9b</sum>
        </package>
        <package arch="amd64" name="libisccc161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2">
          <filename>libisccc161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">05697186e688522f94609c00c1ec45d0e8a3da85</sum>
        </package>
        <package arch="amd64" name="libisccfg-export163" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2">
          <filename>libisccfg-export163_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">bc93447977eadb696ac0afd37799a9d0adb8b1ac</sum>
        </package>
        <package arch="amd64" name="libisccfg163" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2">
          <filename>libisccfg163_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">0591ee932b8b5d2829ed1ea9529e614cf0bdfada</sum>
        </package>
        <package arch="amd64" name="liblwres161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2">
          <filename>liblwres161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">d01c232cfca02f7bde0741dfb0f10cab76ff49fe</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1780477837</id>
    <title>Fix CVE(s): CVE-2026-8376</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: heap buffer overflow in regex compilation with repeated fixed string on 32-bit builds
     - debian/patches/fixes/CVE-2026-8376.patch: add SSize_t overflow check
       before SvGROW in Perl_study_chunk()
     - CVE-2026-8376</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: heap buffer overflow in regex compilation with repeated fixed string on 32-bit builds
     - debian/patches/fixes/CVE-2026-8376.patch: add SSize_t overflow check
       before SvGROW in Perl_study_chunk()
     - CVE-2026-8376</summary>
    <pushcount>0</pushcount>
    <issued date="2026-06-03 09:10:52 UTC" />
    <updated date="2026-06-03 09:10:52 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1780477837.html" id="CLSA-2026:1780477837" title="CLSA-2026:1780477837" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-8376" id="CVE-2026-8376" title="CVE-2026-8376" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libperl-dev" version="5.28.1-6+deb10u1+tuxcare.els2">
          <filename>libperl-dev_5.28.1-6+deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">f4424b173768f58c7fd3951e6c3882e76abccffc</sum>
        </package>
        <package arch="amd64" name="libperl5.28" version="5.28.1-6+deb10u1+tuxcare.els2">
          <filename>libperl5.28_5.28.1-6+deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">9df5e03a54af1b7803964ca25cbc60267ec018b2</sum>
        </package>
        <package arch="amd64" name="perl" version="5.28.1-6+deb10u1+tuxcare.els2">
          <filename>perl_5.28.1-6+deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">b545bdb08239de174c90802a6d6004ee73805a7c</sum>
        </package>
        <package arch="amd64" name="perl-base" version="5.28.1-6+deb10u1+tuxcare.els2">
          <filename>perl-base_5.28.1-6+deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">1b9611ef1ede561327b973a99ce18fb1c7b83f62</sum>
        </package>
        <package arch="amd64" name="perl-debug" version="5.28.1-6+deb10u1+tuxcare.els2">
          <filename>perl-debug_5.28.1-6+deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">18e9a9f73406ef028836733abd598a9c14dc06f1</sum>
        </package>
        <package arch="all" name="perl-doc" version="5.28.1-6+deb10u1+tuxcare.els2">
          <filename>perl-doc_5.28.1-6+deb10u1+tuxcare.els2_all.deb</filename>
          <sum type="sha">994eca441aa475adb5dd1e1615b7c2c90c8a547d</sum>
        </package>
        <package arch="all" name="perl-modules-5.28" version="5.28.1-6+deb10u1+tuxcare.els2">
          <filename>perl-modules-5.28_5.28.1-6+deb10u1+tuxcare.els2_all.deb</filename>
          <sum type="sha">45d652e94b1585213082d14cad43c1ec060d09b6</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1780567799</id>
    <title>Fix CVE(s): CVE-2026-35535</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: make a privilege drop failure before running the mailer fatal
     - debian/patches/CVE-2026-35535.patch: make a privilege drop failure before running the mailer fatal
     - CVE-2026-35535</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: make a privilege drop failure before running the mailer fatal
     - debian/patches/CVE-2026-35535.patch: make a privilege drop failure before running the mailer fatal
     - CVE-2026-35535</summary>
    <pushcount>0</pushcount>
    <issued date="2026-06-04 10:10:17 UTC" />
    <updated date="2026-06-04 10:10:17 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1780567799.html" id="CLSA-2026:1780567799" title="CLSA-2026:1780567799" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-35535" id="CVE-2026-35535" title="CVE-2026-35535" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="sudo" version="1.8.27-1+deb10u6+tuxcare.els2">
          <filename>sudo_1.8.27-1+deb10u6+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">c378b95d7f155724c18814595ceabecf74e61e33</sum>
        </package>
        <package arch="amd64" name="sudo-ldap" version="1.8.27-1+deb10u6+tuxcare.els2">
          <filename>sudo-ldap_1.8.27-1+deb10u6+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">325dc0abb3d2d7bcb3110e52b2e6219997b1f276</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1780672758</id>
    <title>Fix CVE(s): CVE-2026-41080</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Insufficient entropy used for hash flooding protection allowing hash flooding via a crafted XML document (libexpat before 2.8.0)
     - debian/patches/CVE-2026-41080.patch: extract 16 bytes of entropy
       into a 128-bit SipHash key for hash flooding protection, and add the
       new XML_SetHashSalt16Bytes() API (backport of upstream PR #1183)
     - debian/libexpat1.symbols: add XML_SetHashSalt16Bytes
     - CVE-2026-41080</description>
    <severity>Low</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Insufficient entropy used for hash flooding protection allowing hash flooding via a crafted XML document (libexpat before 2.8.0)
     - debian/patches/CVE-2026-41080.patch: extract 16 bytes of entropy
       into a 128-bit SipHash key for hash flooding protection, and add the
       new XML_SetHashSalt16Bytes() API (backport of upstream PR #1183)
     - debian/libexpat1.symbols: add XML_SetHashSalt16Bytes
     - CVE-2026-41080</summary>
    <pushcount>0</pushcount>
    <issued date="2026-06-05 15:19:40 UTC" />
    <updated date="2026-06-05 15:19:40 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1780672758.html" id="CLSA-2026:1780672758" title="CLSA-2026:1780672758" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-41080" id="CVE-2026-41080" title="CVE-2026-41080" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="expat" version="2.2.6-2+deb10u7+tuxcare.els6">
          <filename>expat_2.2.6-2+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">ba7a41e8a619213ab51f17d02e8fed4623f73df3</sum>
        </package>
        <package arch="amd64" name="libexpat1" version="2.2.6-2+deb10u7+tuxcare.els6">
          <filename>libexpat1_2.2.6-2+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">9a7367c5fe9290c964d7aad7e31262699b305299</sum>
        </package>
        <package arch="amd64" name="libexpat1-dev" version="2.2.6-2+deb10u7+tuxcare.els6">
          <filename>libexpat1-dev_2.2.6-2+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">192287188a9ef707a9a5beaad4ff9302b39de7ea</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1780993103</id>
    <title>Fix CVE(s): CVE-2026-6474, CVE-2026-6478, CVE-2026-6637</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Fix stack buffer overrun and SQL injection in refint contrib module
     - debian/patches/CVE-2026-6637.patch: Fix stack buffer overrun and
       SQL injection in refint contrib module, plus follow-up segfault fix
       in check_foreign_key() when a CASCADE update key value is NULL
     - CVE-2026-6637
   * SECURITY UPDATE: Fix format-string memory disclosure via crafted time zone in timeofday() (also harden pg_strftime() error handling)
     - debian/patches/CVE-2026-6474.patch: Fix format-string memory disclosure via crafted time zone in timeofday() (also harden pg_strftime() error handling)
     - CVE-2026-6474
   * SECURITY UPDATE: Use timingsafe_bcmp() in MD5 password and RADIUS authentication paths to prevent timing side-channel
     - debian/patches/CVE-2026-6478.patch: Use timingsafe_bcmp() in MD5 password and RADIUS authentication paths to prevent timing side-channel
     - CVE-2026-6478</description>
    <severity>Low</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Fix stack buffer overrun and SQL injection in refint contrib module
     - debian/patches/CVE-2026-6637.patch: Fix stack buffer overrun and
       SQL injection in refint contrib module, plus follow-up segfault fix
       in check_foreign_key() when a CASCADE update key value is NULL
     - CVE-2026-6637
   * SECURITY UPDATE: Fix format-string memory disclosure via crafted time zone in timeofday() (also harden pg_strftime() error handling)
     - debian/patches/CVE-2026-6474.patch: Fix format-string memory disclosure via crafted time zone in timeofday() (also harden pg_strftime() error handling)
     - CVE-2026-6474
   * SECURITY UPDATE: Use timingsafe_bcmp() in MD5 password and RADIUS authentication paths to prevent timing side-channel
     - debian/patches/CVE-2026-6478.patch: Use timingsafe_bcmp() in MD5 password and RADIUS authentication paths to prevent timing side-channel
     - CVE-2026-6478</summary>
    <pushcount>0</pushcount>
    <issued date="2026-06-09 08:18:43 UTC" />
    <updated date="2026-06-09 08:18:43 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1780993103.html" id="CLSA-2026:1780993103" title="CLSA-2026:1780993103" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-6474" id="CVE-2026-6474" title="CVE-2026-6474" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-6478" id="CVE-2026-6478" title="CVE-2026-6478" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-6637" id="CVE-2026-6637" title="CVE-2026-6637" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libecpg-compat3-9.6" version="9.6.24-0+deb10u1+tuxcare.els2">
          <filename>libecpg-compat3-9.6_9.6.24-0+deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">6c0bbd875f8ee9ae71af9d12a4939efcc60668ac</sum>
        </package>
        <package arch="amd64" name="libecpg-dev-9.6" version="9.6.24-0+deb10u1+tuxcare.els2">
          <filename>libecpg-dev-9.6_9.6.24-0+deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">e27520b4a04e950eea3c80406499d5262cf7aa83</sum>
        </package>
        <package arch="amd64" name="libecpg6-9.6" version="9.6.24-0+deb10u1+tuxcare.els2">
          <filename>libecpg6-9.6_9.6.24-0+deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">ccbb24b48fd09d0827fd8f63db555baf227ab01d</sum>
        </package>
        <package arch="amd64" name="libpgtypes3-9.6" version="9.6.24-0+deb10u1+tuxcare.els2">
          <filename>libpgtypes3-9.6_9.6.24-0+deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">42542e4e9fbcaec1cde78a7caacec040601dda77</sum>
        </package>
        <package arch="amd64" name="libpq-dev-9.6" version="9.6.24-0+deb10u1+tuxcare.els2">
          <filename>libpq-dev-9.6_9.6.24-0+deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">642e65927fa5a8a95e55939e8f33e5e6cd8cc22b</sum>
        </package>
        <package arch="amd64" name="libpq5-9.6" version="9.6.24-0+deb10u1+tuxcare.els2">
          <filename>libpq5-9.6_9.6.24-0+deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">77badc5c8a6c0c75a42653b4a2204541b2ccb27d</sum>
        </package>
        <package arch="amd64" name="postgresql-9.6" version="9.6.24-0+deb10u1+tuxcare.els2">
          <filename>postgresql-9.6_9.6.24-0+deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">d5f6694198e9b9534eb4c3867944b605175333fb</sum>
        </package>
        <package arch="amd64" name="postgresql-client-9.6" version="9.6.24-0+deb10u1+tuxcare.els2">
          <filename>postgresql-client-9.6_9.6.24-0+deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">6ab16db245c402bbbfa9895e4b2fc76ae132e727</sum>
        </package>
        <package arch="amd64" name="postgresql-contrib-9.6" version="9.6.24-0+deb10u1+tuxcare.els2">
          <filename>postgresql-contrib-9.6_9.6.24-0+deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">856970b1854b4bdc1b519cd95c9589d249907902</sum>
        </package>
        <package arch="all" name="postgresql-doc-9.6" version="9.6.24-0+deb10u1+tuxcare.els2">
          <filename>postgresql-doc-9.6_9.6.24-0+deb10u1+tuxcare.els2_all.deb</filename>
          <sum type="sha">f0c29a7a266ac002aa85749966badf8090bed382</sum>
        </package>
        <package arch="amd64" name="postgresql-plperl-9.6" version="9.6.24-0+deb10u1+tuxcare.els2">
          <filename>postgresql-plperl-9.6_9.6.24-0+deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">3f42da30d9744f1f4b28c0f2583bed0f38c32388</sum>
        </package>
        <package arch="amd64" name="postgresql-plpython-9.6" version="9.6.24-0+deb10u1+tuxcare.els2">
          <filename>postgresql-plpython-9.6_9.6.24-0+deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">96053611db63061e46542db20296d3ee4f86918f</sum>
        </package>
        <package arch="amd64" name="postgresql-plpython3-9.6" version="9.6.24-0+deb10u1+tuxcare.els2">
          <filename>postgresql-plpython3-9.6_9.6.24-0+deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">1c0d7f0ed5e7fb38e984b9bd3511f0d7ce85767c</sum>
        </package>
        <package arch="amd64" name="postgresql-pltcl-9.6" version="9.6.24-0+deb10u1+tuxcare.els2">
          <filename>postgresql-pltcl-9.6_9.6.24-0+deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">490a9eb6a35cfb23b1ea846d02ee3cb34e45222f</sum>
        </package>
        <package arch="amd64" name="postgresql-server-dev-9.6" version="9.6.24-0+deb10u1+tuxcare.els2">
          <filename>postgresql-server-dev-9.6_9.6.24-0+deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">44c99c8c553ca79b5562c8ea112b7afb53caa05c</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1781168947</id>
    <title>Fix CVE(s): CVE-2026-3039</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: named configured for TKEY GSS-API authentication could be driven to excessive memory consumption via crafted TKEY queries (GSS-API context leak on incomplete negotiation)
     - debian/patches/CVE-2026-3039.patch: named configured for TKEY GSS-API authentication could be driven to excessive memory consumption via crafted TKEY queries (GSS-API context leak on incomplete negotiation)
     - CVE-2026-3039</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: named configured for TKEY GSS-API authentication could be driven to excessive memory consumption via crafted TKEY queries (GSS-API context leak on incomplete negotiation)
     - debian/patches/CVE-2026-3039.patch: named configured for TKEY GSS-API authentication could be driven to excessive memory consumption via crafted TKEY queries (GSS-API context leak on incomplete negotiation)
     - CVE-2026-3039</summary>
    <pushcount>0</pushcount>
    <issued date="2026-06-11 10:06:15 UTC" />
    <updated date="2026-06-11 10:06:15 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1781168947.html" id="CLSA-2026:1781168947" title="CLSA-2026:1781168947" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-3039" id="CVE-2026-3039" title="CVE-2026-3039" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="bind9" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3">
          <filename>bind9_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">9622f36203c23c4ba86b6ec7fb980bd950cbf413</sum>
        </package>
        <package arch="all" name="bind9-doc" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3">
          <filename>bind9-doc_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3_all.deb</filename>
          <sum type="sha">9d3167943038bfe9b59e8089c16f61cd33045471</sum>
        </package>
        <package arch="amd64" name="bind9-host" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3">
          <filename>bind9-host_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">2788b2f52ad5d59ce3ac7d778234eaf9db28cfd7</sum>
        </package>
        <package arch="amd64" name="bind9utils" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3">
          <filename>bind9utils_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">687d882b6a612fe1a1bb95182c0afa3e715159fb</sum>
        </package>
        <package arch="amd64" name="dnsutils" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3">
          <filename>dnsutils_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">963091a435286814aae20ec8506850d3a20ed40c</sum>
        </package>
        <package arch="amd64" name="libbind-dev" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3">
          <filename>libbind-dev_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">50e2bbadfbdba9c2af47939245102d849fde726c</sum>
        </package>
        <package arch="amd64" name="libbind-export-dev" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3">
          <filename>libbind-export-dev_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">817af3f5bb056b2bac316cb14e9706939c347430</sum>
        </package>
        <package arch="amd64" name="libbind9-161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3">
          <filename>libbind9-161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">be7f2a5ea4bd21038893f161292c2fb8f7f359fb</sum>
        </package>
        <package arch="amd64" name="libdns-export1104" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3">
          <filename>libdns-export1104_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">ecfebc96c72c114fe28832458fdda7bc611d0dc2</sum>
        </package>
        <package arch="amd64" name="libdns1104" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3">
          <filename>libdns1104_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">523bbfb9c66ac850a3426b9167bf5771e52407b6</sum>
        </package>
        <package arch="amd64" name="libirs-export161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3">
          <filename>libirs-export161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">071638c7b51fbcf77a0ca6c795e53c0c48b4f06b</sum>
        </package>
        <package arch="amd64" name="libirs161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3">
          <filename>libirs161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">55304a7600d7737501f6b6f5e1c84b09087514fc</sum>
        </package>
        <package arch="amd64" name="libisc-export1100" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3">
          <filename>libisc-export1100_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">fbf6bf0ef7378931af48e82159393ab45979b057</sum>
        </package>
        <package arch="amd64" name="libisc1100" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3">
          <filename>libisc1100_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">9ef0d46d3199048365f9a8625bfca0ae7863158c</sum>
        </package>
        <package arch="amd64" name="libisccc-export161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3">
          <filename>libisccc-export161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">a4fa8056ee96101e24c5cde39fa567ec823c836b</sum>
        </package>
        <package arch="amd64" name="libisccc161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3">
          <filename>libisccc161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">e9e2b85a86641425f6ce1f5cd53de81fbb64f92e</sum>
        </package>
        <package arch="amd64" name="libisccfg-export163" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3">
          <filename>libisccfg-export163_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">60d6a6fcf0db0a67e7c4f53f86e838fcdecf5d60</sum>
        </package>
        <package arch="amd64" name="libisccfg163" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3">
          <filename>libisccfg163_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">53251a124a564e269d89e4b5658f806d88a3023e</sum>
        </package>
        <package arch="amd64" name="liblwres161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3">
          <filename>liblwres161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">b1ec78a6d3f04250c6fabbedecff296b0ed6c50a</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1781205404</id>
    <title>Fix CVE(s): CVE-2025-13462, CVE-2026-4224, CVE-2026-7210</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: tarfile misinterprets crafted multi-block GNU long name
     archives via AREGTYPE/DIRTYPE normalization
     - debian/patches/CVE-2025-13462.patch: skip the old-v7 AREGTYPE to DIRTYPE
       normalization when reading the follow-up header of a GNU LONGNAME /
       LONGLINK or PAX member in Lib/tarfile.py
     - CVE-2025-13462
   * SECURITY UPDATE: C stack overflow in pyexpat when an ElementDeclHandler
     parses a deeply nested content model
     - debian/patches/CVE-2026-4224.patch: guard conv_content_model() recursion
       with Py_EnterRecursiveCall()/Py_LeaveRecursiveCall() in Modules/pyexpat.c
     - CVE-2026-4224
   * SECURITY UPDATE: insufficient entropy in pyexpat/_elementtree hash-flooding
     protection
     - debian/patches/CVE-2026-7210.patch: bind XML_SetHashSalt16Bytes as a weak
       symbol to seed the Expat parser with 16 bytes of entropy when hash
       randomization is enabled; falls back to the legacy XML_SetHashSalt when
       unavailable. Requires libexpat1 (&gt;= 2.2.6-2+deb10u7+tuxcare.els6).
     - CVE-2026-7210</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: tarfile misinterprets crafted multi-block GNU long name
     archives via AREGTYPE/DIRTYPE normalization
     - debian/patches/CVE-2025-13462.patch: skip the old-v7 AREGTYPE to DIRTYPE
       normalization when reading the follow-up header of a GNU LONGNAME /
       LONGLINK or PAX member in Lib/tarfile.py
     - CVE-2025-13462
   * SECURITY UPDATE: C stack overflow in pyexpat when an ElementDeclHandler
     parses a deeply nested content model
     - debian/patches/CVE-2026-4224.patch: guard conv_content_model() recursion
       with Py_EnterRecursiveCall()/Py_LeaveRecursiveCall() in Modules/pyexpat.c
     - CVE-2026-4224
   * SECURITY UPDATE: insufficient entropy in pyexpat/_elementtree hash-flooding
     protection
     - debian/patches/CVE-2026-7210.patch: bind XML_SetHashSalt16Bytes as a weak
       symbol to seed the Expat parser with 16 bytes of entropy when hash
       randomization is enabled; falls back to the legacy XML_SetHashSalt when
       unavailable. Requires libexpat1 (&gt;= 2.2.6-2+deb10u7+tuxcare.els6).
     - CVE-2026-7210</summary>
    <pushcount>0</pushcount>
    <issued date="2026-06-11 19:17:09 UTC" />
    <updated date="2026-06-11 19:17:09 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1781205404.html" id="CLSA-2026:1781205404" title="CLSA-2026:1781205404" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-13462" id="CVE-2025-13462" title="CVE-2025-13462" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-4224" id="CVE-2026-4224" title="CVE-2026-4224" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-7210" id="CVE-2026-7210" title="CVE-2026-7210" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="all" name="idle-python2.7" version="2.7.16-2+deb10u4+tuxcare.els2">
          <filename>idle-python2.7_2.7.16-2+deb10u4+tuxcare.els2_all.deb</filename>
          <sum type="sha">92de853df9c99a1ecbea5f41bed100544cb8bd75</sum>
        </package>
        <package arch="amd64" name="libpython2.7" version="2.7.16-2+deb10u4+tuxcare.els2">
          <filename>libpython2.7_2.7.16-2+deb10u4+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">d755afc08a23e4b87c63917651959cbbba4a6d07</sum>
        </package>
        <package arch="amd64" name="libpython2.7-dev" version="2.7.16-2+deb10u4+tuxcare.els2">
          <filename>libpython2.7-dev_2.7.16-2+deb10u4+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">c28c97acca33f08b7e4f822ebd59665e1ceb9ccf</sum>
        </package>
        <package arch="amd64" name="libpython2.7-minimal" version="2.7.16-2+deb10u4+tuxcare.els2">
          <filename>libpython2.7-minimal_2.7.16-2+deb10u4+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">c49eb5c4adfbf4e1dd7ce3ed08c9f6638923c604</sum>
        </package>
        <package arch="amd64" name="libpython2.7-stdlib" version="2.7.16-2+deb10u4+tuxcare.els2">
          <filename>libpython2.7-stdlib_2.7.16-2+deb10u4+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">3498f03fa8e56dd67e85d4d6e2f12b8a595930b6</sum>
        </package>
        <package arch="all" name="libpython2.7-testsuite" version="2.7.16-2+deb10u4+tuxcare.els2">
          <filename>libpython2.7-testsuite_2.7.16-2+deb10u4+tuxcare.els2_all.deb</filename>
          <sum type="sha">a497b48669734c0ef3f8bc50be7104f72dd0722d</sum>
        </package>
        <package arch="amd64" name="python2.7" version="2.7.16-2+deb10u4+tuxcare.els2">
          <filename>python2.7_2.7.16-2+deb10u4+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">fb1ec6de5529ce8bddd5414824055c2521031e45</sum>
        </package>
        <package arch="amd64" name="python2.7-dev" version="2.7.16-2+deb10u4+tuxcare.els2">
          <filename>python2.7-dev_2.7.16-2+deb10u4+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">e77661a7ece5895316dba2075caf08a97c6604c3</sum>
        </package>
        <package arch="all" name="python2.7-doc" version="2.7.16-2+deb10u4+tuxcare.els2">
          <filename>python2.7-doc_2.7.16-2+deb10u4+tuxcare.els2_all.deb</filename>
          <sum type="sha">3bcba41d9593a54ba58ee6fc2bf8fe159451aace</sum>
        </package>
        <package arch="all" name="python2.7-examples" version="2.7.16-2+deb10u4+tuxcare.els2">
          <filename>python2.7-examples_2.7.16-2+deb10u4+tuxcare.els2_all.deb</filename>
          <sum type="sha">66ef5e3c480fbc8d6167cde0c56d2e6085e16b58</sum>
        </package>
        <package arch="amd64" name="python2.7-minimal" version="2.7.16-2+deb10u4+tuxcare.els2">
          <filename>python2.7-minimal_2.7.16-2+deb10u4+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">c28280400670b1c1f13ee8bc25cf31eeb8c15a8c</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1781253686</id>
    <title>Fix CVE(s): CVE-2026-45447</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix use-after-free of caller-owned BIO in PKCS7_verify() (pk7_smime.c)
     - debian/patches/CVE-2026-45447.patch: fix use-after-free of caller-owned BIO in PKCS7_verify() (pk7_smime.c)
     - CVE-2026-45447</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix use-after-free of caller-owned BIO in PKCS7_verify() (pk7_smime.c)
     - debian/patches/CVE-2026-45447.patch: fix use-after-free of caller-owned BIO in PKCS7_verify() (pk7_smime.c)
     - CVE-2026-45447</summary>
    <pushcount>0</pushcount>
    <issued date="2026-06-12 08:41:43 UTC" />
    <updated date="2026-06-12 08:41:43 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1781253686.html" id="CLSA-2026:1781253686" title="CLSA-2026:1781253686" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-45447" id="CVE-2026-45447" title="CVE-2026-45447" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libssl-dev" version="1.1.1n-0+deb10u6+tuxcare.els4">
          <filename>libssl-dev_1.1.1n-0+deb10u6+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">0c97b55c6bd800eedd8d7daadeec02e5762add9e</sum>
        </package>
        <package arch="all" name="libssl-doc" version="1.1.1n-0+deb10u6+tuxcare.els4">
          <filename>libssl-doc_1.1.1n-0+deb10u6+tuxcare.els4_all.deb</filename>
          <sum type="sha">a3020a3ffc372178f89a4720d1a046b62c5a13ce</sum>
        </package>
        <package arch="amd64" name="libssl1.1" version="1.1.1n-0+deb10u6+tuxcare.els4">
          <filename>libssl1.1_1.1.1n-0+deb10u6+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">22e994d1a9c8c969ae1afaf9c000d046246bd2c2</sum>
        </package>
        <package arch="amd64" name="openssl" version="1.1.1n-0+deb10u6+tuxcare.els4">
          <filename>openssl_1.1.1n-0+deb10u6+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">79c5dbdc4b36147a630b34d48f4f9e96e042df28</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1781259901</id>
    <title>Fix CVE(s): CVE-2025-13462, CVE-2026-3644, CVE-2026-4224, CVE-2026-7210</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: tarfile AREGTYPE-&gt;DIRTYPE misnormalization of multi-block member headers
     - debian/patches/CVE-2025-13462.patch: in Lib/tarfile.py, add a dircheck flag to
       frombuf()/fromtarfile() and read the follow-up header of GNU long-name and PAX
       multi-block members with dircheck=False in _proc_gnulong()/_proc_pax(), so the old-V7
       "AREGTYPE name ending in / is a directory" normalization is no longer applied to a
       follow-up header based on its truncated name. Prevents a crafted tar archive from being
       interpreted differently by tarfile than by other tools. Backport of upstream commit
       42d754e34c (gh-141707), the same fix shipped by Debian in DLA-4583-1; applies to 3.7.3
       without code changes (the affected functions are structurally identical). Bundles the
       upstream regression test test_longname_file_not_directory (test_tarfile.py).
     - CVE-2025-13462
   * SECURITY UPDATE: C stack overflow in pyexpat via deeply nested DTD content model
     - debian/patches/CVE-2026-4224.patch: guard the recursion in Modules/pyexpat.c
       conv_content_model() with Py_EnterRecursiveCall()/Py_LeaveRecursiveCall() so a deeply
       nested inline DTD content model parsed by an Expat parser with a registered
       ElementDeclHandler raises RecursionError instead of crashing the interpreter. Adapted
       from upstream commit eb0e8be3a7 (gh-145986); upstream uses the private
       _Py_EnterRecursiveCall() API, replaced here with the equivalent public 3.7 macros. The
       upstream regression test is not bundled (it needs 3.7-absent test.support helpers and a
       500000-deep model); the fix was verified manually.
     - CVE-2026-4224
   * SECURITY UPDATE: control-character injection in http.cookies (HTTP response splitting)
     - debian/patches/CVE-2026-3644.patch: reject control characters (\x00-\x1F, \x7F) in
       Lib/http/cookies.py across all Morsel/BaseCookie paths via a new _has_control_character()
       helper. CVE-2026-3644 is the incomplete-fix follow-up to CVE-2026-0672 and its upstream
       fix (commit 57e88c1cf9, gh-145599) depends on the helper introduced by the CVE-2026-0672
       base commit (95746b3a13, gh-143919). 3.7.3 shipped neither fix, so this patch bundles both:
       the base validation in Morsel.__setitem__/setdefault/set and BaseCookie.output, plus the
       follow-up validation in Morsel.update/__setstate__ and BaseCookie.js_output.
       Also closes CVE-2026-0672. The upstream Morsel.__ior__ override is omitted: it only exists
       to neutralize dict.__ior__ (PEP 584, Python 3.9+), which 3.7 does not have, so there is no
       |= bypass to close. The module docstring doctest and the test_basic keebler fixture in
       test_http_cookies.py are updated to drop a \012 control character now rejected by load(),
       and the upstream regression tests test_control_characters/test_control_characters_output
       are bundled with the test.support.control_characters_c0() helper they require.
     - CVE-2026-3644</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: tarfile AREGTYPE-&gt;DIRTYPE misnormalization of multi-block member headers
     - debian/patches/CVE-2025-13462.patch: in Lib/tarfile.py, add a dircheck flag to
       frombuf()/fromtarfile() and read the follow-up header of GNU long-name and PAX
       multi-block members with dircheck=False in _proc_gnulong()/_proc_pax(), so the old-V7
       "AREGTYPE name ending in / is a directory" normalization is no longer applied to a
       follow-up header based on its truncated name. Prevents a crafted tar archive from being
       interpreted differently by tarfile than by other tools. Backport of upstream commit
       42d754e34c (gh-141707), the same fix shipped by Debian in DLA-4583-1; applies to 3.7.3
       without code changes (the affected functions are structurally identical). Bundles the
       upstream regression test test_longname_file_not_directory (test_tarfile.py).
     - CVE-2025-13462
   * SECURITY UPDATE: C stack overflow in pyexpat via deeply nested DTD content model
     - debian/patches/CVE-2026-4224.patch: guard the recursion in Modules/pyexpat.c
       conv_content_model() with Py_EnterRecursiveCall()/Py_LeaveRecursiveCall() so a deeply
       nested inline DTD content model parsed by an Expat parser with a registered
       ElementDeclHandler raises RecursionError instead of crashing the interpreter. Adapted
       from upstream commit eb0e8be3a7 (gh-145986); upstream uses the private
       _Py_EnterRecursiveCall() API, replaced here with the equivalent public 3.7 macros. The
       upstream regression test is not bundled (it needs 3.7-absent test.support helpers and a
       500000-deep model); the fix was verified manually.
     - CVE-2026-4224
   * SECURITY UPDATE: control-character injection in http.cookies (HTTP response splitting)
     - debian/patches/CVE-2026-3644.patch: reject control characters (\x00-\x1F, \x7F) in
       Lib/http/cookies.py across all Morsel/BaseCookie paths via a new _has_control_character()
       helper. CVE-2026-3644 is the incomplete-fix follow-up to CVE-2026-0672 and its upstream
       fix (commit 57e88c1cf9, gh-145599) depends on the helper introduced by the CVE-2026-0672
       base commit (95746b3a13, gh-143919). 3.7.3 shipped neither fix, so this patch bundles both:
       the base validation in Morsel.__setitem__/setdefault/set and BaseCookie.output, plus the
       follow-up validation in Morsel.update/__setstate__ and BaseCookie.js_output.
       Also closes CVE-2026-0672. The upstream Morsel.__ior__ override is omitted: it only exists
       to neutralize dict.__ior__ (PEP 584, Python 3.9+), which 3.7 does not have, so there is no
       |= bypass to close. The module docstring doctest and the test_basic keebler fixture in
       test_http_cookies.py are updated to drop a \012 control character now rejected by load(),
       and the upstream regression tests test_control_characters/test_control_characters_output
       are bundled with the test.support.control_characters_c0() helper they require.
     - CVE-2026-3644</summary>
    <pushcount>0</pushcount>
    <issued date="2026-06-12 10:27:16 UTC" />
    <updated date="2026-06-12 10:27:16 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1781259901.html" id="CLSA-2026:1781259901" title="CLSA-2026:1781259901" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-13462" id="CVE-2025-13462" title="CVE-2025-13462" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-3644" id="CVE-2026-3644" title="CVE-2026-3644" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-4224" id="CVE-2026-4224" title="CVE-2026-4224" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-7210" id="CVE-2026-7210" title="CVE-2026-7210" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="all" name="idle-python3.7" version="3.7.3-2+deb10u7+tuxcare.els5">
          <filename>idle-python3.7_3.7.3-2+deb10u7+tuxcare.els5_all.deb</filename>
          <sum type="sha">a884b0d26a24691ca0846094152bd3c34d6da959</sum>
        </package>
        <package arch="amd64" name="libpython3.7" version="3.7.3-2+deb10u7+tuxcare.els5">
          <filename>libpython3.7_3.7.3-2+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">b8ecaf460df60798cfb89d342cacff8c9c8c250c</sum>
        </package>
        <package arch="amd64" name="libpython3.7-dev" version="3.7.3-2+deb10u7+tuxcare.els5">
          <filename>libpython3.7-dev_3.7.3-2+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">9deae664f05034a439a97d2a9fba23936e730400</sum>
        </package>
        <package arch="amd64" name="libpython3.7-minimal" version="3.7.3-2+deb10u7+tuxcare.els5">
          <filename>libpython3.7-minimal_3.7.3-2+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">d1199532e2c9101a4f78adb26db7122cc77094f4</sum>
        </package>
        <package arch="amd64" name="libpython3.7-stdlib" version="3.7.3-2+deb10u7+tuxcare.els5">
          <filename>libpython3.7-stdlib_3.7.3-2+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">9037d9efee86e45134f50fd70c5c31272872dca3</sum>
        </package>
        <package arch="all" name="libpython3.7-testsuite" version="3.7.3-2+deb10u7+tuxcare.els5">
          <filename>libpython3.7-testsuite_3.7.3-2+deb10u7+tuxcare.els5_all.deb</filename>
          <sum type="sha">2f4ad8488571fd6124cf850b63f139bfac480e6a</sum>
        </package>
        <package arch="amd64" name="python3.7" version="3.7.3-2+deb10u7+tuxcare.els5">
          <filename>python3.7_3.7.3-2+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">dd85f04607f791ef510e2db5af2446f24301b116</sum>
        </package>
        <package arch="amd64" name="python3.7-dev" version="3.7.3-2+deb10u7+tuxcare.els5">
          <filename>python3.7-dev_3.7.3-2+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">389caa189ceba45ef4b587f5b26988b6a5825a7d</sum>
        </package>
        <package arch="all" name="python3.7-doc" version="3.7.3-2+deb10u7+tuxcare.els5">
          <filename>python3.7-doc_3.7.3-2+deb10u7+tuxcare.els5_all.deb</filename>
          <sum type="sha">64da6ae3c233dbc4f56ab407773ce5f6acdc2a04</sum>
        </package>
        <package arch="all" name="python3.7-examples" version="3.7.3-2+deb10u7+tuxcare.els5">
          <filename>python3.7-examples_3.7.3-2+deb10u7+tuxcare.els5_all.deb</filename>
          <sum type="sha">5932e0599c4e1aab44129a0b8927f55928353d18</sum>
        </package>
        <package arch="amd64" name="python3.7-minimal" version="3.7.3-2+deb10u7+tuxcare.els5">
          <filename>python3.7-minimal_3.7.3-2+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">07cde4ad4d2647b17ac871afc9210326865b89fc</sum>
        </package>
        <package arch="amd64" name="python3.7-venv" version="3.7.3-2+deb10u7+tuxcare.els5">
          <filename>python3.7-venv_3.7.3-2+deb10u7+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">2448e87a9bf013a71b2b0edb1761a2ba4a225b2f</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1781628808</id>
    <title>Fix of 7 CVEs</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix use-after-free in mod_http2 when the server runs out of file handles, which left beam bucket callbacks referencing freed memory
     - debian/patches/CVE-2026-48913.patch: fix use-after-free in mod_http2 when the server runs out of file handles, which left beam bucket callbacks referencing freed memory
     - CVE-2026-48913</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix use-after-free in mod_http2 when the server runs out of file handles, which left beam bucket callbacks referencing freed memory
     - debian/patches/CVE-2026-48913.patch: fix use-after-free in mod_http2 when the server runs out of file handles, which left beam bucket callbacks referencing freed memory
     - CVE-2026-48913</summary>
    <pushcount>0</pushcount>
    <issued date="2026-06-16 16:53:51 UTC" />
    <updated date="2026-06-16 16:53:51 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1781628808.html" id="CLSA-2026:1781628808" title="CLSA-2026:1781628808" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-29167" id="CVE-2026-29167" title="CVE-2026-29167" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-29170" id="CVE-2026-29170" title="CVE-2026-29170" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-34355" id="CVE-2026-34355" title="CVE-2026-34355" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-34356" id="CVE-2026-34356" title="CVE-2026-34356" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-42535" id="CVE-2026-42535" title="CVE-2026-42535" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-42536" id="CVE-2026-42536" title="CVE-2026-42536" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-48913" id="CVE-2026-48913" title="CVE-2026-48913" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="apache2" version="2.4.59-1~deb10u1+tuxcare.els8">
          <filename>apache2_2.4.59-1~deb10u1+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">e29d64bb58ce25e92cd607fc76ccb629c233f89b</sum>
        </package>
        <package arch="amd64" name="apache2-bin" version="2.4.59-1~deb10u1+tuxcare.els8">
          <filename>apache2-bin_2.4.59-1~deb10u1+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">fba7e9e88205022df429f791b9ba81c85327e1e8</sum>
        </package>
        <package arch="all" name="apache2-data" version="2.4.59-1~deb10u1+tuxcare.els8">
          <filename>apache2-data_2.4.59-1~deb10u1+tuxcare.els8_all.deb</filename>
          <sum type="sha">3ecf0e30fc64eec32139446b6a8598bafc6c5b6a</sum>
        </package>
        <package arch="amd64" name="apache2-dev" version="2.4.59-1~deb10u1+tuxcare.els8">
          <filename>apache2-dev_2.4.59-1~deb10u1+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">1079984de0b8c051f11ca63700e6982dfba82794</sum>
        </package>
        <package arch="all" name="apache2-doc" version="2.4.59-1~deb10u1+tuxcare.els8">
          <filename>apache2-doc_2.4.59-1~deb10u1+tuxcare.els8_all.deb</filename>
          <sum type="sha">e8dc08073aa439bc2b65656ed8bf6ace604efd74</sum>
        </package>
        <package arch="amd64" name="apache2-ssl-dev" version="2.4.59-1~deb10u1+tuxcare.els8">
          <filename>apache2-ssl-dev_2.4.59-1~deb10u1+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">6c2111edda0b7d4c4dcfdae4a09fb8f719aac524</sum>
        </package>
        <package arch="amd64" name="apache2-suexec-custom" version="2.4.59-1~deb10u1+tuxcare.els8">
          <filename>apache2-suexec-custom_2.4.59-1~deb10u1+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">7422d2ae8f922de461c47841393b823809e4d3a9</sum>
        </package>
        <package arch="amd64" name="apache2-suexec-pristine" version="2.4.59-1~deb10u1+tuxcare.els8">
          <filename>apache2-suexec-pristine_2.4.59-1~deb10u1+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">b1a3d30c9363059529618e5dedf1534db0aa0332</sum>
        </package>
        <package arch="amd64" name="apache2-utils" version="2.4.59-1~deb10u1+tuxcare.els8">
          <filename>apache2-utils_2.4.59-1~deb10u1+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">3d4deaab4348ce3a7e272ceb6877586a88803142</sum>
        </package>
        <package arch="amd64" name="libapache2-mod-md" version="2.4.59-1~deb10u1+tuxcare.els8">
          <filename>libapache2-mod-md_2.4.59-1~deb10u1+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">36d06fad725701e9e0e25e11b10dbc11a0f5ef79</sum>
        </package>
        <package arch="amd64" name="libapache2-mod-proxy-uwsgi" version="2.4.59-1~deb10u1+tuxcare.els8">
          <filename>libapache2-mod-proxy-uwsgi_2.4.59-1~deb10u1+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">8324cc967ab9c64a1b1273a95ec15f4fc96cf14f</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1782142073</id>
    <title>Fix CVE(s): CVE-2026-46692</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: heap buffer over-write in the distributed pixel cache
     read and write paths
     - debian/patches/CVE-2026-46692.patch: validate the requested region/length
       against the pixel-cache extent in the Read and Write DistributeCache
       functions (ReadDistributeCacheIndexes/Pixels,
       WriteDistributeCacheIndexes/Pixels) in magick/distribute-cache.c
     - CVE-2026-46692</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: heap buffer over-write in the distributed pixel cache
     read and write paths
     - debian/patches/CVE-2026-46692.patch: validate the requested region/length
       against the pixel-cache extent in the Read and Write DistributeCache
       functions (ReadDistributeCacheIndexes/Pixels,
       WriteDistributeCacheIndexes/Pixels) in magick/distribute-cache.c
     - CVE-2026-46692</summary>
    <pushcount>0</pushcount>
    <issued date="2026-06-22 15:28:08 UTC" />
    <updated date="2026-06-22 15:28:08 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1782142073.html" id="CLSA-2026:1782142073" title="CLSA-2026:1782142073" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-46692" id="CVE-2026-46692" title="CVE-2026-46692" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="imagemagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>imagemagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">d005f1b63f964e8a8819f85c7797142e77e3890c</sum>
        </package>
        <package arch="all" name="imagemagick-6-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>imagemagick-6-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_all.deb</filename>
          <sum type="sha">a507b386add4f5193392bc94631a0aacf2815df5</sum>
        </package>
        <package arch="all" name="imagemagick-6-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>imagemagick-6-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_all.deb</filename>
          <sum type="sha">5273887337014e113bddf3bf8c9ba1f4ed2a0f9b</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>imagemagick-6.q16_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">d6f35ee424abf4a8824b823be670c976ac06be23</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16hdri" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>imagemagick-6.q16hdri_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">b3b5229f16918622368ffa53404b7ef19f6b4bc5</sum>
        </package>
        <package arch="all" name="imagemagick-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>imagemagick-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_all.deb</filename>
          <sum type="sha">26a9f8bbb82c28c764ebbfd4d07d9747c9fac9f8</sum>
        </package>
        <package arch="all" name="imagemagick-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>imagemagick-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_all.deb</filename>
          <sum type="sha">4539ba10d61460f34655afe3cd8e53e463509c48</sum>
        </package>
        <package arch="all" name="libimage-magick-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libimage-magick-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_all.deb</filename>
          <sum type="sha">6fd47dc73b369343e5aa3853f703d9733edd41a4</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libimage-magick-q16-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">19a39d14bb450c1b160cd4d8f60ca95de5e362f9</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16hdri-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libimage-magick-q16hdri-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">704d52da3acf1e08503ee8dde072bed4ece3f4f0</sum>
        </package>
        <package arch="all" name="libmagick++-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libmagick++-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_all.deb</filename>
          <sum type="sha">60f8a57e02ba47904568df1004099b149a89ccc5</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libmagick++-6.q16-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">1548325500e070565ae4858a3000ae102b10cf4d</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libmagick++-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">0f7505673990b5ae58d51f8b9805d030ac37c5d6</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libmagick++-6.q16hdri-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">772927507396ba980c1082713686ad67a302e5e0</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libmagick++-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">508fd1150084eea2645d9ff406ccbc7e5ec30109</sum>
        </package>
        <package arch="all" name="libmagick++-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libmagick++-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_all.deb</filename>
          <sum type="sha">5a6a7397c82af6af3d86fe0f9d09c9f30e07b351</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6-arch-config" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libmagickcore-6-arch-config_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">4b60ac43c9bd9af6a983e599764439a7f8d832ec</sum>
        </package>
        <package arch="all" name="libmagickcore-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libmagickcore-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_all.deb</filename>
          <sum type="sha">307b39487adb0013d732e67a93fceedb338887b8</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libmagickcore-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">4fc36f603894f9cc505b24f70680c1a2d9f5fcf3</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libmagickcore-6.q16-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">0f28e77e5d76650682b53e82e011d1b5335f497f</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libmagickcore-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">5d2cd0e8e4b87f5417da276a9e32b90f7f9bdfea</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libmagickcore-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">e40298aaa7c33ed848ad3b4840e59e7d8bef0454</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libmagickcore-6.q16hdri-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">cdf8cd0f76ced71e90ee7580c75c855e7b2b865e</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libmagickcore-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">a2e3476693a9cf466656b468d190cb58d4a994c7</sum>
        </package>
        <package arch="all" name="libmagickcore-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libmagickcore-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_all.deb</filename>
          <sum type="sha">1e6bb6ee9ea377e92e36bf5854838e44c20fdeb7</sum>
        </package>
        <package arch="all" name="libmagickwand-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libmagickwand-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_all.deb</filename>
          <sum type="sha">792659122ef22d941776b719ca7889d5420d5d09</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libmagickwand-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">2abc87dbddc42d0618379aad65b060dc5c3b69af</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libmagickwand-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">62b62911a7388fba825fe4f6696ba06a3d7b1b5e</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libmagickwand-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">e211a3d56ee012bf8ee00c260647f073b4aee8ee</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libmagickwand-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">14dcaf5e724aacd749b2c56bf68ca4af2c91e256</sum>
        </package>
        <package arch="all" name="libmagickwand-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>libmagickwand-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_all.deb</filename>
          <sum type="sha">7914078a0f0523a7dea7605e169261ba3e60c538</sum>
        </package>
        <package arch="all" name="perlmagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8">
          <filename>perlmagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els8_all.deb</filename>
          <sum type="sha">236363f80f43d919808bff6a475e788d9f3de476</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1782221662</id>
    <title>Fix CVE(s): CVE-2026-47162, CVE-2026-52858, CVE-2026-52859, CVE-2026-52860</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Code execution via Python omni-completion executing import and from statements harvested from the current buffer through exec() (gate buffer-derived import execution behind the new g:pythoncomplete_allow_import option, disabled by default)
     - debian/patches/CVE-2026-52858.patch: disable execution of import and from statements found in the buffer during python3complete and pythoncomplete omni-completion unless g:pythoncomplete_allow_import is set
     - CVE-2026-52858
   * SECURITY UPDATE: Out-of-bounds read in update_snapshot() in src/terminal.c when a terminal cell fills all VTERM_MAX_CHARS_PER_CELL slots and the bundled libvterm returns the chars array without a NUL terminator
     - debian/patches/CVE-2026-52859.patch: bound the cell.chars[] copy loop in update_snapshot() with i &lt; VTERM_MAX_CHARS_PER_CELL to prevent reading past the fixed six-element array
     - CVE-2026-52859
   * SECURITY UPDATE: Code execution via Python omni-completion evaluating function default values, parameter annotations, and class base expressions reconstructed from the current buffer and run through exec()
     - debian/patches/CVE-2026-52860.patch: strip default expressions and annotations from generated function parameters and whitelist dotted class base expressions in python3complete and pythoncomplete get_code() so attacker-controlled expressions are not executed
     - CVE-2026-52860</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Code execution via Python omni-completion executing import and from statements harvested from the current buffer through exec() (gate buffer-derived import execution behind the new g:pythoncomplete_allow_import option, disabled by default)
     - debian/patches/CVE-2026-52858.patch: disable execution of import and from statements found in the buffer during python3complete and pythoncomplete omni-completion unless g:pythoncomplete_allow_import is set
     - CVE-2026-52858
   * SECURITY UPDATE: Out-of-bounds read in update_snapshot() in src/terminal.c when a terminal cell fills all VTERM_MAX_CHARS_PER_CELL slots and the bundled libvterm returns the chars array without a NUL terminator
     - debian/patches/CVE-2026-52859.patch: bound the cell.chars[] copy loop in update_snapshot() with i &lt; VTERM_MAX_CHARS_PER_CELL to prevent reading past the fixed six-element array
     - CVE-2026-52859
   * SECURITY UPDATE: Code execution via Python omni-completion evaluating function default values, parameter annotations, and class base expressions reconstructed from the current buffer and run through exec()
     - debian/patches/CVE-2026-52860.patch: strip default expressions and annotations from generated function parameters and whitelist dotted class base expressions in python3complete and pythoncomplete get_code() so attacker-controlled expressions are not executed
     - CVE-2026-52860</summary>
    <pushcount>0</pushcount>
    <issued date="2026-06-23 13:34:43 UTC" />
    <updated date="2026-06-23 13:34:43 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1782221662.html" id="CLSA-2026:1782221662" title="CLSA-2026:1782221662" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-47162" id="CVE-2026-47162" title="CVE-2026-47162" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-52858" id="CVE-2026-52858" title="CVE-2026-52858" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-52859" id="CVE-2026-52859" title="CVE-2026-52859" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-52860" id="CVE-2026-52860" title="CVE-2026-52860" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="vim" version="2:8.1.0875-5+deb10u6+tuxcare.els22">
          <filename>vim_8.1.0875-5+deb10u6+tuxcare.els22_amd64.deb</filename>
          <sum type="sha">475638e80ccd77a652664a692cf59e1ef8d5cbb7</sum>
        </package>
        <package arch="amd64" name="vim-athena" version="2:8.1.0875-5+deb10u6+tuxcare.els22">
          <filename>vim-athena_8.1.0875-5+deb10u6+tuxcare.els22_amd64.deb</filename>
          <sum type="sha">545cdef20117b1e685df9fd676b90d515dc73a1a</sum>
        </package>
        <package arch="all" name="vim-common" version="2:8.1.0875-5+deb10u6+tuxcare.els22">
          <filename>vim-common_8.1.0875-5+deb10u6+tuxcare.els22_all.deb</filename>
          <sum type="sha">a601f2a6939228a0c09666d4c96a9392f2b17341</sum>
        </package>
        <package arch="all" name="vim-doc" version="2:8.1.0875-5+deb10u6+tuxcare.els22">
          <filename>vim-doc_8.1.0875-5+deb10u6+tuxcare.els22_all.deb</filename>
          <sum type="sha">08e787b63edf35b80e85d89594c9eff84c7ef9ea</sum>
        </package>
        <package arch="amd64" name="vim-gtk" version="2:8.1.0875-5+deb10u6+tuxcare.els22">
          <filename>vim-gtk_8.1.0875-5+deb10u6+tuxcare.els22_amd64.deb</filename>
          <sum type="sha">c60257f15e1b40391efcf4630bed0e1f1b2bb167</sum>
        </package>
        <package arch="amd64" name="vim-gtk3" version="2:8.1.0875-5+deb10u6+tuxcare.els22">
          <filename>vim-gtk3_8.1.0875-5+deb10u6+tuxcare.els22_amd64.deb</filename>
          <sum type="sha">cc9f0b3aedd849d0be24b7f23ff7979832094ac7</sum>
        </package>
        <package arch="all" name="vim-gui-common" version="2:8.1.0875-5+deb10u6+tuxcare.els22">
          <filename>vim-gui-common_8.1.0875-5+deb10u6+tuxcare.els22_all.deb</filename>
          <sum type="sha">a05b891836375bda521b17c4311de10e02193c47</sum>
        </package>
        <package arch="amd64" name="vim-nox" version="2:8.1.0875-5+deb10u6+tuxcare.els22">
          <filename>vim-nox_8.1.0875-5+deb10u6+tuxcare.els22_amd64.deb</filename>
          <sum type="sha">990b1a3b4fb9dc4f5537fb7c9b972596059225ea</sum>
        </package>
        <package arch="all" name="vim-runtime" version="2:8.1.0875-5+deb10u6+tuxcare.els22">
          <filename>vim-runtime_8.1.0875-5+deb10u6+tuxcare.els22_all.deb</filename>
          <sum type="sha">65403283669664931eb86e6b612afcb819e04d61</sum>
        </package>
        <package arch="amd64" name="vim-tiny" version="2:8.1.0875-5+deb10u6+tuxcare.els22">
          <filename>vim-tiny_8.1.0875-5+deb10u6+tuxcare.els22_amd64.deb</filename>
          <sum type="sha">c8b3208d49d76c072a3ceab9ade50296321655ad</sum>
        </package>
        <package arch="amd64" name="xxd" version="2:8.1.0875-5+deb10u6+tuxcare.els22">
          <filename>xxd_8.1.0875-5+deb10u6+tuxcare.els22_amd64.deb</filename>
          <sum type="sha">554416a35cc9d8d324e7212de90f67c88409646a</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1782808222</id>
    <title>Fix CVE(s): CVE-2026-46559, CVE-2026-49218, CVE-2026-53460</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix missing dimension check in DCM decoder (invalid image dimensions)
     - debian/patches/CVE-2026-49218.patch: fix missing dimension check in DCM decoder (invalid image dimensions)
     - CVE-2026-49218
   * SECURITY UPDATE: fix missing maximum memory request check in AcquireAlignedMemory (out-of-memory)
     - debian/patches/CVE-2026-53460.patch: fix missing maximum memory request check in AcquireAlignedMemory (out-of-memory)
     - CVE-2026-53460
   * SECURITY UPDATE: fix single-byte heap buffer over-write in JP2 coder (jp2:quality / jp2:rate options)
     - debian/patches/CVE-2026-46559.patch: fix single-byte heap buffer over-write in JP2 coder (jp2:quality / jp2:rate options)
     - CVE-2026-46559</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix missing dimension check in DCM decoder (invalid image dimensions)
     - debian/patches/CVE-2026-49218.patch: fix missing dimension check in DCM decoder (invalid image dimensions)
     - CVE-2026-49218
   * SECURITY UPDATE: fix missing maximum memory request check in AcquireAlignedMemory (out-of-memory)
     - debian/patches/CVE-2026-53460.patch: fix missing maximum memory request check in AcquireAlignedMemory (out-of-memory)
     - CVE-2026-53460
   * SECURITY UPDATE: fix single-byte heap buffer over-write in JP2 coder (jp2:quality / jp2:rate options)
     - debian/patches/CVE-2026-46559.patch: fix single-byte heap buffer over-write in JP2 coder (jp2:quality / jp2:rate options)
     - CVE-2026-46559</summary>
    <pushcount>0</pushcount>
    <issued date="2026-06-30 08:30:42 UTC" />
    <updated date="2026-06-30 08:30:42 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1782808222.html" id="CLSA-2026:1782808222" title="CLSA-2026:1782808222" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-46559" id="CVE-2026-46559" title="CVE-2026-46559" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-49218" id="CVE-2026-49218" title="CVE-2026-49218" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-53460" id="CVE-2026-53460" title="CVE-2026-53460" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="imagemagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>imagemagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">58a4da33cffe3c954543bf238449e7b6e67ee2e9</sum>
        </package>
        <package arch="all" name="imagemagick-6-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>imagemagick-6-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_all.deb</filename>
          <sum type="sha">d8b056d75d1c1267e8070658f0dd942c2dc3a078</sum>
        </package>
        <package arch="all" name="imagemagick-6-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>imagemagick-6-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_all.deb</filename>
          <sum type="sha">8e4d14e266b03f87b023ead137d21c01fbcd2390</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>imagemagick-6.q16_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">a7d93a93dd9d6cd7b280696d88340e730c44e2f8</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16hdri" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>imagemagick-6.q16hdri_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">1df74c01a4cdc5a2f425d591327cc601838aba06</sum>
        </package>
        <package arch="all" name="imagemagick-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>imagemagick-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_all.deb</filename>
          <sum type="sha">4d08bcd9147f36c76b470a750168da833b763e2b</sum>
        </package>
        <package arch="all" name="imagemagick-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>imagemagick-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_all.deb</filename>
          <sum type="sha">7d17bfc5ea59803388d31c2f5367ea2b0b7a780e</sum>
        </package>
        <package arch="all" name="libimage-magick-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libimage-magick-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_all.deb</filename>
          <sum type="sha">b2ed8dd371ff981b40dc290e8fda75d6e16b62c8</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libimage-magick-q16-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">92183ff5f7d1961664d5409fe3b9bfea27920ca2</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16hdri-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libimage-magick-q16hdri-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">778564bd1846bf42821f328822346ed5eda18984</sum>
        </package>
        <package arch="all" name="libmagick++-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libmagick++-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_all.deb</filename>
          <sum type="sha">6e76ca290f4017efdbc12dd94fd1e53207ca7e85</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libmagick++-6.q16-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">94117e7fc393861230c3bbbf0666b828efdd2d8b</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libmagick++-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">f49ba3f13dd164003d0a327397895680a29403d2</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libmagick++-6.q16hdri-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">5424ffb606f204c179ec637f976fade3151d3258</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libmagick++-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">98d627aeb7ccd7ea10e453026a3e9550a79677e0</sum>
        </package>
        <package arch="all" name="libmagick++-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libmagick++-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_all.deb</filename>
          <sum type="sha">df8734fb9da3fad2087bcef6981abd0c70dcc8b0</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6-arch-config" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libmagickcore-6-arch-config_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">a34e6c647f791a64eb66200042fa9024664cd78f</sum>
        </package>
        <package arch="all" name="libmagickcore-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libmagickcore-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_all.deb</filename>
          <sum type="sha">070e32ac9e5716eedc7087334219c1599621923c</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libmagickcore-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">1c78eec98f0e486baa0c677cdd0e213c24dacfec</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libmagickcore-6.q16-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">827d6b6aef14be5a0cf41a9e83f3aca1a4504ccf</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libmagickcore-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">94233dcd9631b01a552ea5a5add5d6f390427809</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libmagickcore-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">6eec715b20b163f0ed68daeb2200c43d1b3b9b6d</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libmagickcore-6.q16hdri-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">9d66e842d1e7b50771a47a60988f32430a67725c</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libmagickcore-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">8ea9f0ec6283198236fcb054f98173d863b557b3</sum>
        </package>
        <package arch="all" name="libmagickcore-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libmagickcore-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_all.deb</filename>
          <sum type="sha">97f831d8832156c892b432a4c8b45195b6d6685d</sum>
        </package>
        <package arch="all" name="libmagickwand-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libmagickwand-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_all.deb</filename>
          <sum type="sha">8b135c868d63fe4c173260d6bd2ad4b86406a87b</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libmagickwand-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">78f689da4b4fa19e4b1abfd9939e15fcd21346f6</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libmagickwand-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">66ba499c73e05d0a56dd7658eb29ee780a8adc1b</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libmagickwand-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">82ebee617a036feb1575b072e6540d735761c32d</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libmagickwand-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">c358d59db8bf18bb48ee9c65a034e88389d4b51f</sum>
        </package>
        <package arch="all" name="libmagickwand-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>libmagickwand-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_all.deb</filename>
          <sum type="sha">89253fa667b7e6adecf39f46b2dd354a0c3f157e</sum>
        </package>
        <package arch="all" name="perlmagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9">
          <filename>perlmagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els9_all.deb</filename>
          <sum type="sha">461606edfcca7faafc3d7ee9e129b4d4bdadf1ff</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1782809093</id>
    <title>Fix CVE(s): CVE-2026-11822, CVE-2026-11824</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: heap buffer overflow in FTS5 corrupt-record handling
     - debian/patches/CVE-2026-11822-and-11824.patch: reject leaf pages with
       szLeaf &lt; 4 in fts5LeafRead() in ext/fts5/fts5_index.c, closing the
       out-of-bounds read / heap buffer overflow paths in fts5ChunkIterate()
       and fts5LeafSeek().
     - CVE-2026-11822
     - CVE-2026-11824</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: heap buffer overflow in FTS5 corrupt-record handling
     - debian/patches/CVE-2026-11822-and-11824.patch: reject leaf pages with
       szLeaf &lt; 4 in fts5LeafRead() in ext/fts5/fts5_index.c, closing the
       out-of-bounds read / heap buffer overflow paths in fts5ChunkIterate()
       and fts5LeafSeek().
     - CVE-2026-11822
     - CVE-2026-11824</summary>
    <pushcount>0</pushcount>
    <issued date="2026-06-30 08:45:11 UTC" />
    <updated date="2026-06-30 08:45:11 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1782809093.html" id="CLSA-2026:1782809093" title="CLSA-2026:1782809093" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-11822" id="CVE-2026-11822" title="CVE-2026-11822" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-11824" id="CVE-2026-11824" title="CVE-2026-11824" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="lemon" version="3.31.1-4ubuntu0.7+tuxcare.els2">
          <filename>lemon_3.31.1-4ubuntu0.7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">ab831f83e7a68cd7092e89796f62ee21e760717c</sum>
        </package>
        <package arch="amd64" name="libsqlite3-0" version="3.31.1-4ubuntu0.7+tuxcare.els2">
          <filename>libsqlite3-0_3.31.1-4ubuntu0.7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">27de5713b56400ada88e64adab52f681e3a58266</sum>
        </package>
        <package arch="amd64" name="libsqlite3-dev" version="3.31.1-4ubuntu0.7+tuxcare.els2">
          <filename>libsqlite3-dev_3.31.1-4ubuntu0.7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">0c2cf2b7fd85f2adb6f0dfc504d856c890f8d2c0</sum>
        </package>
        <package arch="amd64" name="libsqlite3-tcl" version="3.31.1-4ubuntu0.7+tuxcare.els2">
          <filename>libsqlite3-tcl_3.31.1-4ubuntu0.7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">b8a630d65de7547e56c16ff19890b79dd1b58f65</sum>
        </package>
        <package arch="amd64" name="sqlite3" version="3.31.1-4ubuntu0.7+tuxcare.els2">
          <filename>sqlite3_3.31.1-4ubuntu0.7+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">a938df65f41e43280936b571169759877d6b8143</sum>
        </package>
        <package arch="all" name="sqlite3-doc" version="3.31.1-4ubuntu0.7+tuxcare.els2">
          <filename>sqlite3-doc_3.31.1-4ubuntu0.7+tuxcare.els2_all.deb</filename>
          <sum type="sha">40c36394b28245c92f301a71fd883ca185675efb</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1782895938</id>
    <title>Fix CVE(s): CVE-2026-55204</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: NULL pointer dereference in HPACK dynamic table insertion
     - debian/patches/CVE-2026-55204.patch: add missing NULL check after
       hpack_dht_defrag() in hpack_dht_insert() in src/hpack-tbl.c
     - CVE-2026-55204</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: NULL pointer dereference in HPACK dynamic table insertion
     - debian/patches/CVE-2026-55204.patch: add missing NULL check after
       hpack_dht_defrag() in hpack_dht_insert() in src/hpack-tbl.c
     - CVE-2026-55204</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-01 08:52:34 UTC" />
    <updated date="2026-07-01 08:52:34 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1782895938.html" id="CLSA-2026:1782895938" title="CLSA-2026:1782895938" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-55204" id="CVE-2026-55204" title="CVE-2026-55204" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="haproxy" version="1.8.19-1+deb10u5+tuxcare.els1">
          <filename>haproxy_1.8.19-1+deb10u5+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">dd6b0a44d90d9faa35333ad5d8e0ee2f11ce059d</sum>
        </package>
        <package arch="all" name="haproxy-doc" version="1.8.19-1+deb10u5+tuxcare.els1">
          <filename>haproxy-doc_1.8.19-1+deb10u5+tuxcare.els1_all.deb</filename>
          <sum type="sha">f50568b23d8e9b9e596389cceee6b0c1cc77755e</sum>
        </package>
        <package arch="all" name="vim-haproxy" version="1.8.19-1+deb10u5+tuxcare.els1">
          <filename>vim-haproxy_1.8.19-1+deb10u5+tuxcare.els1_all.deb</filename>
          <sum type="sha">4d37e42dd65f79ad12c57f6c0590bfa23699ac9a</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1782896270</id>
    <title>Fix CVE(s): CVE-2026-55693, CVE-2026-57455, CVE-2026-57456</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Out-of-bounds write in tree_count_words() in src/spellfile.c when a crafted .spl/.sug spell-file pair loaded during spell suggestion drives the word-trie descent past the end of the MAXWLEN-sized arridx, curi and wordcount stack arrays
     - debian/patches/CVE-2026-55693.patch: bound the descent in tree_count_words() and sug_filltree() with depth &lt; MAXWLEN - 1, matching the sibling trie walkers, so the depth index can no longer run past the fixed MAXWLEN-sized arrays
     - CVE-2026-55693
   * SECURITY UPDATE: Out-of-bounds write in spell_soundfold_sofo() in src/spell.c when a word longer than MAXWLEN is sound-folded through a spell file's SOFO byte map while a SOFO-based spell language is active, writing past the end of the caller's MAXWLEN-sized result buffer
     - debian/patches/CVE-2026-57455.patch: bound the single-byte SOFO translation loop in spell_soundfold_sofo() with ri &lt; MAXWLEN - 1 so the output index can no longer run past the fixed MAXWLEN-sized result buffer
     - CVE-2026-57455
   * SECURITY UPDATE: Code execution via Python omni-completion inserting buffer-derived docstrings verbatim between triple quotes in the reconstructed source run through exec(), letting a crafted docstring break out of the triple-quoted literal and execute attacker-controlled code
     - debian/patches/CVE-2026-57456.patch: use repr() to quote docstrings in the Scope, Class, and Function get_code() methods of python3complete and pythoncomplete so docstring text can no longer break out of the generated string literal
     - CVE-2026-57456</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Out-of-bounds write in tree_count_words() in src/spellfile.c when a crafted .spl/.sug spell-file pair loaded during spell suggestion drives the word-trie descent past the end of the MAXWLEN-sized arridx, curi and wordcount stack arrays
     - debian/patches/CVE-2026-55693.patch: bound the descent in tree_count_words() and sug_filltree() with depth &lt; MAXWLEN - 1, matching the sibling trie walkers, so the depth index can no longer run past the fixed MAXWLEN-sized arrays
     - CVE-2026-55693
   * SECURITY UPDATE: Out-of-bounds write in spell_soundfold_sofo() in src/spell.c when a word longer than MAXWLEN is sound-folded through a spell file's SOFO byte map while a SOFO-based spell language is active, writing past the end of the caller's MAXWLEN-sized result buffer
     - debian/patches/CVE-2026-57455.patch: bound the single-byte SOFO translation loop in spell_soundfold_sofo() with ri &lt; MAXWLEN - 1 so the output index can no longer run past the fixed MAXWLEN-sized result buffer
     - CVE-2026-57455
   * SECURITY UPDATE: Code execution via Python omni-completion inserting buffer-derived docstrings verbatim between triple quotes in the reconstructed source run through exec(), letting a crafted docstring break out of the triple-quoted literal and execute attacker-controlled code
     - debian/patches/CVE-2026-57456.patch: use repr() to quote docstrings in the Scope, Class, and Function get_code() methods of python3complete and pythoncomplete so docstring text can no longer break out of the generated string literal
     - CVE-2026-57456</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-01 08:58:09 UTC" />
    <updated date="2026-07-01 08:58:09 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1782896270.html" id="CLSA-2026:1782896270" title="CLSA-2026:1782896270" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-55693" id="CVE-2026-55693" title="CVE-2026-55693" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-57455" id="CVE-2026-57455" title="CVE-2026-57455" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-57456" id="CVE-2026-57456" title="CVE-2026-57456" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="vim" version="2:8.1.0875-5+deb10u6+tuxcare.els23">
          <filename>vim_8.1.0875-5+deb10u6+tuxcare.els23_amd64.deb</filename>
          <sum type="sha">812e4d46235341fb64b840642cf9a30e787d01e5</sum>
        </package>
        <package arch="amd64" name="vim-athena" version="2:8.1.0875-5+deb10u6+tuxcare.els23">
          <filename>vim-athena_8.1.0875-5+deb10u6+tuxcare.els23_amd64.deb</filename>
          <sum type="sha">6389e1643a4e00def9ea34b491c8692478a0df04</sum>
        </package>
        <package arch="all" name="vim-common" version="2:8.1.0875-5+deb10u6+tuxcare.els23">
          <filename>vim-common_8.1.0875-5+deb10u6+tuxcare.els23_all.deb</filename>
          <sum type="sha">3cf11ce636051ed39931ea67369e9888b0dea917</sum>
        </package>
        <package arch="all" name="vim-doc" version="2:8.1.0875-5+deb10u6+tuxcare.els23">
          <filename>vim-doc_8.1.0875-5+deb10u6+tuxcare.els23_all.deb</filename>
          <sum type="sha">22aa16a25acfc7945766860c8573217d94c02b54</sum>
        </package>
        <package arch="amd64" name="vim-gtk" version="2:8.1.0875-5+deb10u6+tuxcare.els23">
          <filename>vim-gtk_8.1.0875-5+deb10u6+tuxcare.els23_amd64.deb</filename>
          <sum type="sha">4067125e0ab13a6120932332649e6ac9cccaa7bd</sum>
        </package>
        <package arch="amd64" name="vim-gtk3" version="2:8.1.0875-5+deb10u6+tuxcare.els23">
          <filename>vim-gtk3_8.1.0875-5+deb10u6+tuxcare.els23_amd64.deb</filename>
          <sum type="sha">0224c1a4e7d62cd87ca794c0881ce354feaf9e43</sum>
        </package>
        <package arch="all" name="vim-gui-common" version="2:8.1.0875-5+deb10u6+tuxcare.els23">
          <filename>vim-gui-common_8.1.0875-5+deb10u6+tuxcare.els23_all.deb</filename>
          <sum type="sha">b8dc4aba98806983170bd35890f23ee462cfcd48</sum>
        </package>
        <package arch="amd64" name="vim-nox" version="2:8.1.0875-5+deb10u6+tuxcare.els23">
          <filename>vim-nox_8.1.0875-5+deb10u6+tuxcare.els23_amd64.deb</filename>
          <sum type="sha">60478a1898fe8f413994f71572f2214dbd50933e</sum>
        </package>
        <package arch="all" name="vim-runtime" version="2:8.1.0875-5+deb10u6+tuxcare.els23">
          <filename>vim-runtime_8.1.0875-5+deb10u6+tuxcare.els23_all.deb</filename>
          <sum type="sha">9c8eaef816b634979a3f7c711958c219c0bd30c7</sum>
        </package>
        <package arch="amd64" name="vim-tiny" version="2:8.1.0875-5+deb10u6+tuxcare.els23">
          <filename>vim-tiny_8.1.0875-5+deb10u6+tuxcare.els23_amd64.deb</filename>
          <sum type="sha">9f0c51c2b2a851a777fe51d003c8cb395e2b133e</sum>
        </package>
        <package arch="amd64" name="xxd" version="2:8.1.0875-5+deb10u6+tuxcare.els23">
          <filename>xxd_8.1.0875-5+deb10u6+tuxcare.els23_amd64.deb</filename>
          <sum type="sha">e9a7a971fa3ec273a03960b21707cb3334c3d3aa</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1782920014</id>
    <title>Fix CVE(s): CVE-2026-55892</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Stack out-of-bounds write in dump_prefixes() in src/spell.c during :spelldump when a crafted spell file containing a self-referential BY_INDEX node in the prefix tree drives the descent depth past the MAXWLEN-sized prefix[]/arridx[]/curi[] stack arrays
     - debian/patches/CVE-2026-55892.patch: bound the prefix-tree descent in dump_prefixes() with "else if (depth &lt; MAXWLEN - 1)" so the depth index cannot exceed the MAXWLEN-sized stack arrays
     - CVE-2026-55892</description>
    <severity>Moderate</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Stack out-of-bounds write in dump_prefixes() in src/spell.c during :spelldump when a crafted spell file containing a self-referential BY_INDEX node in the prefix tree drives the descent depth past the MAXWLEN-sized prefix[]/arridx[]/curi[] stack arrays
     - debian/patches/CVE-2026-55892.patch: bound the prefix-tree descent in dump_prefixes() with "else if (depth &lt; MAXWLEN - 1)" so the depth index cannot exceed the MAXWLEN-sized stack arrays
     - CVE-2026-55892</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-01 15:34:37 UTC" />
    <updated date="2026-07-01 15:34:37 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1782920014.html" id="CLSA-2026:1782920014" title="CLSA-2026:1782920014" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-55892" id="CVE-2026-55892" title="CVE-2026-55892" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="vim" version="2:8.1.0875-5+deb10u6+tuxcare.els24">
          <filename>vim_8.1.0875-5+deb10u6+tuxcare.els24_amd64.deb</filename>
          <sum type="sha">c4acb64221f9369f00ecde3ab94bb85f12a20050</sum>
        </package>
        <package arch="amd64" name="vim-athena" version="2:8.1.0875-5+deb10u6+tuxcare.els24">
          <filename>vim-athena_8.1.0875-5+deb10u6+tuxcare.els24_amd64.deb</filename>
          <sum type="sha">e6f6f1574aaad9c6b83770a2c0d1f3f593d10092</sum>
        </package>
        <package arch="all" name="vim-common" version="2:8.1.0875-5+deb10u6+tuxcare.els24">
          <filename>vim-common_8.1.0875-5+deb10u6+tuxcare.els24_all.deb</filename>
          <sum type="sha">3edce2737f1e846c27b44bcaa9b2b2c293da4195</sum>
        </package>
        <package arch="all" name="vim-doc" version="2:8.1.0875-5+deb10u6+tuxcare.els24">
          <filename>vim-doc_8.1.0875-5+deb10u6+tuxcare.els24_all.deb</filename>
          <sum type="sha">14ba827ead7d1c46ac1bf6a39de46a3dfe202c8e</sum>
        </package>
        <package arch="amd64" name="vim-gtk" version="2:8.1.0875-5+deb10u6+tuxcare.els24">
          <filename>vim-gtk_8.1.0875-5+deb10u6+tuxcare.els24_amd64.deb</filename>
          <sum type="sha">6600eb6a598399bc97b6bb258eef7158ec397b6d</sum>
        </package>
        <package arch="amd64" name="vim-gtk3" version="2:8.1.0875-5+deb10u6+tuxcare.els24">
          <filename>vim-gtk3_8.1.0875-5+deb10u6+tuxcare.els24_amd64.deb</filename>
          <sum type="sha">7b7bf89276649968263cc32cd976201afc56c201</sum>
        </package>
        <package arch="all" name="vim-gui-common" version="2:8.1.0875-5+deb10u6+tuxcare.els24">
          <filename>vim-gui-common_8.1.0875-5+deb10u6+tuxcare.els24_all.deb</filename>
          <sum type="sha">e1dffc82017ac170d63a4a487293682ef0954857</sum>
        </package>
        <package arch="amd64" name="vim-nox" version="2:8.1.0875-5+deb10u6+tuxcare.els24">
          <filename>vim-nox_8.1.0875-5+deb10u6+tuxcare.els24_amd64.deb</filename>
          <sum type="sha">15ee34282fc9493e36c09f00058ec91df887bf52</sum>
        </package>
        <package arch="all" name="vim-runtime" version="2:8.1.0875-5+deb10u6+tuxcare.els24">
          <filename>vim-runtime_8.1.0875-5+deb10u6+tuxcare.els24_all.deb</filename>
          <sum type="sha">7e8fb32ae636da23740e0a39d9a3e97e10302324</sum>
        </package>
        <package arch="amd64" name="vim-tiny" version="2:8.1.0875-5+deb10u6+tuxcare.els24">
          <filename>vim-tiny_8.1.0875-5+deb10u6+tuxcare.els24_amd64.deb</filename>
          <sum type="sha">714e2ecf89f639aba2c0fabe2aa291e0660211e7</sum>
        </package>
        <package arch="amd64" name="xxd" version="2:8.1.0875-5+deb10u6+tuxcare.els24">
          <filename>xxd_8.1.0875-5+deb10u6+tuxcare.els24_amd64.deb</filename>
          <sum type="sha">3f8b36c5f0c3f22785311c7a85cb687d99e59996</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1782990961</id>
    <title>Fix CVE(s): CVE-2026-4408</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix remote command execution via unescaped %u in 'check password script'
     - debian/patches/CVE-2026-4408.patch: fix remote command execution via unescaped %u in 'check password script'
     - CVE-2026-4408</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix remote command execution via unescaped %u in 'check password script'
     - debian/patches/CVE-2026-4408.patch: fix remote command execution via unescaped %u in 'check password script'
     - CVE-2026-4408</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-02 11:34:41 UTC" />
    <updated date="2026-07-02 11:34:41 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1782990961.html" id="CLSA-2026:1782990961" title="CLSA-2026:1782990961" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-4408" id="CVE-2026-4408" title="CVE-2026-4408" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="ctdb" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els8">
          <filename>ctdb_4.9.5+dfsg-5+deb10u5+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">d05a11ff9547faa23ba91c532048f14f51bb4843</sum>
        </package>
        <package arch="amd64" name="libnss-winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els8">
          <filename>libnss-winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">ca65ddb237b740803c959c16a245014a4b4755fd</sum>
        </package>
        <package arch="amd64" name="libpam-winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els8">
          <filename>libpam-winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">5f49670a878bd0f70e0d7063cbe1564960e25388</sum>
        </package>
        <package arch="amd64" name="libsmbclient" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els8">
          <filename>libsmbclient_4.9.5+dfsg-5+deb10u5+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">dfb03410727c76545f7d13c2108a3ba87f1bd819</sum>
        </package>
        <package arch="amd64" name="libsmbclient-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els8">
          <filename>libsmbclient-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">c699ffe205c6accb5cc9c2b3794d134efb5459d0</sum>
        </package>
        <package arch="amd64" name="libwbclient-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els8">
          <filename>libwbclient-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">90a4c583ac5062ab3ea87ffd28204a80ca6ecbe7</sum>
        </package>
        <package arch="amd64" name="libwbclient0" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els8">
          <filename>libwbclient0_4.9.5+dfsg-5+deb10u5+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">28ebffec310d969b9de542677b15405c98f2d029</sum>
        </package>
        <package arch="amd64" name="python-samba" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els8">
          <filename>python-samba_4.9.5+dfsg-5+deb10u5+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">67ae0535e54b6f69f7e7808d4bfe1d97a0464257</sum>
        </package>
        <package arch="amd64" name="registry-tools" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els8">
          <filename>registry-tools_4.9.5+dfsg-5+deb10u5+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">b449e44e11ea8a18d39690cf27d69dcbfe2ec28b</sum>
        </package>
        <package arch="amd64" name="samba" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els8">
          <filename>samba_4.9.5+dfsg-5+deb10u5+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">5aa94694a51a6b296c37d52e53a4e74bf6bbe611</sum>
        </package>
        <package arch="all" name="samba-common" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els8">
          <filename>samba-common_4.9.5+dfsg-5+deb10u5+tuxcare.els8_all.deb</filename>
          <sum type="sha">46e28104049907981cc8c08f89b1976c0010ae41</sum>
        </package>
        <package arch="amd64" name="samba-common-bin" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els8">
          <filename>samba-common-bin_4.9.5+dfsg-5+deb10u5+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">5f6fc3380c0a19d5f4b737d30f243f68baa2dae4</sum>
        </package>
        <package arch="amd64" name="samba-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els8">
          <filename>samba-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">5d6a7ee1c6cf45e9ee7935c574f22eb09eecc0bb</sum>
        </package>
        <package arch="amd64" name="samba-dsdb-modules" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els8">
          <filename>samba-dsdb-modules_4.9.5+dfsg-5+deb10u5+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">2988aca116f04ba3b5dd5961bb4d0faba615d0c7</sum>
        </package>
        <package arch="amd64" name="samba-libs" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els8">
          <filename>samba-libs_4.9.5+dfsg-5+deb10u5+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">f5468d66317945b9502f0797a9b3c2096670bc7a</sum>
        </package>
        <package arch="amd64" name="samba-testsuite" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els8">
          <filename>samba-testsuite_4.9.5+dfsg-5+deb10u5+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">16a09b7287eb522dca4e6d9a6b3ac465289cb90f</sum>
        </package>
        <package arch="amd64" name="samba-vfs-modules" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els8">
          <filename>samba-vfs-modules_4.9.5+dfsg-5+deb10u5+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">7175bdfb7ff568530d3b52dbe86046d94e72881c</sum>
        </package>
        <package arch="amd64" name="smbclient" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els8">
          <filename>smbclient_4.9.5+dfsg-5+deb10u5+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">7250c9f61ea5ea12767e23047208ef8a218abc9c</sum>
        </package>
        <package arch="amd64" name="winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els8">
          <filename>winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">6dd6fa55f63cbe6a54e38683c17b7e91b475bf4c</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1782987193</id>
    <title>Fix CVE(s): CVE-2026-44186</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: infinite loop in mod_proxy_ftp Retry-After parsing
     - debian/patches/CVE-2026-44186.patch: advance the scan pointer while
       searching for the delta-seconds digit in an FTP error response
       Retry-After header in modules/proxy/mod_proxy_ftp.c so the loop
       terminates instead of spinning forever
     - CVE-2026-44186</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: infinite loop in mod_proxy_ftp Retry-After parsing
     - debian/patches/CVE-2026-44186.patch: advance the scan pointer while
       searching for the delta-seconds digit in an FTP error response
       Retry-After header in modules/proxy/mod_proxy_ftp.c so the loop
       terminates instead of spinning forever
     - CVE-2026-44186</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-03 11:05:51 UTC" />
    <updated date="2026-07-03 11:05:51 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1782987193.html" id="CLSA-2026:1782987193" title="CLSA-2026:1782987193" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-44186" id="CVE-2026-44186" title="CVE-2026-44186" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="apache2" version="2.4.59-1~deb10u1+tuxcare.els9">
          <filename>apache2_2.4.59-1~deb10u1+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">6cbacce5e595dca4655400709972d35ae75d0729</sum>
        </package>
        <package arch="amd64" name="apache2-bin" version="2.4.59-1~deb10u1+tuxcare.els9">
          <filename>apache2-bin_2.4.59-1~deb10u1+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">dff96809912bda4ab92b86d120e58b3caf5aebaa</sum>
        </package>
        <package arch="all" name="apache2-data" version="2.4.59-1~deb10u1+tuxcare.els9">
          <filename>apache2-data_2.4.59-1~deb10u1+tuxcare.els9_all.deb</filename>
          <sum type="sha">ef8d19e93c30b88cd095a7d1911549f0014a074e</sum>
        </package>
        <package arch="amd64" name="apache2-dev" version="2.4.59-1~deb10u1+tuxcare.els9">
          <filename>apache2-dev_2.4.59-1~deb10u1+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">29c63fbcb3b80b774fd30f5ae0fc38a50c5168ac</sum>
        </package>
        <package arch="all" name="apache2-doc" version="2.4.59-1~deb10u1+tuxcare.els9">
          <filename>apache2-doc_2.4.59-1~deb10u1+tuxcare.els9_all.deb</filename>
          <sum type="sha">402cc310673ba858810661adc569cd39828bc247</sum>
        </package>
        <package arch="amd64" name="apache2-ssl-dev" version="2.4.59-1~deb10u1+tuxcare.els9">
          <filename>apache2-ssl-dev_2.4.59-1~deb10u1+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">8610fc667984eb019a1d8fe586b4c5a45cd3d07f</sum>
        </package>
        <package arch="amd64" name="apache2-suexec-custom" version="2.4.59-1~deb10u1+tuxcare.els9">
          <filename>apache2-suexec-custom_2.4.59-1~deb10u1+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">b9b94f14c729142ffb0f9935b3ae2bf5c5e416ba</sum>
        </package>
        <package arch="amd64" name="apache2-suexec-pristine" version="2.4.59-1~deb10u1+tuxcare.els9">
          <filename>apache2-suexec-pristine_2.4.59-1~deb10u1+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">ed290f1e39d7ad7715cb04397c1688b6fd985c9c</sum>
        </package>
        <package arch="amd64" name="apache2-utils" version="2.4.59-1~deb10u1+tuxcare.els9">
          <filename>apache2-utils_2.4.59-1~deb10u1+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">c8f0bb6271f7edc460351d47bcf6484512bc4228</sum>
        </package>
        <package arch="amd64" name="libapache2-mod-md" version="2.4.59-1~deb10u1+tuxcare.els9">
          <filename>libapache2-mod-md_2.4.59-1~deb10u1+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">198725309dcef8b93af25bbfa8fde9b0bc8857a8</sum>
        </package>
        <package arch="amd64" name="libapache2-mod-proxy-uwsgi" version="2.4.59-1~deb10u1+tuxcare.els9">
          <filename>libapache2-mod-proxy-uwsgi_2.4.59-1~deb10u1+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">6a4c61a2ebe36b407237d58b553cdb6d68f42900</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1783095251</id>
    <title>Fix CVE(s): CVE-2026-11979</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: stack buffer overflows in xmlcatalog --shell mode
     - debian/patches/CVE-2026-11979.patch: add bounds checks in the
       usershell() command-line parser in xmlcatalog.c to prevent stack
       buffer overflows when parsing overly long command lines
     - CVE-2026-11979</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: stack buffer overflows in xmlcatalog --shell mode
     - debian/patches/CVE-2026-11979.patch: add bounds checks in the
       usershell() command-line parser in xmlcatalog.c to prevent stack
       buffer overflows when parsing overly long command lines
     - CVE-2026-11979</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-03 16:14:28 UTC" />
    <updated date="2026-07-03 16:14:28 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1783095251.html" id="CLSA-2026:1783095251" title="CLSA-2026:1783095251" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-11979" id="CVE-2026-11979" title="CVE-2026-11979" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libxml2" version="2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els6">
          <filename>libxml2_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">91fd690672b069de7be1083b789942361c045fa9</sum>
        </package>
        <package arch="amd64" name="libxml2-dev" version="2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els6">
          <filename>libxml2-dev_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">5d9ee29c616c03de931f5c20140f12ba545b274e</sum>
        </package>
        <package arch="all" name="libxml2-doc" version="2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els6">
          <filename>libxml2-doc_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els6_all.deb</filename>
          <sum type="sha">1ba4817ae3a395fa8c8b733bbe29fd2fa89ff50b</sum>
        </package>
        <package arch="amd64" name="libxml2-utils" version="2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els6">
          <filename>libxml2-utils_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">fbd603f0531f00a2b76ba1ec12cce99dcb940088</sum>
        </package>
        <package arch="amd64" name="python-libxml2" version="2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els6">
          <filename>python-libxml2_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">95a73af57b125b277c31f79c86046d1aab2f57f2</sum>
        </package>
        <package arch="amd64" name="python3-libxml2" version="2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els6">
          <filename>python3-libxml2_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">0e16c21063f992c5279621145e9e6fcae429a759</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1783525080</id>
    <title>Fix CVE(s): CVE-2026-49975</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: memory allocation with excessive size value (DoS) in
     mod_http2 HTTP/2 cookie header merging
     - debian/patches/CVE-2026-49975.patch: count merged cookie headers as an
       add so they keep counting against LimitRequestFields, and ignore
       duplicate empty cookie headers, in req_add_header() in
       modules/http2/h2_util.c; otherwise repeated HTTP/2 cookie headers merge
       into one growing value without tripping the LimitRequestFields guard,
       letting a single stream drive unbounded memory allocation. Upstream fix
       35c6e405390ed361189a82acd96675401ea5947c (SVN r1934882).
     - CVE-2026-49975</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: memory allocation with excessive size value (DoS) in
     mod_http2 HTTP/2 cookie header merging
     - debian/patches/CVE-2026-49975.patch: count merged cookie headers as an
       add so they keep counting against LimitRequestFields, and ignore
       duplicate empty cookie headers, in req_add_header() in
       modules/http2/h2_util.c; otherwise repeated HTTP/2 cookie headers merge
       into one growing value without tripping the LimitRequestFields guard,
       letting a single stream drive unbounded memory allocation. Upstream fix
       35c6e405390ed361189a82acd96675401ea5947c (SVN r1934882).
     - CVE-2026-49975</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-08 15:38:16 UTC" />
    <updated date="2026-07-08 15:38:16 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1783525080.html" id="CLSA-2026:1783525080" title="CLSA-2026:1783525080" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-49975" id="CVE-2026-49975" title="CVE-2026-49975" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="apache2" version="2.4.59-1~deb10u1+tuxcare.els11">
          <filename>apache2_2.4.59-1~deb10u1+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">c3579aaacf1e823a5c62ec3264b73ff70cdaf458</sum>
        </package>
        <package arch="amd64" name="apache2-bin" version="2.4.59-1~deb10u1+tuxcare.els11">
          <filename>apache2-bin_2.4.59-1~deb10u1+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">d29335411a8b5c9140ed2401e30ea589ee3a1a24</sum>
        </package>
        <package arch="all" name="apache2-data" version="2.4.59-1~deb10u1+tuxcare.els11">
          <filename>apache2-data_2.4.59-1~deb10u1+tuxcare.els11_all.deb</filename>
          <sum type="sha">985e176cd7f161e48550639d1a8151a2646b0c11</sum>
        </package>
        <package arch="amd64" name="apache2-dev" version="2.4.59-1~deb10u1+tuxcare.els11">
          <filename>apache2-dev_2.4.59-1~deb10u1+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">01084f04af3441e57a63aa6de5e7495543020d17</sum>
        </package>
        <package arch="all" name="apache2-doc" version="2.4.59-1~deb10u1+tuxcare.els11">
          <filename>apache2-doc_2.4.59-1~deb10u1+tuxcare.els11_all.deb</filename>
          <sum type="sha">dce2c85a3f329bb01d2b57b7c96c19201012f546</sum>
        </package>
        <package arch="amd64" name="apache2-ssl-dev" version="2.4.59-1~deb10u1+tuxcare.els11">
          <filename>apache2-ssl-dev_2.4.59-1~deb10u1+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">01914b1f9e3c38fdd33947bcf6dc1258a7f63246</sum>
        </package>
        <package arch="amd64" name="apache2-suexec-custom" version="2.4.59-1~deb10u1+tuxcare.els11">
          <filename>apache2-suexec-custom_2.4.59-1~deb10u1+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">85d5a88cd87308abd1477d72dbf59f56c70987cb</sum>
        </package>
        <package arch="amd64" name="apache2-suexec-pristine" version="2.4.59-1~deb10u1+tuxcare.els11">
          <filename>apache2-suexec-pristine_2.4.59-1~deb10u1+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">0e7c13aa7fd2c240c4dd94be62e7e81df01d46e3</sum>
        </package>
        <package arch="amd64" name="apache2-utils" version="2.4.59-1~deb10u1+tuxcare.els11">
          <filename>apache2-utils_2.4.59-1~deb10u1+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">eccd36d02f3d3f2837474f251da7eef7390b2e05</sum>
        </package>
        <package arch="amd64" name="libapache2-mod-md" version="2.4.59-1~deb10u1+tuxcare.els11">
          <filename>libapache2-mod-md_2.4.59-1~deb10u1+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">379da7a96e2bdc5c2a230433d2ce400baee4bfdb</sum>
        </package>
        <package arch="amd64" name="libapache2-mod-proxy-uwsgi" version="2.4.59-1~deb10u1+tuxcare.els11">
          <filename>libapache2-mod-proxy-uwsgi_2.4.59-1~deb10u1+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">5e0c92dbe7196b04ead71d2607b893265dcd004c</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1783529026</id>
    <title>Fix CVE(s): CVE-2026-44631</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: buffer underwrite in ap_regname() regex capture handling
     - debian/patches/CVE-2026-44631.patch: cast the PCRE name-table bytes to
       unsigned char in ap_regname() so the capture group number cannot become
       negative, and reject capture numbers above 1024, in server/util_pcre.c;
       check the return value in the &lt;Directory&gt;, &lt;Location&gt;, &lt;Files&gt; and
       &lt;Proxy&gt; section handlers in server/core.c and modules/proxy/mod_proxy.c
     - CVE-2026-44631</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: buffer underwrite in ap_regname() regex capture handling
     - debian/patches/CVE-2026-44631.patch: cast the PCRE name-table bytes to
       unsigned char in ap_regname() so the capture group number cannot become
       negative, and reject capture numbers above 1024, in server/util_pcre.c;
       check the return value in the &lt;Directory&gt;, &lt;Location&gt;, &lt;Files&gt; and
       &lt;Proxy&gt; section handlers in server/core.c and modules/proxy/mod_proxy.c
     - CVE-2026-44631</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-08 16:44:03 UTC" />
    <updated date="2026-07-08 16:44:03 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1783529026.html" id="CLSA-2026:1783529026" title="CLSA-2026:1783529026" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-44631" id="CVE-2026-44631" title="CVE-2026-44631" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="apache2" version="2.4.59-1~deb10u1+tuxcare.els10">
          <filename>apache2_2.4.59-1~deb10u1+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">423f532f7492a0ec23384d469b988f68ff071d8b</sum>
        </package>
        <package arch="amd64" name="apache2-bin" version="2.4.59-1~deb10u1+tuxcare.els10">
          <filename>apache2-bin_2.4.59-1~deb10u1+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">48abb05c0d6fc039a80c238bc66f5836052e49de</sum>
        </package>
        <package arch="all" name="apache2-data" version="2.4.59-1~deb10u1+tuxcare.els10">
          <filename>apache2-data_2.4.59-1~deb10u1+tuxcare.els10_all.deb</filename>
          <sum type="sha">0c6aded390ea93ac1f1c6a416a47c9735b941534</sum>
        </package>
        <package arch="amd64" name="apache2-dev" version="2.4.59-1~deb10u1+tuxcare.els10">
          <filename>apache2-dev_2.4.59-1~deb10u1+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">b0ceb40f384ef892cb48a500a3dec0c37d70a3fd</sum>
        </package>
        <package arch="all" name="apache2-doc" version="2.4.59-1~deb10u1+tuxcare.els10">
          <filename>apache2-doc_2.4.59-1~deb10u1+tuxcare.els10_all.deb</filename>
          <sum type="sha">b5238db4071b378af9c57bacd440adf598f042ed</sum>
        </package>
        <package arch="amd64" name="apache2-ssl-dev" version="2.4.59-1~deb10u1+tuxcare.els10">
          <filename>apache2-ssl-dev_2.4.59-1~deb10u1+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">464f90b7e549193ac62656309a1f598a8b459589</sum>
        </package>
        <package arch="amd64" name="apache2-suexec-custom" version="2.4.59-1~deb10u1+tuxcare.els10">
          <filename>apache2-suexec-custom_2.4.59-1~deb10u1+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">e2062ca09382f2a152f6a99f27b114c6c60be9c2</sum>
        </package>
        <package arch="amd64" name="apache2-suexec-pristine" version="2.4.59-1~deb10u1+tuxcare.els10">
          <filename>apache2-suexec-pristine_2.4.59-1~deb10u1+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">ff201986a39b95fe5ce08bc731acd22011763568</sum>
        </package>
        <package arch="amd64" name="apache2-utils" version="2.4.59-1~deb10u1+tuxcare.els10">
          <filename>apache2-utils_2.4.59-1~deb10u1+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">40703a4bdda9f2cc4c913e3ac5272f68f89c754d</sum>
        </package>
        <package arch="amd64" name="libapache2-mod-md" version="2.4.59-1~deb10u1+tuxcare.els10">
          <filename>libapache2-mod-md_2.4.59-1~deb10u1+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">a988122d32f60869e01f9c4d2d34ee9ca5988706</sum>
        </package>
        <package arch="amd64" name="libapache2-mod-proxy-uwsgi" version="2.4.59-1~deb10u1+tuxcare.els10">
          <filename>libapache2-mod-proxy-uwsgi_2.4.59-1~deb10u1+tuxcare.els10_amd64.deb</filename>
          <sum type="sha">2d41e934bf1f8af34a58c7d84b62fa864c3d831d</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1783591738</id>
    <title>Fix of 12 CVEs</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: out-of-bounds read when writing an IPTC output file (single-byte over-read)
     - debian/patches/CVE-2026-42326.patch: tighten the IPTC tag-length bound check in GetIPTCStream() in coders/meta.c
     - CVE-2026-42326
   * SECURITY UPDATE: out-of-bounds over-read of 24 bytes during polynomial distortion
     - debian/patches/CVE-2026-45624.patch: validate the control-point argument count in GenerateCoefficients() in magick/distort.c
     - CVE-2026-45624
   * SECURITY UPDATE: out-of-bounds write in the MIFF encoder when using LZMA compression
     - debian/patches/CVE-2026-46521.patch: include LZMAMaxExtent in the buffer-length computation and fail on LZMA-encoder errors in WriteMIFFImage() in coders/miff.c
     - CVE-2026-46521
   * SECURITY UPDATE: stack overflow via a crafted MVG file (missing recursion-depth check)
     - debian/patches/CVE-2026-48734.patch: add a recursion-depth guard on nested MVG class expansion in RenderMVGContent() in magick/draw.c
     - CVE-2026-48734
   * SECURITY UPDATE: heap buffer over-write in the MAT decoder on 32-bit systems (missing return-value check)
     - debian/patches/CVE-2026-48994.patch: check the quantum-format setters' return values and bail out on failure in ReadMATImageV4() in coders/mat.c
     - CVE-2026-48994
   * SECURITY UPDATE: complete the CVE-2026-45664 MNG LOOP/ENDL loop-cap fix by releasing the chunk buffer before raising the resource-limit exception (heap memory leak on the loop-cap abort path)
     - debian/patches/CVE-2026-45664-1.patch: free chunk before both ThrowReaderException calls in ReadOneMNGImage() in coders/png.c
     - CVE-2026-45664</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: out-of-bounds read when writing an IPTC output file (single-byte over-read)
     - debian/patches/CVE-2026-42326.patch: tighten the IPTC tag-length bound check in GetIPTCStream() in coders/meta.c
     - CVE-2026-42326
   * SECURITY UPDATE: out-of-bounds over-read of 24 bytes during polynomial distortion
     - debian/patches/CVE-2026-45624.patch: validate the control-point argument count in GenerateCoefficients() in magick/distort.c
     - CVE-2026-45624
   * SECURITY UPDATE: out-of-bounds write in the MIFF encoder when using LZMA compression
     - debian/patches/CVE-2026-46521.patch: include LZMAMaxExtent in the buffer-length computation and fail on LZMA-encoder errors in WriteMIFFImage() in coders/miff.c
     - CVE-2026-46521
   * SECURITY UPDATE: stack overflow via a crafted MVG file (missing recursion-depth check)
     - debian/patches/CVE-2026-48734.patch: add a recursion-depth guard on nested MVG class expansion in RenderMVGContent() in magick/draw.c
     - CVE-2026-48734
   * SECURITY UPDATE: heap buffer over-write in the MAT decoder on 32-bit systems (missing return-value check)
     - debian/patches/CVE-2026-48994.patch: check the quantum-format setters' return values and bail out on failure in ReadMATImageV4() in coders/mat.c
     - CVE-2026-48994
   * SECURITY UPDATE: complete the CVE-2026-45664 MNG LOOP/ENDL loop-cap fix by releasing the chunk buffer before raising the resource-limit exception (heap memory leak on the loop-cap abort path)
     - debian/patches/CVE-2026-45664-1.patch: free chunk before both ThrowReaderException calls in ReadOneMNGImage() in coders/png.c
     - CVE-2026-45664</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-09 10:09:27 UTC" />
    <updated date="2026-07-09 10:09:27 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1783591738.html" id="CLSA-2026:1783591738" title="CLSA-2026:1783591738" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-33901" id="CVE-2026-33901" title="CVE-2026-33901" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-33908" id="CVE-2026-33908" title="CVE-2026-33908" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-42326" id="CVE-2026-42326" title="CVE-2026-42326" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-45031" id="CVE-2026-45031" title="CVE-2026-45031" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-45624" id="CVE-2026-45624" title="CVE-2026-45624" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-45664" id="CVE-2026-45664" title="CVE-2026-45664" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-46520" id="CVE-2026-46520" title="CVE-2026-46520" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-46521" id="CVE-2026-46521" title="CVE-2026-46521" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-46522" id="CVE-2026-46522" title="CVE-2026-46522" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-46523" id="CVE-2026-46523" title="CVE-2026-46523" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-48734" id="CVE-2026-48734" title="CVE-2026-48734" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-48994" id="CVE-2026-48994" title="CVE-2026-48994" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="imagemagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>imagemagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">78b3c1a1591284da614fdc9dcfe4bb52d6a9a555</sum>
        </package>
        <package arch="all" name="imagemagick-6-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>imagemagick-6-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_all.deb</filename>
          <sum type="sha">7817e639297f7a25ea64223a3383ab8fa820c83e</sum>
        </package>
        <package arch="all" name="imagemagick-6-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>imagemagick-6-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_all.deb</filename>
          <sum type="sha">b094891fa089b36909a3f87fbf55eea18512fddf</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>imagemagick-6.q16_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">306977dbf9a4d99adc2a6e78d9a456cb2c09e5b7</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16hdri" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>imagemagick-6.q16hdri_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">069274281257095bdbaa108dffeac3c4c394c047</sum>
        </package>
        <package arch="all" name="imagemagick-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>imagemagick-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_all.deb</filename>
          <sum type="sha">58d9d336e4980462c4a4ab1cffcbce8122c85355</sum>
        </package>
        <package arch="all" name="imagemagick-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>imagemagick-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_all.deb</filename>
          <sum type="sha">e81a1f360fa9136d3e7e0ff85235741293ef2606</sum>
        </package>
        <package arch="all" name="libimage-magick-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libimage-magick-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_all.deb</filename>
          <sum type="sha">20558151bb76b77ddb8e2bc00ffb53d5e51e7351</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libimage-magick-q16-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">d19aa26a52013e8577c741add008bc6b83d15e66</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16hdri-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libimage-magick-q16hdri-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">a12563d8c93345705de595ac19b0ffc322c0e942</sum>
        </package>
        <package arch="all" name="libmagick++-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libmagick++-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_all.deb</filename>
          <sum type="sha">5b997a92e90c5ca56933c4b1bc814332cce61fb0</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libmagick++-6.q16-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">7855948e5e07c2efd2b6f60dd6ea631f801e823d</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libmagick++-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">61f494848038b61d1aabe5e59f4d1e4b61cfd9f7</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libmagick++-6.q16hdri-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">48c765abdc983eefaedbc01259a657ddf5e9d480</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libmagick++-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">ef0063e2901666d082189adfde29a9b132a5e553</sum>
        </package>
        <package arch="all" name="libmagick++-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libmagick++-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_all.deb</filename>
          <sum type="sha">d465f3a13e85670e85bbe3e5d188cd628c9c321f</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6-arch-config" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libmagickcore-6-arch-config_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">06af25f37a68499add4de6a663a4229bc71d8782</sum>
        </package>
        <package arch="all" name="libmagickcore-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libmagickcore-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_all.deb</filename>
          <sum type="sha">6c2b43cacc830ad9fd4a0985f2c4b4e5d4cee2fd</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libmagickcore-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">49cf8cda04b2b5c960c156ac3a28dd8be0977110</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libmagickcore-6.q16-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">2ff7a79e1c4cefb3b5a7482b7ba5029f7615509a</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libmagickcore-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">43aaa3c884c45ba9562e39da9d75c3d548d19b37</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libmagickcore-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">95a7cb57cde28f1fc8a43627cd1d3b4763aab820</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libmagickcore-6.q16hdri-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">4536253616a4953c23a5c02734204156cc183947</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libmagickcore-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">d9442af0e116069fbfcda2f7a64efb7b4c58d7fa</sum>
        </package>
        <package arch="all" name="libmagickcore-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libmagickcore-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_all.deb</filename>
          <sum type="sha">983033db97135f811faafb3f9a03a35b32b229bf</sum>
        </package>
        <package arch="all" name="libmagickwand-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libmagickwand-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_all.deb</filename>
          <sum type="sha">7273f022516326cfbfcc2c42414a5479e42c19f9</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libmagickwand-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">6d26d07c7664356a214ca659295ff6280c9455ad</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libmagickwand-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">9f8e8f4decbe82fd911186a57d1b55e70e63f415</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libmagickwand-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">6d11ff287aa142cc9cb666960e3f70e0902086cd</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libmagickwand-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_amd64.deb</filename>
          <sum type="sha">f4ff3bbccd6def802addef31e24a8148086eb2f7</sum>
        </package>
        <package arch="all" name="libmagickwand-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>libmagickwand-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_all.deb</filename>
          <sum type="sha">f4f57fc82eb4dcdb136a80f6ae23bcbc092cf173</sum>
        </package>
        <package arch="all" name="perlmagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11">
          <filename>perlmagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els11_all.deb</filename>
          <sum type="sha">8c94ca10ad5de35ef1e1addc02b0d1a7b86c3fa7</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1783632526</id>
    <title>Fix CVE(s): CVE-2026-41992</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: out-of-bounds read in the LZH decoder from stale shared
     decompression state (left/right) reused across a .Z then .lzh member in a
     single gzip -d invocation
     - debian/patches/CVE-2026-41992.patch: clear left/right when n == 0 in
       read_c_len() in unlzh.c
     - CVE-2026-41992</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: out-of-bounds read in the LZH decoder from stale shared
     decompression state (left/right) reused across a .Z then .lzh member in a
     single gzip -d invocation
     - debian/patches/CVE-2026-41992.patch: clear left/right when n == 0 in
       read_c_len() in unlzh.c
     - CVE-2026-41992</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-09 21:29:01 UTC" />
    <updated date="2026-07-09 21:29:01 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1783632526.html" id="CLSA-2026:1783632526" title="CLSA-2026:1783632526" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-41992" id="CVE-2026-41992" title="CVE-2026-41992" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="gzip" version="1.9-3+deb10u1+tuxcare.els1">
          <filename>gzip_1.9-3+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">dfdf7d0cb031bad50db3eed2074a3f786e90b2e5</sum>
        </package>
        <package arch="all" name="gzip-win32" version="1.9-3+deb10u1+tuxcare.els1">
          <filename>gzip-win32_1.9-3+deb10u1+tuxcare.els1_all.deb</filename>
          <sum type="sha">3192c7fc68c0d2e3b858606e5875b8700b603eec</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1783970505</id>
    <title>Fix CVE(s): CVE-2025-43965</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: image depth mishandled after SetQuantumFormat in the MIFF reader (out-of-bounds read on crafted image)
     - debian/patches/CVE-2025-43965.patch: update image-&gt;depth from the quantum format's depth after SetQuantumFormat() in ReadMIFFImage() in coders/miff.c
     - CVE-2025-43965</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: image depth mishandled after SetQuantumFormat in the MIFF reader (out-of-bounds read on crafted image)
     - debian/patches/CVE-2025-43965.patch: update image-&gt;depth from the quantum format's depth after SetQuantumFormat() in ReadMIFFImage() in coders/miff.c
     - CVE-2025-43965</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-13 19:22:01 UTC" />
    <updated date="2026-07-13 19:22:01 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1783970505.html" id="CLSA-2026:1783970505" title="CLSA-2026:1783970505" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-43965" id="CVE-2025-43965" title="CVE-2025-43965" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="imagemagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>imagemagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">dc9d53dd05b075a71d9facdeaad50ac2b3de47c8</sum>
        </package>
        <package arch="all" name="imagemagick-6-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>imagemagick-6-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_all.deb</filename>
          <sum type="sha">500a3fcf2861b591097d9fc6d72c56f1f213af06</sum>
        </package>
        <package arch="all" name="imagemagick-6-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>imagemagick-6-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_all.deb</filename>
          <sum type="sha">8320d6d9d7f56e7d987ea5b546356aafc5d26b46</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>imagemagick-6.q16_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">b7340193adc2561817ec70f254a972e1acaf60da</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16hdri" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>imagemagick-6.q16hdri_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">1423f051fec881e5911121966a1239ac39f37e25</sum>
        </package>
        <package arch="all" name="imagemagick-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>imagemagick-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_all.deb</filename>
          <sum type="sha">af611af201e8aa7599301a9b90d730bae3009f54</sum>
        </package>
        <package arch="all" name="imagemagick-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>imagemagick-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_all.deb</filename>
          <sum type="sha">64a3fea695d38b8f0cd0423212d9966509839c72</sum>
        </package>
        <package arch="all" name="libimage-magick-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libimage-magick-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_all.deb</filename>
          <sum type="sha">2a9ff2f9cd8c5ef03c691d6a72cee8c76af9a4f1</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libimage-magick-q16-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">826d8becc68ade45f3541b211c4020caa429edc6</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16hdri-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libimage-magick-q16hdri-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">fe8de8da84a78d087193e3296d261c1a1478e8f5</sum>
        </package>
        <package arch="all" name="libmagick++-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libmagick++-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_all.deb</filename>
          <sum type="sha">37077db6345fcfbb1c87ffcb2aaa32bba141084f</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libmagick++-6.q16-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">4cdf873b4847927d817548c2f94ae0bb43203f49</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libmagick++-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">5e012f5a0aacfbfa4320359ab8157654b8b851f4</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libmagick++-6.q16hdri-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">4723544656d033aef4d6b281095afff7ea9dde9e</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libmagick++-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">7a47d0b272c8688a862d20242c66e3e29f74d9b4</sum>
        </package>
        <package arch="all" name="libmagick++-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libmagick++-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_all.deb</filename>
          <sum type="sha">485a44fb7072a3a2dace7574ed4c2538efeadfa2</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6-arch-config" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libmagickcore-6-arch-config_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">e3dd101c30cb74535db99815d1f0bd27b265b1e7</sum>
        </package>
        <package arch="all" name="libmagickcore-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libmagickcore-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_all.deb</filename>
          <sum type="sha">a7620bf8e64394ec38a1b6f34794f768733e4171</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libmagickcore-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">bbf3aa52a040d3b5d9f2aa1d2d2c90c1c8e0bb83</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libmagickcore-6.q16-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">da716e2cff72c18af24a2b82cb1f02fbd715ee24</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libmagickcore-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">cfdd2e6c16bf06aaeaf34c62374226ece342cd13</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libmagickcore-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">209c86949974e9ecace55a2787b7a7aad5201197</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libmagickcore-6.q16hdri-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">047abd807d37dcddd1a7aa28b9114c475f3a8740</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libmagickcore-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">4da0eb184d707f395e19297e32124b473e1b40b7</sum>
        </package>
        <package arch="all" name="libmagickcore-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libmagickcore-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_all.deb</filename>
          <sum type="sha">b326a43cf7c30d2314ba2fc09ce2975e5dc118d3</sum>
        </package>
        <package arch="all" name="libmagickwand-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libmagickwand-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_all.deb</filename>
          <sum type="sha">f574c8ee5d9d23886d54eada06dd3d22db1cbc1e</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libmagickwand-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">7714fc3357d94ae356e54b711227c85f638d2fc6</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libmagickwand-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">63aa075fe90c4e7ee03aa4b4e9b7eaded877eb90</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libmagickwand-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">eee6cad4c025d82ab3c1c99eb0833bc75470a178</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libmagickwand-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">78dc1e7a4a3194ce2e46c9d5973a193f06d57d6a</sum>
        </package>
        <package arch="all" name="libmagickwand-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>libmagickwand-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_all.deb</filename>
          <sum type="sha">41eafeaa6ba11156ca0d6fa7c92a149ec6410a69</sum>
        </package>
        <package arch="all" name="perlmagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12">
          <filename>perlmagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els12_all.deb</filename>
          <sum type="sha">34ebfb7180fa7e5098cd332beeb0c9e1ba4912af</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="bugfix" version="1">
    <id>CLSA-2025:1759937401</id>
    <title>Update of els-os-release</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * Move gpg key and repo installation from debian/install to postinst
   * Add support for multiple deb platforms</description>
    <severity>None</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * Move gpg key and repo installation from debian/install to postinst
   * Add support for multiple deb platforms</summary>
    <pushcount>0</pushcount>
    <issued date="2025-10-08 15:35:05 UTC" />
    <updated date="2025-10-08 15:35:05 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1759937401.html" id="CLSA-2025:1759937401" title="CLSA-2025:1759937401" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="els-os-release" version="1.0.0-2">
          <filename>els-os-release_1.0.0-2_amd64.deb</filename>
          <sum type="sha">47238eb136a07fb1b91fe531b6e4ebbd3207a6ab</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="bugfix" version="1">
    <id>CLSA-2026:1770325139</id>
    <title>Update of intel-microcode</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * New microcode update packages from upstream up to 2025-11-11:
     - New microcodes:
       sig 0x000606c1, pf_mask 0x10, 2025-03-06, rev 0x10002e0, size 301056
       sig 0x000806f4, pf_mask 0x10, 2025-05-29, rev 0x2c000410, size 625664
       sig 0x000806f4, pf_mask 0x87, 2025-05-29, rev 0x2b000650, size 593920
       sig 0x000806f5, pf_mask 0x10, 2025-05-29, rev 0x2c000410, size 625664
       sig 0x000806f5, pf_mask 0x87, 2025-05-29, rev 0x2b000650, size 593920
       sig 0x000806f6, pf_mask 0x10, 2025-05-29, rev 0x2c000410, size 625664
       sig 0x000806f6, pf_mask 0x87, 2025-05-29, rev 0x2b000650, size 593920
       sig 0x000806f7, pf_mask 0x87, 2025-05-29, rev 0x2b000650, size 593920
       sig 0x000806f8, pf_mask 0x10, 2025-05-29, rev 0x2c000410, size 625664
       sig 0x000806f8, pf_mask 0x87, 2025-05-29, rev 0x2b000650, size 593920
       sig 0x000a06a4, pf_mask 0xe6, 2025-03-19, rev 0x0025, size 140288
       sig 0x000a06d1, pf_mask 0x20, 2025-08-29, rev 0xa000124, size 1642496
       sig 0x000a06d1, pf_mask 0x95, 2025-07-23, rev 0x10003f0, size 1670144
       sig 0x000a06e1, pf_mask 0x97, 2025-06-27, rev 0x1000273, size 1635328
       sig 0x000a06f3, pf_mask 0x01, 2025-07-30, rev 0x3000382, size 1534976
       sig 0x000b0650, pf_mask 0x80, 2025-03-18, rev 0x000a, size 136192
       sig 0x000b0671, pf_mask 0x32, 2025-10-08, rev 0x0132, size 219136
       sig 0x000b0674, pf_mask 0x32, 2025-10-08, rev 0x0132, size 219136
       sig 0x000b06a2, pf_mask 0xe0, 2025-10-08, rev 0x6133, size 224256
       sig 0x000b06a3, pf_mask 0xe0, 2025-10-08, rev 0x6133, size 224256
       sig 0x000b06a8, pf_mask 0xe0, 2025-10-08, rev 0x6133, size 224256
       sig 0x000b06d1, pf_mask 0x80, 2025-08-28, rev 0x0125, size 80896
       sig 0x000b06e0, pf_mask 0x19, 2025-05-16, rev 0x001e, size 139264
       sig 0x000b06f6, pf_mask 0x07, 2025-10-12, rev 0x003d, size 226304
       sig 0x000b06f7, pf_mask 0x07, 2025-10-12, rev 0x003d, size 226304
       sig 0x000c0652, pf_mask 0x82, 2025-06-30, rev 0x011a, size 90112
       sig 0x000c0662, pf_mask 0x82, 2025-06-30, rev 0x011a, size 90112
       sig 0x000c0664, pf_mask 0x82, 2025-06-30, rev 0x011a, size 90112
       sig 0x000c06a2, pf_mask 0x82, 2025-06-30, rev 0x011a, size 90112
       sig 0x000c06f1, pf_mask 0x87, 2025-05-29, rev 0x210002c0, size 564224
       sig 0x000c06f2, pf_mask 0x87, 2025-05-29, rev 0x210002c0, size 564224
     - Updated microcodes:
       sig 0x00050653, pf_mask 0x97, 2023-07-28, rev 0x1000191, size 36864
       sig 0x00050654, pf_mask 0xb7, 2023-03-06, rev 0x2007006, size 44032
       sig 0x00050657, pf_mask 0xbf, 2024-12-12, rev 0x5003901, size 39936
       sig 0x0005065b, pf_mask 0xbf, 2024-12-12, rev 0x7002b01, size 30720
       sig 0x00050665, pf_mask 0x10, 2023-08-03, rev 0xe000015, size 23552
       sig 0x000506f1, pf_mask 0x01, 2023-10-05, rev 0x003e, size 11264
       sig 0x000606a6, pf_mask 0x87, 2025-03-11, rev 0xd000410, size 309248
       sig 0x000706a1, pf_mask 0x01, 2024-04-19, rev 0x0042, size 76800
       sig 0x000706a8, pf_mask 0x01, 2024-12-05, rev 0x0026, size 76800
       sig 0x000706e5, pf_mask 0x80, 2025-01-07, rev 0x00ca, size 115712
       sig 0x000806a1, pf_mask 0x10, 2023-01-13, rev 0x0033, size 34816
       sig 0x000806c1, pf_mask 0x80, 2024-12-01, rev 0x00bc, size 112640
       sig 0x000806c2, pf_mask 0xc2, 2024-12-01, rev 0x003c, size 99328
       sig 0x000806d1, pf_mask 0xc2, 2024-12-11, rev 0x0056, size 105472
       sig 0x000806e9, pf_mask 0x10, 2024-02-01, rev 0x00f6, size 106496
       sig 0x000806e9, pf_mask 0xc0, 2024-02-01, rev 0x00f6, size 106496
       sig 0x000806ea, pf_mask 0xc0, 2024-02-01, rev 0x00f6, size 105472
       sig 0x000806eb, pf_mask 0xd0, 2024-02-01, rev 0x00f6, size 106496
       sig 0x000806ec, pf_mask 0x94, 2024-11-17, rev 0x0100, size 106496
       sig 0x00090661, pf_mask 0x01, 2024-04-05, rev 0x001a, size 20480
       sig 0x00090672, pf_mask 0x07, 2025-10-12, rev 0x003d, size 226304
       sig 0x00090675, pf_mask 0x07, 2025-10-12, rev 0x003d, size 226304
       sig 0x000906a3, pf_mask 0x80, 2025-10-12, rev 0x043a, size 224256
       sig 0x000906a4, pf_mask 0x40, 2025-06-13, rev 0x000b, size 119808
       sig 0x000906a4, pf_mask 0x80, 2025-10-12, rev 0x043a, size 224256
       sig 0x000906c0, pf_mask 0x01, 2023-09-26, rev 0x24000026, size 20480
       sig 0x000906e9, pf_mask 0x2a, 2023-09-28, rev 0x00f8, size 108544
       sig 0x000906ea, pf_mask 0x22, 2024-07-28, rev 0x00fa, size 105472
       sig 0x000906eb, pf_mask 0x02, 2024-02-01, rev 0x00f6, size 106496
       sig 0x000906ec, pf_mask 0x22, 2024-02-01, rev 0x00f8, size 106496
       sig 0x000906ed, pf_mask 0x22, 2024-11-14, rev 0x0104, size 106496
       sig 0x000a0652, pf_mask 0x20, 2024-11-14, rev 0x0100, size 97280
       sig 0x000a0653, pf_mask 0x22, 2024-11-14, rev 0x0100, size 98304
       sig 0x000a0655, pf_mask 0x22, 2024-11-14, rev 0x0100, size 97280
       sig 0x000a0660, pf_mask 0x80, 2024-11-14, rev 0x0102, size 98304
       sig 0x000a0661, pf_mask 0x80, 2024-11-14, rev 0x0100, size 97280
       sig 0x000a0671, pf_mask 0x02, 2024-12-01, rev 0x0064, size 108544
       sig 0x000b06f2, pf_mask 0x07, 2025-10-12, rev 0x003d, size 226304
       sig 0x000b06f5, pf_mask 0x07, 2025-10-12, rev 0x003d, size 226304
     - Removed microcodes:
       sig 0x00050656, pf_mask 0xbf, 2021-12-10, rev 0x4003302, size 37888</description>
    <severity>None</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * New microcode update packages from upstream up to 2025-11-11:
     - New microcodes:
       sig 0x000606c1, pf_mask 0x10, 2025-03-06, rev 0x10002e0, size 301056
       sig 0x000806f4, pf_mask 0x10, 2025-05-29, rev 0x2c000410, size 625664
       sig 0x000806f4, pf_mask 0x87, 2025-05-29, rev 0x2b000650, size 593920
       sig 0x000806f5, pf_mask 0x10, 2025-05-29, rev 0x2c000410, size 625664
       sig 0x000806f5, pf_mask 0x87, 2025-05-29, rev 0x2b000650, size 593920
       sig 0x000806f6, pf_mask 0x10, 2025-05-29, rev 0x2c000410, size 625664
       sig 0x000806f6, pf_mask 0x87, 2025-05-29, rev 0x2b000650, size 593920
       sig 0x000806f7, pf_mask 0x87, 2025-05-29, rev 0x2b000650, size 593920
       sig 0x000806f8, pf_mask 0x10, 2025-05-29, rev 0x2c000410, size 625664
       sig 0x000806f8, pf_mask 0x87, 2025-05-29, rev 0x2b000650, size 593920
       sig 0x000a06a4, pf_mask 0xe6, 2025-03-19, rev 0x0025, size 140288
       sig 0x000a06d1, pf_mask 0x20, 2025-08-29, rev 0xa000124, size 1642496
       sig 0x000a06d1, pf_mask 0x95, 2025-07-23, rev 0x10003f0, size 1670144
       sig 0x000a06e1, pf_mask 0x97, 2025-06-27, rev 0x1000273, size 1635328
       sig 0x000a06f3, pf_mask 0x01, 2025-07-30, rev 0x3000382, size 1534976
       sig 0x000b0650, pf_mask 0x80, 2025-03-18, rev 0x000a, size 136192
       sig 0x000b0671, pf_mask 0x32, 2025-10-08, rev 0x0132, size 219136
       sig 0x000b0674, pf_mask 0x32, 2025-10-08, rev 0x0132, size 219136
       sig 0x000b06a2, pf_mask 0xe0, 2025-10-08, rev 0x6133, size 224256
       sig 0x000b06a3, pf_mask 0xe0, 2025-10-08, rev 0x6133, size 224256
       sig 0x000b06a8, pf_mask 0xe0, 2025-10-08, rev 0x6133, size 224256
       sig 0x000b06d1, pf_mask 0x80, 2025-08-28, rev 0x0125, size 80896
       sig 0x000b06e0, pf_mask 0x19, 2025-05-16, rev 0x001e, size 139264
       sig 0x000b06f6, pf_mask 0x07, 2025-10-12, rev 0x003d, size 226304
       sig 0x000b06f7, pf_mask 0x07, 2025-10-12, rev 0x003d, size 226304
       sig 0x000c0652, pf_mask 0x82, 2025-06-30, rev 0x011a, size 90112
       sig 0x000c0662, pf_mask 0x82, 2025-06-30, rev 0x011a, size 90112
       sig 0x000c0664, pf_mask 0x82, 2025-06-30, rev 0x011a, size 90112
       sig 0x000c06a2, pf_mask 0x82, 2025-06-30, rev 0x011a, size 90112
       sig 0x000c06f1, pf_mask 0x87, 2025-05-29, rev 0x210002c0, size 564224
       sig 0x000c06f2, pf_mask 0x87, 2025-05-29, rev 0x210002c0, size 564224
     - Updated microcodes:
       sig 0x00050653, pf_mask 0x97, 2023-07-28, rev 0x1000191, size 36864
       sig 0x00050654, pf_mask 0xb7, 2023-03-06, rev 0x2007006, size 44032
       sig 0x00050657, pf_mask 0xbf, 2024-12-12, rev 0x5003901, size 39936
       sig 0x0005065b, pf_mask 0xbf, 2024-12-12, rev 0x7002b01, size 30720
       sig 0x00050665, pf_mask 0x10, 2023-08-03, rev 0xe000015, size 23552
       sig 0x000506f1, pf_mask 0x01, 2023-10-05, rev 0x003e, size 11264
       sig 0x000606a6, pf_mask 0x87, 2025-03-11, rev 0xd000410, size 309248
       sig 0x000706a1, pf_mask 0x01, 2024-04-19, rev 0x0042, size 76800
       sig 0x000706a8, pf_mask 0x01, 2024-12-05, rev 0x0026, size 76800
       sig 0x000706e5, pf_mask 0x80, 2025-01-07, rev 0x00ca, size 115712
       sig 0x000806a1, pf_mask 0x10, 2023-01-13, rev 0x0033, size 34816
       sig 0x000806c1, pf_mask 0x80, 2024-12-01, rev 0x00bc, size 112640
       sig 0x000806c2, pf_mask 0xc2, 2024-12-01, rev 0x003c, size 99328
       sig 0x000806d1, pf_mask 0xc2, 2024-12-11, rev 0x0056, size 105472
       sig 0x000806e9, pf_mask 0x10, 2024-02-01, rev 0x00f6, size 106496
       sig 0x000806e9, pf_mask 0xc0, 2024-02-01, rev 0x00f6, size 106496
       sig 0x000806ea, pf_mask 0xc0, 2024-02-01, rev 0x00f6, size 105472
       sig 0x000806eb, pf_mask 0xd0, 2024-02-01, rev 0x00f6, size 106496
       sig 0x000806ec, pf_mask 0x94, 2024-11-17, rev 0x0100, size 106496
       sig 0x00090661, pf_mask 0x01, 2024-04-05, rev 0x001a, size 20480
       sig 0x00090672, pf_mask 0x07, 2025-10-12, rev 0x003d, size 226304
       sig 0x00090675, pf_mask 0x07, 2025-10-12, rev 0x003d, size 226304
       sig 0x000906a3, pf_mask 0x80, 2025-10-12, rev 0x043a, size 224256
       sig 0x000906a4, pf_mask 0x40, 2025-06-13, rev 0x000b, size 119808
       sig 0x000906a4, pf_mask 0x80, 2025-10-12, rev 0x043a, size 224256
       sig 0x000906c0, pf_mask 0x01, 2023-09-26, rev 0x24000026, size 20480
       sig 0x000906e9, pf_mask 0x2a, 2023-09-28, rev 0x00f8, size 108544
       sig 0x000906ea, pf_mask 0x22, 2024-07-28, rev 0x00fa, size 105472
       sig 0x000906eb, pf_mask 0x02, 2024-02-01, rev 0x00f6, size 106496
       sig 0x000906ec, pf_mask 0x22, 2024-02-01, rev 0x00f8, size 106496
       sig 0x000906ed, pf_mask 0x22, 2024-11-14, rev 0x0104, size 106496
       sig 0x000a0652, pf_mask 0x20, 2024-11-14, rev 0x0100, size 97280
       sig 0x000a0653, pf_mask 0x22, 2024-11-14, rev 0x0100, size 98304
       sig 0x000a0655, pf_mask 0x22, 2024-11-14, rev 0x0100, size 97280
       sig 0x000a0660, pf_mask 0x80, 2024-11-14, rev 0x0102, size 98304
       sig 0x000a0661, pf_mask 0x80, 2024-11-14, rev 0x0100, size 97280
       sig 0x000a0671, pf_mask 0x02, 2024-12-01, rev 0x0064, size 108544
       sig 0x000b06f2, pf_mask 0x07, 2025-10-12, rev 0x003d, size 226304
       sig 0x000b06f5, pf_mask 0x07, 2025-10-12, rev 0x003d, size 226304
     - Removed microcodes:
       sig 0x00050656, pf_mask 0xbf, 2021-12-10, rev 0x4003302, size 37888</summary>
    <pushcount>0</pushcount>
    <issued date="2026-02-05 20:59:03 UTC" />
    <updated date="2026-02-05 20:59:03 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1770325139.html" id="CLSA-2026:1770325139" title="CLSA-2026:1770325139" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="intel-microcode" version="3.20251111.1~deb10u1+tuxcare.els1">
          <filename>intel-microcode_3.20251111.1~deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">1df0b8ae50a874caddbda29836cade4fbada56fe</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="bugfix" version="1">
    <id>CLSA-2026:1771112524</id>
    <title>Update of nss</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * Update ca-certificates database to 20260129:
     - mozilla\{certdata.h,nssckbi.h}: Update Mozilla certificate
       authority bundle of the version 2.82.
     - The following certificates were updated:
       # Certificate "GlobalSign Root CA"
       # Certificate "Entrust.net Premium 2048 Secure Server CA"
       # Certificate "Comodo AAA Services root"
       # Certificate "XRamp Global CA Root"
       # Certificate "Go Daddy Class 2 CA"
       # Certificate "Starfield Class 2 CA"
       # Certificate "OISTE WISeKey Global Root GA CA"
       # Certificate "certSIGN ROOT CA"
       # Certificate "ACCVRAIZ1"
       # Certificate "Staat der Nederlanden Root CA - G3"
       # Certificate "OISTE WISeKey Global Root GC CA"
     - The following certificates were added:
       # Certificate "emSign Root CA - G1"
       # Certificate "emSign ECC Root CA - G3"
       # Certificate "emSign Root CA - C1"
       # Certificate "emSign ECC Root CA - C3"
       # Certificate "Hongkong Post Root CA 3"
       # Certificate "Entrust Root Certification Authority - G4"
       # Certificate "Microsoft ECC Root Certificate Authority 2017"
       # Certificate "Microsoft RSA Root Certificate Authority 2017"
       # Certificate "e-Szigno Root CA 2017"
       # Certificate "certSIGN Root CA G2"
       # Certificate "Trustwave Global Certification Authority"
       # Certificate "Trustwave Global ECC P256 Certification Authority"
       # Certificate "Trustwave Global ECC P384 Certification Authority"
       # Certificate "NAVER Global Root Certification Authority"
       # Certificate "AC RAIZ FNMT-RCM SERVIDORES SEGUROS"
       # Certificate "GlobalSign Secure Mail Root R45"
       # Certificate "GlobalSign Secure Mail Root E45"
       # Certificate "GlobalSign Root R46"
       # Certificate "GlobalSign Root E46"
       # Certificate "GLOBALTRUST 2020"
       # Certificate "ANF Secure Server Root CA"
       # Certificate "Certum EC-384 CA"
       # Certificate "Certum Trusted Root CA"
       # Certificate "TunTrust Root CA"
       # Certificate "HARICA TLS RSA Root CA 2021"
       # Certificate "HARICA TLS ECC Root CA 2021"
       # Certificate "HARICA Client RSA Root CA 2021"
       # Certificate "HARICA Client ECC Root CA 2021"
       # Certificate "Autoridad de Certificacion Firmaprofesional CIF A62634068"
       # Certificate "vTrus ECC Root CA"
       # Certificate "vTrus Root CA"
       # Certificate "ISRG Root X2"
       # Certificate "HiPKI Root CA - G1"
       # Certificate "GlobalSign ECC Root CA - R4"
       # Certificate "GTS Root R1"
       # Certificate "GTS Root R2"
       # Certificate "GTS Root R3"
       # Certificate "GTS Root R4"
       # Certificate "Telia Root CA v2"
       # Certificate "D-TRUST BR Root CA 1 2020"
       # Certificate "D-TRUST EV Root CA 1 2020"
       # Certificate "DigiCert TLS ECC P384 Root G5"
       # Certificate "DigiCert TLS RSA4096 Root G5"
       # Certificate "DigiCert SMIME ECC P384 Root G5"
       # Certificate "DigiCert SMIME RSA4096 Root G5"
       # Certificate "Certainly Root R1"
       # Certificate "Certainly Root E1"
       # Certificate "DIGITALSIGN GLOBAL ROOT RSA CA"
       # Certificate "DIGITALSIGN GLOBAL ROOT ECDSA CA"
       # Certificate "Security Communication ECC RootCA1"
       # Certificate "BJCA Global Root CA1"
       # Certificate "BJCA Global Root CA2"
       # Certificate "LAWtrust Root CA2 (4096)"
       # Certificate "Sectigo Public Email Protection Root E46"
       # Certificate "Sectigo Public Email Protection Root R46"
       # Certificate "Sectigo Public Server Authentication Root E46"
       # Certificate "Sectigo Public Server Authentication Root R46"
       # Certificate "SSL.com TLS RSA Root CA 2022"
       # Certificate "SSL.com TLS ECC Root CA 2022"
       # Certificate "SSL.com Client ECC Root CA 2022"
       # Certificate "SSL.com Client RSA Root CA 2022"
       # Certificate "Atos TrustedRoot Root CA ECC G2 2020"
       # Certificate "Atos TrustedRoot Root CA RSA G2 2020"
       # Certificate "Atos TrustedRoot Root CA ECC TLS 2021"
       # Certificate "Atos TrustedRoot Root CA RSA TLS 2021"
       # Certificate "TrustAsia Global Root CA G3"
       # Certificate "TrustAsia Global Root CA G4"
       # Certificate "D-Trust SBR Root CA 1 2022"
       # Certificate "D-Trust SBR Root CA 2 2022"
       # Certificate "Telekom Security SMIME ECC Root 2021"
       # Certificate "Telekom Security TLS ECC Root 2020"
       # Certificate "Telekom Security SMIME RSA Root 2023"
       # Certificate "Telekom Security TLS RSA Root 2023"
       # Certificate "FIRMAPROFESIONAL CA ROOT-A WEB"
       # Certificate "TWCA CYBER Root CA"
       # Certificate "TWCA Global Root CA G2"
       # Certificate "SecureSign Root CA12"
       # Certificate "SecureSign Root CA14"
       # Certificate "SecureSign Root CA15"
       # Certificate "D-TRUST BR Root CA 2 2023"
       # Certificate "TrustAsia SMIME ECC Root CA"
       # Certificate "TrustAsia SMIME RSA Root CA"
       # Certificate "TrustAsia TLS ECC Root CA"
       # Certificate "TrustAsia TLS RSA Root CA"
       # Certificate "D-TRUST EV Root CA 2 2023"
       # Certificate "SwissSign RSA SMIME Root CA 2022 - 1"
       # Certificate "SwissSign RSA TLS Root CA 2022 - 1"
       # Certificate "OISTE Client Root ECC G1"
       # Certificate "OISTE Client Root RSA G1"
       # Certificate "OISTE Server Root ECC G1"
       # Certificate " OISTE Server Root RSA G1"
     - The following certificates were removed:
       # Certificate "GlobalSign Root CA - R2"
       # Certificate "Baltimore CyberTrust Root"
       # Certificate "AddTrust Low-Value Services Root"
       # Certificate "AddTrust External Root"
       # Certificate "GeoTrust Global CA"
       # Certificate "QuoVadis Root CA"
       # Certificate "Security Communication Root CA"
       # Certificate "Sonera Class 2 Root CA"
       # Certificate "UTN USERFirst Email Root CA"
       # Certificate "Camerfirma Chambers of Commerce Root"
       # Certificate "Camerfirma Global Chambersign Root"
       # Certificate "Certplus Class 2 Primary CA"
       # Certificate "DST Root CA X3"
       # Certificate "Deutsche Telekom Root CA 2"
       # Certificate "Cybertrust Global Root"
       # Certificate "Staat der Nederlanden Root CA - G2"
       # Certificate "Hongkong Post Root CA 1"
       # Certificate "Chambers of Commerce Root - 2008"
       # Certificate "Global Chambersign Root - 2008"
       # Certificate "Trustis FPS Root CA"
       # Certificate "E-Tugra Certification Authority"
       # Certificate "Staat der Nederlanden EV Root CA"
       # Certificate "TrustCor RootCert CA-1"
       # Certificate "TrustCor RootCert CA-2"
       # Certificate "TrustCor ECA-1"</description>
    <severity>None</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * Update ca-certificates database to 20260129:
     - mozilla\{certdata.h,nssckbi.h}: Update Mozilla certificate
       authority bundle of the version 2.82.
     - The following certificates were updated:
       # Certificate "GlobalSign Root CA"
       # Certificate "Entrust.net Premium 2048 Secure Server CA"
       # Certificate "Comodo AAA Services root"
       # Certificate "XRamp Global CA Root"
       # Certificate "Go Daddy Class 2 CA"
       # Certificate "Starfield Class 2 CA"
       # Certificate "OISTE WISeKey Global Root GA CA"
       # Certificate "certSIGN ROOT CA"
       # Certificate "ACCVRAIZ1"
       # Certificate "Staat der Nederlanden Root CA - G3"
       # Certificate "OISTE WISeKey Global Root GC CA"
     - The following certificates were added:
       # Certificate "emSign Root CA - G1"
       # Certificate "emSign ECC Root CA - G3"
       # Certificate "emSign Root CA - C1"
       # Certificate "emSign ECC Root CA - C3"
       # Certificate "Hongkong Post Root CA 3"
       # Certificate "Entrust Root Certification Authority - G4"
       # Certificate "Microsoft ECC Root Certificate Authority 2017"
       # Certificate "Microsoft RSA Root Certificate Authority 2017"
       # Certificate "e-Szigno Root CA 2017"
       # Certificate "certSIGN Root CA G2"
       # Certificate "Trustwave Global Certification Authority"
       # Certificate "Trustwave Global ECC P256 Certification Authority"
       # Certificate "Trustwave Global ECC P384 Certification Authority"
       # Certificate "NAVER Global Root Certification Authority"
       # Certificate "AC RAIZ FNMT-RCM SERVIDORES SEGUROS"
       # Certificate "GlobalSign Secure Mail Root R45"
       # Certificate "GlobalSign Secure Mail Root E45"
       # Certificate "GlobalSign Root R46"
       # Certificate "GlobalSign Root E46"
       # Certificate "GLOBALTRUST 2020"
       # Certificate "ANF Secure Server Root CA"
       # Certificate "Certum EC-384 CA"
       # Certificate "Certum Trusted Root CA"
       # Certificate "TunTrust Root CA"
       # Certificate "HARICA TLS RSA Root CA 2021"
       # Certificate "HARICA TLS ECC Root CA 2021"
       # Certificate "HARICA Client RSA Root CA 2021"
       # Certificate "HARICA Client ECC Root CA 2021"
       # Certificate "Autoridad de Certificacion Firmaprofesional CIF A62634068"
       # Certificate "vTrus ECC Root CA"
       # Certificate "vTrus Root CA"
       # Certificate "ISRG Root X2"
       # Certificate "HiPKI Root CA - G1"
       # Certificate "GlobalSign ECC Root CA - R4"
       # Certificate "GTS Root R1"
       # Certificate "GTS Root R2"
       # Certificate "GTS Root R3"
       # Certificate "GTS Root R4"
       # Certificate "Telia Root CA v2"
       # Certificate "D-TRUST BR Root CA 1 2020"
       # Certificate "D-TRUST EV Root CA 1 2020"
       # Certificate "DigiCert TLS ECC P384 Root G5"
       # Certificate "DigiCert TLS RSA4096 Root G5"
       # Certificate "DigiCert SMIME ECC P384 Root G5"
       # Certificate "DigiCert SMIME RSA4096 Root G5"
       # Certificate "Certainly Root R1"
       # Certificate "Certainly Root E1"
       # Certificate "DIGITALSIGN GLOBAL ROOT RSA CA"
       # Certificate "DIGITALSIGN GLOBAL ROOT ECDSA CA"
       # Certificate "Security Communication ECC RootCA1"
       # Certificate "BJCA Global Root CA1"
       # Certificate "BJCA Global Root CA2"
       # Certificate "LAWtrust Root CA2 (4096)"
       # Certificate "Sectigo Public Email Protection Root E46"
       # Certificate "Sectigo Public Email Protection Root R46"
       # Certificate "Sectigo Public Server Authentication Root E46"
       # Certificate "Sectigo Public Server Authentication Root R46"
       # Certificate "SSL.com TLS RSA Root CA 2022"
       # Certificate "SSL.com TLS ECC Root CA 2022"
       # Certificate "SSL.com Client ECC Root CA 2022"
       # Certificate "SSL.com Client RSA Root CA 2022"
       # Certificate "Atos TrustedRoot Root CA ECC G2 2020"
       # Certificate "Atos TrustedRoot Root CA RSA G2 2020"
       # Certificate "Atos TrustedRoot Root CA ECC TLS 2021"
       # Certificate "Atos TrustedRoot Root CA RSA TLS 2021"
       # Certificate "TrustAsia Global Root CA G3"
       # Certificate "TrustAsia Global Root CA G4"
       # Certificate "D-Trust SBR Root CA 1 2022"
       # Certificate "D-Trust SBR Root CA 2 2022"
       # Certificate "Telekom Security SMIME ECC Root 2021"
       # Certificate "Telekom Security TLS ECC Root 2020"
       # Certificate "Telekom Security SMIME RSA Root 2023"
       # Certificate "Telekom Security TLS RSA Root 2023"
       # Certificate "FIRMAPROFESIONAL CA ROOT-A WEB"
       # Certificate "TWCA CYBER Root CA"
       # Certificate "TWCA Global Root CA G2"
       # Certificate "SecureSign Root CA12"
       # Certificate "SecureSign Root CA14"
       # Certificate "SecureSign Root CA15"
       # Certificate "D-TRUST BR Root CA 2 2023"
       # Certificate "TrustAsia SMIME ECC Root CA"
       # Certificate "TrustAsia SMIME RSA Root CA"
       # Certificate "TrustAsia TLS ECC Root CA"
       # Certificate "TrustAsia TLS RSA Root CA"
       # Certificate "D-TRUST EV Root CA 2 2023"
       # Certificate "SwissSign RSA SMIME Root CA 2022 - 1"
       # Certificate "SwissSign RSA TLS Root CA 2022 - 1"
       # Certificate "OISTE Client Root ECC G1"
       # Certificate "OISTE Client Root RSA G1"
       # Certificate "OISTE Server Root ECC G1"
       # Certificate " OISTE Server Root RSA G1"
     - The following certificates were removed:
       # Certificate "GlobalSign Root CA - R2"
       # Certificate "Baltimore CyberTrust Root"
       # Certificate "AddTrust Low-Value Services Root"
       # Certificate "AddTrust External Root"
       # Certificate "GeoTrust Global CA"
       # Certificate "QuoVadis Root CA"
       # Certificate "Security Communication Root CA"
       # Certificate "Sonera Class 2 Root CA"
       # Certificate "UTN USERFirst Email Root CA"
       # Certificate "Camerfirma Chambers of Commerce Root"
       # Certificate "Camerfirma Global Chambersign Root"
       # Certificate "Certplus Class 2 Primary CA"
       # Certificate "DST Root CA X3"
       # Certificate "Deutsche Telekom Root CA 2"
       # Certificate "Cybertrust Global Root"
       # Certificate "Staat der Nederlanden Root CA - G2"
       # Certificate "Hongkong Post Root CA 1"
       # Certificate "Chambers of Commerce Root - 2008"
       # Certificate "Global Chambersign Root - 2008"
       # Certificate "Trustis FPS Root CA"
       # Certificate "E-Tugra Certification Authority"
       # Certificate "Staat der Nederlanden EV Root CA"
       # Certificate "TrustCor RootCert CA-1"
       # Certificate "TrustCor RootCert CA-2"
       # Certificate "TrustCor ECA-1"</summary>
    <pushcount>0</pushcount>
    <issued date="2026-02-14 23:42:09 UTC" />
    <updated date="2026-02-14 23:42:09 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1771112524.html" id="CLSA-2026:1771112524" title="CLSA-2026:1771112524" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libnss3" version="2:3.42.1-1+deb10u8+tuxcare.els1">
          <filename>libnss3_3.42.1-1+deb10u8+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">1bbf7b27a59d9322cf3cb00f360a991e5e1fca14</sum>
        </package>
        <package arch="amd64" name="libnss3-dev" version="2:3.42.1-1+deb10u8+tuxcare.els1">
          <filename>libnss3-dev_3.42.1-1+deb10u8+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">33e84edce8931fb7dde6e54792b1e494a31d2ab1</sum>
        </package>
        <package arch="amd64" name="libnss3-tools" version="2:3.42.1-1+deb10u8+tuxcare.els1">
          <filename>libnss3-tools_3.42.1-1+deb10u8+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">6e021ad5009bbba4f4f8d9e0f0e7995c8842ed1b</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="bugfix" version="1">
    <id>CLSA-2026:1771412755</id>
    <title>Update of ca-certificates</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * Update ca-certificates database to 20260210:
     - mozilla\{certdata.h,nssckbi.h}: Update Mozilla certificate
       authority bundle of the version 2.82.
     - The following certificates were updated:
       # Certificate "Entrust Root Certification Authority"
       # Certificate "ePKI Root Certification Authority"
       # Certificate "AffirmTrust Commercial"
       # Certificate "AffirmTrust Networking"
       # Certificate "AffirmTrust Premium"
       # Certificate "AffirmTrust Premium ECC"
       # Certificate "Entrust Root Certification Authority - G2"
       # Certificate "Entrust Root Certification Authority - EC1"
       # Certificate "certSIGN ROOT CA"
       # Certificate "ACCVRAIZ1"
       # Certificate "OISTE WISeKey Global Root GC CA"
     - The following certificates were added:
       # Certificate "Microsoft ECC Root Certificate Authority 2017"
       # Certificate "Microsoft RSA Root Certificate Authority 2017"
       # Certificate "e-Szigno Root CA 2017"
       # Certificate "certSIGN Root CA G2"
       # Certificate "Trustwave Global Certification Authority"
       # Certificate "Trustwave Global ECC P256 Certification Authority"
       # Certificate "Trustwave Global ECC P384 Certification Authority"
       # Certificate "NAVER Global Root Certification Authority"
       # Certificate "AC RAIZ FNMT-RCM SERVIDORES SEGUROS"
       # Certificate "GlobalSign Root R46"
       # Certificate "GlobalSign Root E46"
       # Certificate "GLOBALTRUST 2020"
       # Certificate "ANF Secure Server Root CA"
       # Certificate "Certum EC-384 CA"
       # Certificate "Certum Trusted Root CA"
       # Certificate "TunTrust Root CA"
       # Certificate "HARICA TLS RSA Root CA 2021"
       # Certificate "HARICA TLS ECC Root CA 2021"
       # Certificate "Autoridad de Certificacion Firmaprofesional CIF A62634068"
       # Certificate "vTrus ECC Root CA"
       # Certificate "vTrus Root CA"
       # Certificate "ISRG Root X2"
       # Certificate "HiPKI Root CA - G1"
       # Certificate "GlobalSign ECC Root CA - R4"
       # Certificate "GTS Root R1"
       # Certificate "GTS Root R2"
       # Certificate "GTS Root R3"
       # Certificate "GTS Root R4"
       # Certificate "Telia Root CA v2"
       # Certificate "D-TRUST BR Root CA 1 2020"
       # Certificate "D-TRUST EV Root CA 1 2020"
       # Certificate "DigiCert TLS ECC P384 Root G5"
       # Certificate "DigiCert TLS RSA4096 Root G5"
       # Certificate "Certainly Root R1"
       # Certificate "Certainly Root E1"
       # Certificate "Security Communication ECC RootCA1"
       # Certificate "BJCA Global Root CA1"
       # Certificate "BJCA Global Root CA2"
       # Certificate "Sectigo Public Server Authentication Root E46"
       # Certificate "Sectigo Public Server Authentication Root R46"
       # Certificate "SSL.com TLS RSA Root CA 2022"
       # Certificate "SSL.com TLS ECC Root CA 2022"
       # Certificate "Atos TrustedRoot Root CA ECC TLS 2021"
       # Certificate "Atos TrustedRoot Root CA RSA TLS 2021"
       # Certificate "TrustAsia Global Root CA G3"
       # Certificate "TrustAsia Global Root CA G4"
       # Certificate "Telekom Security TLS ECC Root 2020"
       # Certificate "Telekom Security TLS RSA Root 2023"
       # Certificate "FIRMAPROFESIONAL CA ROOT-A WEB"
       # Certificate "TWCA CYBER Root CA"
       # Certificate "SecureSign Root CA12"
       # Certificate "SecureSign Root CA14"
       # Certificate "SecureSign Root CA15"
       # Certificate "D-TRUST BR Root CA 2 2023"
       # Certificate "TrustAsia TLS ECC Root CA"
       # Certificate "TrustAsia TLS RSA Root CA"
       # Certificate "D-TRUST EV Root CA 2 2023"
       # Certificate "SwissSign RSA TLS Root CA 2022 - 1"
       # Certificate "OISTE Server Root ECC G1"
       # Certificate " OISTE Server Root RSA G1"
     - The following certificates were removed:
       # Certificate "GlobalSign Root CA - R2"
       # Certificate "Baltimore CyberTrust Root"
       # Certificate "AddTrust Low-Value Services Root"
       # Certificate "AddTrust External Root"
       # Certificate "GeoTrust Global CA"
       # Certificate "QuoVadis Root CA"
       # Certificate "Security Communication Root CA"
       # Certificate "Sonera Class 2 Root CA"
       # Certificate "Camerfirma Chambers of Commerce Root"
       # Certificate "Camerfirma Global Chambersign Root"
       # Certificate "DST Root CA X3"
       # Certificate "Cybertrust Global Root"
       # Certificate "Staat der Nederlanden Root CA - G2"
       # Certificate "Hongkong Post Root CA 1"
       # Certificate "Chambers of Commerce Root - 2008"
       # Certificate "Global Chambersign Root - 2008"
       # Certificate "Trustis FPS Root CA"
       # Certificate "E-Tugra Certification Authority"
       # Certificate "Staat der Nederlanden EV Root CA"
       # Certificate "TrustCor RootCert CA-1"
       # Certificate "TrustCor RootCert CA-2"
       # Certificate "TrustCor ECA-1"</description>
    <severity>None</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * Update ca-certificates database to 20260210:
     - mozilla\{certdata.h,nssckbi.h}: Update Mozilla certificate
       authority bundle of the version 2.82.
     - The following certificates were updated:
       # Certificate "Entrust Root Certification Authority"
       # Certificate "ePKI Root Certification Authority"
       # Certificate "AffirmTrust Commercial"
       # Certificate "AffirmTrust Networking"
       # Certificate "AffirmTrust Premium"
       # Certificate "AffirmTrust Premium ECC"
       # Certificate "Entrust Root Certification Authority - G2"
       # Certificate "Entrust Root Certification Authority - EC1"
       # Certificate "certSIGN ROOT CA"
       # Certificate "ACCVRAIZ1"
       # Certificate "OISTE WISeKey Global Root GC CA"
     - The following certificates were added:
       # Certificate "Microsoft ECC Root Certificate Authority 2017"
       # Certificate "Microsoft RSA Root Certificate Authority 2017"
       # Certificate "e-Szigno Root CA 2017"
       # Certificate "certSIGN Root CA G2"
       # Certificate "Trustwave Global Certification Authority"
       # Certificate "Trustwave Global ECC P256 Certification Authority"
       # Certificate "Trustwave Global ECC P384 Certification Authority"
       # Certificate "NAVER Global Root Certification Authority"
       # Certificate "AC RAIZ FNMT-RCM SERVIDORES SEGUROS"
       # Certificate "GlobalSign Root R46"
       # Certificate "GlobalSign Root E46"
       # Certificate "GLOBALTRUST 2020"
       # Certificate "ANF Secure Server Root CA"
       # Certificate "Certum EC-384 CA"
       # Certificate "Certum Trusted Root CA"
       # Certificate "TunTrust Root CA"
       # Certificate "HARICA TLS RSA Root CA 2021"
       # Certificate "HARICA TLS ECC Root CA 2021"
       # Certificate "Autoridad de Certificacion Firmaprofesional CIF A62634068"
       # Certificate "vTrus ECC Root CA"
       # Certificate "vTrus Root CA"
       # Certificate "ISRG Root X2"
       # Certificate "HiPKI Root CA - G1"
       # Certificate "GlobalSign ECC Root CA - R4"
       # Certificate "GTS Root R1"
       # Certificate "GTS Root R2"
       # Certificate "GTS Root R3"
       # Certificate "GTS Root R4"
       # Certificate "Telia Root CA v2"
       # Certificate "D-TRUST BR Root CA 1 2020"
       # Certificate "D-TRUST EV Root CA 1 2020"
       # Certificate "DigiCert TLS ECC P384 Root G5"
       # Certificate "DigiCert TLS RSA4096 Root G5"
       # Certificate "Certainly Root R1"
       # Certificate "Certainly Root E1"
       # Certificate "Security Communication ECC RootCA1"
       # Certificate "BJCA Global Root CA1"
       # Certificate "BJCA Global Root CA2"
       # Certificate "Sectigo Public Server Authentication Root E46"
       # Certificate "Sectigo Public Server Authentication Root R46"
       # Certificate "SSL.com TLS RSA Root CA 2022"
       # Certificate "SSL.com TLS ECC Root CA 2022"
       # Certificate "Atos TrustedRoot Root CA ECC TLS 2021"
       # Certificate "Atos TrustedRoot Root CA RSA TLS 2021"
       # Certificate "TrustAsia Global Root CA G3"
       # Certificate "TrustAsia Global Root CA G4"
       # Certificate "Telekom Security TLS ECC Root 2020"
       # Certificate "Telekom Security TLS RSA Root 2023"
       # Certificate "FIRMAPROFESIONAL CA ROOT-A WEB"
       # Certificate "TWCA CYBER Root CA"
       # Certificate "SecureSign Root CA12"
       # Certificate "SecureSign Root CA14"
       # Certificate "SecureSign Root CA15"
       # Certificate "D-TRUST BR Root CA 2 2023"
       # Certificate "TrustAsia TLS ECC Root CA"
       # Certificate "TrustAsia TLS RSA Root CA"
       # Certificate "D-TRUST EV Root CA 2 2023"
       # Certificate "SwissSign RSA TLS Root CA 2022 - 1"
       # Certificate "OISTE Server Root ECC G1"
       # Certificate " OISTE Server Root RSA G1"
     - The following certificates were removed:
       # Certificate "GlobalSign Root CA - R2"
       # Certificate "Baltimore CyberTrust Root"
       # Certificate "AddTrust Low-Value Services Root"
       # Certificate "AddTrust External Root"
       # Certificate "GeoTrust Global CA"
       # Certificate "QuoVadis Root CA"
       # Certificate "Security Communication Root CA"
       # Certificate "Sonera Class 2 Root CA"
       # Certificate "Camerfirma Chambers of Commerce Root"
       # Certificate "Camerfirma Global Chambersign Root"
       # Certificate "DST Root CA X3"
       # Certificate "Cybertrust Global Root"
       # Certificate "Staat der Nederlanden Root CA - G2"
       # Certificate "Hongkong Post Root CA 1"
       # Certificate "Chambers of Commerce Root - 2008"
       # Certificate "Global Chambersign Root - 2008"
       # Certificate "Trustis FPS Root CA"
       # Certificate "E-Tugra Certification Authority"
       # Certificate "Staat der Nederlanden EV Root CA"
       # Certificate "TrustCor RootCert CA-1"
       # Certificate "TrustCor RootCert CA-2"
       # Certificate "TrustCor ECA-1"</summary>
    <pushcount>0</pushcount>
    <issued date="2026-02-18 11:06:01 UTC" />
    <updated date="2026-02-18 11:06:01 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1771412755.html" id="CLSA-2026:1771412755" title="CLSA-2026:1771412755" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="all" name="ca-certificates" version="20260210~deb10u2+tuxcare.els1">
          <filename>ca-certificates_20260210~deb10u2+tuxcare.els1_all.deb</filename>
          <sum type="sha">1f432000007d52bfc9f59343cfbea4ff6972e9de</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="bugfix" version="1">
    <id>CLSA-2026:1773782865</id>
    <title>Update of amd64-microcode</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * New microcode update packages from upstream up to 2026-02-21:
     - Addition AMD CPU microcode for processor family 0x19:
       cpuid:0x00A00F10(ver:0x0A00107A), cpuid:0x00A00F11(ver:0x0A0011D5),
       cpuid:0x00A00F11(ver:0x0A0011DE), cpuid:0x00A00F12(ver:0x0A001238),
       cpuid:0x00A00F12(ver:0x0A001247), cpuid:0x00A00F82(ver:0x0A00820D),
       cpuid:0x00A10F11(ver:0x0A101148), cpuid:0x00A10F11(ver:0x0A101158),
       cpuid:0x00A10F12(ver:0x0A101248), cpuid:0x00A10F12(ver:0x0A101253),
       cpuid:0x00A10F81(ver:0x0A108109), cpuid:0x00A20F10(ver:0x0A20102E),
       cpuid:0x00A20F12(ver:0x0A201211), cpuid:0x00A40F41(ver:0x0A404108),
       cpuid:0x00A50F00(ver:0x0A500012), cpuid:0x00A60F12(ver:0x0A60120A),
       cpuid:0x00A70F41(ver:0x0A704108), cpuid:0x00A70F52(ver:0x0A705208),
       cpuid:0x00A70F80(ver:0x0A708008), cpuid:0x00A70FC0(ver:0x0A70C008),
       cpuid:0x00AA0F01(ver:0x0AA00116), cpuid:0x00AA0F02(ver:0x0AA00215),
       cpuid:0x00AA0F02(ver:0x0AA0021C);
     - Addition AMD CPU microcode for processor family 0x1a:
       cpuid:0x00B00F21(ver:0x0B002161), cpuid:0x00B00F81(ver:0x0B008121),
       cpuid:0x00B10F10(ver:0x0B101058), cpuid:0x00B20F40(ver:0x0B204037),
       cpuid:0x00B40F40(ver:0x0B404035), cpuid:0x00B40F41(ver:0x0B404108),
       cpuid:0x00B60F00(ver:0x0B600037), cpuid:0x00B60F80(ver:0x0B608038),
       cpuid:0x00B70F00(ver:0x0B700037);
     - Addition AMD CPU microcode for processor family 0x17:
       cpuid:0x00870F10(ver:0x08701034), cpuid:0x00830F10(ver:0x0830107C),
       cpuid:0x00860F01(ver:0x0860010D), cpuid:0x008A0F00(ver:0x08A0000A),
       cpuid:0x00860F81(ver:0x08608108);
     - Update AMD CPU microcode for processor family 0x17:
       cpuid:0x00800F12(ver:0x0800126F), cpuid:0x00800F82(ver:0x0800820D);</description>
    <severity>None</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * New microcode update packages from upstream up to 2026-02-21:
     - Addition AMD CPU microcode for processor family 0x19:
       cpuid:0x00A00F10(ver:0x0A00107A), cpuid:0x00A00F11(ver:0x0A0011D5),
       cpuid:0x00A00F11(ver:0x0A0011DE), cpuid:0x00A00F12(ver:0x0A001238),
       cpuid:0x00A00F12(ver:0x0A001247), cpuid:0x00A00F82(ver:0x0A00820D),
       cpuid:0x00A10F11(ver:0x0A101148), cpuid:0x00A10F11(ver:0x0A101158),
       cpuid:0x00A10F12(ver:0x0A101248), cpuid:0x00A10F12(ver:0x0A101253),
       cpuid:0x00A10F81(ver:0x0A108109), cpuid:0x00A20F10(ver:0x0A20102E),
       cpuid:0x00A20F12(ver:0x0A201211), cpuid:0x00A40F41(ver:0x0A404108),
       cpuid:0x00A50F00(ver:0x0A500012), cpuid:0x00A60F12(ver:0x0A60120A),
       cpuid:0x00A70F41(ver:0x0A704108), cpuid:0x00A70F52(ver:0x0A705208),
       cpuid:0x00A70F80(ver:0x0A708008), cpuid:0x00A70FC0(ver:0x0A70C008),
       cpuid:0x00AA0F01(ver:0x0AA00116), cpuid:0x00AA0F02(ver:0x0AA00215),
       cpuid:0x00AA0F02(ver:0x0AA0021C);
     - Addition AMD CPU microcode for processor family 0x1a:
       cpuid:0x00B00F21(ver:0x0B002161), cpuid:0x00B00F81(ver:0x0B008121),
       cpuid:0x00B10F10(ver:0x0B101058), cpuid:0x00B20F40(ver:0x0B204037),
       cpuid:0x00B40F40(ver:0x0B404035), cpuid:0x00B40F41(ver:0x0B404108),
       cpuid:0x00B60F00(ver:0x0B600037), cpuid:0x00B60F80(ver:0x0B608038),
       cpuid:0x00B70F00(ver:0x0B700037);
     - Addition AMD CPU microcode for processor family 0x17:
       cpuid:0x00870F10(ver:0x08701034), cpuid:0x00830F10(ver:0x0830107C),
       cpuid:0x00860F01(ver:0x0860010D), cpuid:0x008A0F00(ver:0x08A0000A),
       cpuid:0x00860F81(ver:0x08608108);
     - Update AMD CPU microcode for processor family 0x17:
       cpuid:0x00800F12(ver:0x0800126F), cpuid:0x00800F82(ver:0x0800820D);</summary>
    <pushcount>0</pushcount>
    <issued date="2026-03-17 21:52:34 UTC" />
    <updated date="2026-03-17 21:52:34 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1773782865.html" id="CLSA-2026:1773782865" title="CLSA-2026:1773782865" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="amd64-microcode" version="3.20260221.1+tuxcare.els1">
          <filename>amd64-microcode_3.20260221.1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">deafbbd3e02de59d90cf3822719eed0ebb850f52</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="bugfix" version="1">
    <id>CLSA-2026:1773784132</id>
    <title>Update of postgresql-9.6</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * Port to Debian 10 (buster) with renamed libraries to avoid conflicts
     with system PostgreSQL packages.
   * Rename library packages to allow coexistence with other PostgreSQL versions:
     - libpq5 -&gt; libpq5-9.6 (library: libpq-9.6.so.5)
     - libpq-dev -&gt; libpq-dev-9.6
     - libecpg6 -&gt; libecpg6-9.6 (library: libecpg-9.6.so.6)
     - libecpg-dev -&gt; libecpg-dev-9.6
     - libecpg-compat3 -&gt; libecpg-compat3-9.6 (library: libecpg_compat-9.6.so.3)
     - libpgtypes3 -&gt; libpgtypes3-9.6 (library: libpgtypes-9.6.so.3)
   * Add patch rename-libraries-to-avoid-conflicts.patch to change library
     SONAMEs so they don't conflict with system libraries.
   * Library packages can be installed alongside Debian 10's PostgreSQL 11
     libraries.
   * Add conflicts with postgresql-11 and postgresql-client-11 to prevent
     simultaneous installation of server/client with Debian 10's default
     PostgreSQL (libraries can still coexist).</description>
    <severity>None</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * Port to Debian 10 (buster) with renamed libraries to avoid conflicts
     with system PostgreSQL packages.
   * Rename library packages to allow coexistence with other PostgreSQL versions:
     - libpq5 -&gt; libpq5-9.6 (library: libpq-9.6.so.5)
     - libpq-dev -&gt; libpq-dev-9.6
     - libecpg6 -&gt; libecpg6-9.6 (library: libecpg-9.6.so.6)
     - libecpg-dev -&gt; libecpg-dev-9.6
     - libecpg-compat3 -&gt; libecpg-compat3-9.6 (library: libecpg_compat-9.6.so.3)
     - libpgtypes3 -&gt; libpgtypes3-9.6 (library: libpgtypes-9.6.so.3)
   * Add patch rename-libraries-to-avoid-conflicts.patch to change library
     SONAMEs so they don't conflict with system libraries.
   * Library packages can be installed alongside Debian 10's PostgreSQL 11
     libraries.
   * Add conflicts with postgresql-11 and postgresql-client-11 to prevent
     simultaneous installation of server/client with Debian 10's default
     PostgreSQL (libraries can still coexist).</summary>
    <pushcount>0</pushcount>
    <issued date="2026-03-17 21:53:56 UTC" />
    <updated date="2026-03-17 21:53:56 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1773784132.html" id="CLSA-2026:1773784132" title="CLSA-2026:1773784132" type="self" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libecpg-compat3-9.6" version="9.6.24-0+deb10u1+tuxcare.els1">
          <filename>libecpg-compat3-9.6_9.6.24-0+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">4d219bd67f3f6294ddb4a82c041e7dd32e7419c1</sum>
        </package>
        <package arch="amd64" name="libecpg-dev-9.6" version="9.6.24-0+deb10u1+tuxcare.els1">
          <filename>libecpg-dev-9.6_9.6.24-0+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">2ab528cc14c01b96cacdfb31a1d43896897ef6d3</sum>
        </package>
        <package arch="amd64" name="libecpg6-9.6" version="9.6.24-0+deb10u1+tuxcare.els1">
          <filename>libecpg6-9.6_9.6.24-0+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">9e36a0b0083d878c026b1f8d75191cf9f8cb6a16</sum>
        </package>
        <package arch="amd64" name="libpgtypes3-9.6" version="9.6.24-0+deb10u1+tuxcare.els1">
          <filename>libpgtypes3-9.6_9.6.24-0+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">2a427f199a4f55638a517d374c3a3835571a58ac</sum>
        </package>
        <package arch="amd64" name="libpq-dev-9.6" version="9.6.24-0+deb10u1+tuxcare.els1">
          <filename>libpq-dev-9.6_9.6.24-0+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">6647e6cf2ab20d7345394579a70dc4a8aaa362a4</sum>
        </package>
        <package arch="amd64" name="libpq5-9.6" version="9.6.24-0+deb10u1+tuxcare.els1">
          <filename>libpq5-9.6_9.6.24-0+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">42a52c0d676e76dfa5febc3c9ab123c1794b1aae</sum>
        </package>
        <package arch="amd64" name="postgresql-9.6" version="9.6.24-0+deb10u1+tuxcare.els1">
          <filename>postgresql-9.6_9.6.24-0+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">ef27c2f2d9e075497d85c72c79bc7d3061ca3add</sum>
        </package>
        <package arch="amd64" name="postgresql-client-9.6" version="9.6.24-0+deb10u1+tuxcare.els1">
          <filename>postgresql-client-9.6_9.6.24-0+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">383eac39927af8ae98986e3f92591a716ec04fad</sum>
        </package>
        <package arch="amd64" name="postgresql-contrib-9.6" version="9.6.24-0+deb10u1+tuxcare.els1">
          <filename>postgresql-contrib-9.6_9.6.24-0+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">90338052bedd31d901f6ba9f133d41e52e344e6a</sum>
        </package>
        <package arch="all" name="postgresql-doc-9.6" version="9.6.24-0+deb10u1+tuxcare.els1">
          <filename>postgresql-doc-9.6_9.6.24-0+deb10u1+tuxcare.els1_all.deb</filename>
          <sum type="sha">a69bae1a522d76f45f7c531ec906271a03e4df82</sum>
        </package>
        <package arch="amd64" name="postgresql-plperl-9.6" version="9.6.24-0+deb10u1+tuxcare.els1">
          <filename>postgresql-plperl-9.6_9.6.24-0+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">0ae2496b4cef1432038a4db307048cbcde83aec3</sum>
        </package>
        <package arch="amd64" name="postgresql-plpython-9.6" version="9.6.24-0+deb10u1+tuxcare.els1">
          <filename>postgresql-plpython-9.6_9.6.24-0+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">f80176dcb5b42767a1b424924c89315541cdb8ff</sum>
        </package>
        <package arch="amd64" name="postgresql-plpython3-9.6" version="9.6.24-0+deb10u1+tuxcare.els1">
          <filename>postgresql-plpython3-9.6_9.6.24-0+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">88b2c4ed7dde868726789ccdaccd7e2ba13d193b</sum>
        </package>
        <package arch="amd64" name="postgresql-pltcl-9.6" version="9.6.24-0+deb10u1+tuxcare.els1">
          <filename>postgresql-pltcl-9.6_9.6.24-0+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">51f0880b86bbf24888571e700036d3179fbfc28c</sum>
        </package>
        <package arch="amd64" name="postgresql-server-dev-9.6" version="9.6.24-0+deb10u1+tuxcare.els1">
          <filename>postgresql-server-dev-9.6_9.6.24-0+deb10u1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">2be46a541d6a2c4534537354ede1e5491a0ed84a</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1784036814</id>
    <title>Fix CVE(s): CVE-2026-59858</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Arbitrary Ex command execution during C omni-completion: the typeref/typename tag field is interpolated unescaped into the :vimgrep pattern in s:StructMembers() in runtime/autoload/ccomplete.vim, so a crafted tags file can close the search pattern and append an arbitrary Ex command when completing a struct/union member
     - debian/patches/CVE-2026-59858.patch: wrap the type field with escape(typename, '/\') before inserting it into the :vimgrep pattern in s:StructMembers() so it can no longer close the search pattern and start a new Ex command
     - CVE-2026-59858</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Arbitrary Ex command execution during C omni-completion: the typeref/typename tag field is interpolated unescaped into the :vimgrep pattern in s:StructMembers() in runtime/autoload/ccomplete.vim, so a crafted tags file can close the search pattern and append an arbitrary Ex command when completing a struct/union member
     - debian/patches/CVE-2026-59858.patch: wrap the type field with escape(typename, '/\') before inserting it into the :vimgrep pattern in s:StructMembers() so it can no longer close the search pattern and start a new Ex command
     - CVE-2026-59858</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-14 13:47:11 UTC" />
    <updated date="2026-07-14 13:47:11 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1784036814.html" id="CLSA-2026:1784036814" title="CLSA-2026:1784036814" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-59858" id="CVE-2026-59858" title="CVE-2026-59858" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="vim" version="2:8.1.0875-5+deb10u6+tuxcare.els25">
          <filename>vim_8.1.0875-5+deb10u6+tuxcare.els25_amd64.deb</filename>
          <sum type="sha">73a501155536742c333f395e06e7caf2907ac7d6</sum>
        </package>
        <package arch="amd64" name="vim-athena" version="2:8.1.0875-5+deb10u6+tuxcare.els25">
          <filename>vim-athena_8.1.0875-5+deb10u6+tuxcare.els25_amd64.deb</filename>
          <sum type="sha">29cdb0a119de149587f41c501ecbe0ae0868df30</sum>
        </package>
        <package arch="all" name="vim-common" version="2:8.1.0875-5+deb10u6+tuxcare.els25">
          <filename>vim-common_8.1.0875-5+deb10u6+tuxcare.els25_all.deb</filename>
          <sum type="sha">4c2720c6e4407cc55ec133fabed021b4b5e935aa</sum>
        </package>
        <package arch="all" name="vim-doc" version="2:8.1.0875-5+deb10u6+tuxcare.els25">
          <filename>vim-doc_8.1.0875-5+deb10u6+tuxcare.els25_all.deb</filename>
          <sum type="sha">32e44fc7fc9ff8dd202ee6592443ff432ddc0ae1</sum>
        </package>
        <package arch="amd64" name="vim-gtk" version="2:8.1.0875-5+deb10u6+tuxcare.els25">
          <filename>vim-gtk_8.1.0875-5+deb10u6+tuxcare.els25_amd64.deb</filename>
          <sum type="sha">cb899ecfb1a70173c9298e1f0da5289d8e54c179</sum>
        </package>
        <package arch="amd64" name="vim-gtk3" version="2:8.1.0875-5+deb10u6+tuxcare.els25">
          <filename>vim-gtk3_8.1.0875-5+deb10u6+tuxcare.els25_amd64.deb</filename>
          <sum type="sha">32220aa5dd8c860123066b4ea37226dbecf057fa</sum>
        </package>
        <package arch="all" name="vim-gui-common" version="2:8.1.0875-5+deb10u6+tuxcare.els25">
          <filename>vim-gui-common_8.1.0875-5+deb10u6+tuxcare.els25_all.deb</filename>
          <sum type="sha">54a21d7289f28da38246e6bce4ef58b85180e711</sum>
        </package>
        <package arch="amd64" name="vim-nox" version="2:8.1.0875-5+deb10u6+tuxcare.els25">
          <filename>vim-nox_8.1.0875-5+deb10u6+tuxcare.els25_amd64.deb</filename>
          <sum type="sha">cf93fec0422d76f7f6e566d5ef2edc82c2ad3569</sum>
        </package>
        <package arch="all" name="vim-runtime" version="2:8.1.0875-5+deb10u6+tuxcare.els25">
          <filename>vim-runtime_8.1.0875-5+deb10u6+tuxcare.els25_all.deb</filename>
          <sum type="sha">143ee55e309973a94f05f9882150c74c1db5a68d</sum>
        </package>
        <package arch="amd64" name="vim-tiny" version="2:8.1.0875-5+deb10u6+tuxcare.els25">
          <filename>vim-tiny_8.1.0875-5+deb10u6+tuxcare.els25_amd64.deb</filename>
          <sum type="sha">edc347aedb4b078af54f4414ea8b7767e8885a93</sum>
        </package>
        <package arch="amd64" name="xxd" version="2:8.1.0875-5+deb10u6+tuxcare.els25">
          <filename>xxd_8.1.0875-5+deb10u6+tuxcare.els25_amd64.deb</filename>
          <sum type="sha">293edafb58c0a5910036e2d580b39bfb7858f3ef</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1784038140</id>
    <title>Fix CVE(s): CVE-2026-58470, CVE-2026-58471, CVE-2026-58472</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix integer overflow in Content-Range header parsing in src/http.c
     - debian/patches/CVE-2026-58470.patch: fix integer overflow in Content-Range header parsing in src/http.c
     - CVE-2026-58470
   * SECURITY UPDATE: fix heap buffer overflow in filename charset conversion (convert_fname) in src/url.c
     - debian/patches/CVE-2026-58471.patch: fix heap buffer overflow in filename charset conversion (convert_fname) in src/url.c
     - CVE-2026-58471
   * SECURITY UPDATE: fix integer/heap buffer overflow in HTML attribute entity encoding (html_quote_string) in src/convert.c
     - debian/patches/CVE-2026-58472.patch: fix integer/heap buffer overflow in HTML attribute entity encoding (html_quote_string) in src/convert.c
     - CVE-2026-58472</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix integer overflow in Content-Range header parsing in src/http.c
     - debian/patches/CVE-2026-58470.patch: fix integer overflow in Content-Range header parsing in src/http.c
     - CVE-2026-58470
   * SECURITY UPDATE: fix heap buffer overflow in filename charset conversion (convert_fname) in src/url.c
     - debian/patches/CVE-2026-58471.patch: fix heap buffer overflow in filename charset conversion (convert_fname) in src/url.c
     - CVE-2026-58471
   * SECURITY UPDATE: fix integer/heap buffer overflow in HTML attribute entity encoding (html_quote_string) in src/convert.c
     - debian/patches/CVE-2026-58472.patch: fix integer/heap buffer overflow in HTML attribute entity encoding (html_quote_string) in src/convert.c
     - CVE-2026-58472</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-14 14:09:19 UTC" />
    <updated date="2026-07-14 14:09:19 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1784038140.html" id="CLSA-2026:1784038140" title="CLSA-2026:1784038140" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-58470" id="CVE-2026-58470" title="CVE-2026-58470" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-58471" id="CVE-2026-58471" title="CVE-2026-58471" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-58472" id="CVE-2026-58472" title="CVE-2026-58472" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="wget" version="1.20.1-1.1+tuxcare.els2">
          <filename>wget_1.20.1-1.1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">e8d23296670eb8618b75057f15046e0955527921</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1784069784</id>
    <title>Fix CVE(s): CVE-2026-58050</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: potential multiplication overflow in the publickey
     subsystem leading to a heap buffer overflow on 32-bit platforms
     - debian/patches/CVE-2026-58050.patch: cap the publickey attribute
       count at 1024, and zero-initialise the freshly (re)allocated list
       entry before parsing to avoid a free of uninitialised memory on the
       new bounds-check error path, in libssh2_publickey_list_fetch() in
       src/publickey.c
     - CVE-2026-58050</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: potential multiplication overflow in the publickey
     subsystem leading to a heap buffer overflow on 32-bit platforms
     - debian/patches/CVE-2026-58050.patch: cap the publickey attribute
       count at 1024, and zero-initialise the freshly (re)allocated list
       entry before parsing to avoid a free of uninitialised memory on the
       new bounds-check error path, in libssh2_publickey_list_fetch() in
       src/publickey.c
     - CVE-2026-58050</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-14 22:56:36 UTC" />
    <updated date="2026-07-14 22:56:36 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1784069784.html" id="CLSA-2026:1784069784" title="CLSA-2026:1784069784" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-58050" id="CVE-2026-58050" title="CVE-2026-58050" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libssh2-1" version="1.8.0-2.1+deb10u1+tuxcare.els2">
          <filename>libssh2-1_1.8.0-2.1+deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">eff983ded23a0d351f283d9db79cc9b4da60fda0</sum>
        </package>
        <package arch="amd64" name="libssh2-1-dev" version="1.8.0-2.1+deb10u1+tuxcare.els2">
          <filename>libssh2-1-dev_1.8.0-2.1+deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">fff1e55a6017172730f7091021911c463025e01b</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1784126834</id>
    <title>Fix CVE(s): CVE-2026-15308</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser via
     repeated unterminated markup declarations in incremental parsing
     - debian/patches/CVE-2026-15308.patch: accumulate incrementally fed
       data in a list and only join and parse it once enough has piled up,
       avoiding the quadratic rescanning and concatenation of an
       unterminated construct across feed() calls in Lib/HTMLParser.py
     - CVE-2026-15308</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser via
     repeated unterminated markup declarations in incremental parsing
     - debian/patches/CVE-2026-15308.patch: accumulate incrementally fed
       data in a list and only join and parse it once enough has piled up,
       avoiding the quadratic rescanning and concatenation of an
       unterminated construct across feed() calls in Lib/HTMLParser.py
     - CVE-2026-15308</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-15 14:47:28 UTC" />
    <updated date="2026-07-15 14:47:28 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1784126834.html" id="CLSA-2026:1784126834" title="CLSA-2026:1784126834" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-15308" id="CVE-2026-15308" title="CVE-2026-15308" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="all" name="idle-python2.7" version="2.7.16-2+deb10u4+tuxcare.els3">
          <filename>idle-python2.7_2.7.16-2+deb10u4+tuxcare.els3_all.deb</filename>
          <sum type="sha">ae16be592548a06bdf6f42267f2835ff171b2a7f</sum>
        </package>
        <package arch="amd64" name="libpython2.7" version="2.7.16-2+deb10u4+tuxcare.els3">
          <filename>libpython2.7_2.7.16-2+deb10u4+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">7100432728a355377e6347c6c85540d2789fbf29</sum>
        </package>
        <package arch="amd64" name="libpython2.7-dev" version="2.7.16-2+deb10u4+tuxcare.els3">
          <filename>libpython2.7-dev_2.7.16-2+deb10u4+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">91957b4c423a808bd940edaf491377d83ff08e12</sum>
        </package>
        <package arch="amd64" name="libpython2.7-minimal" version="2.7.16-2+deb10u4+tuxcare.els3">
          <filename>libpython2.7-minimal_2.7.16-2+deb10u4+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">4fdef3982dcee7a2fe111ea0bde6c8de3a8ab756</sum>
        </package>
        <package arch="amd64" name="libpython2.7-stdlib" version="2.7.16-2+deb10u4+tuxcare.els3">
          <filename>libpython2.7-stdlib_2.7.16-2+deb10u4+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">4e7f02e03711c7a2d2955aa3194fd23c0a91aeda</sum>
        </package>
        <package arch="all" name="libpython2.7-testsuite" version="2.7.16-2+deb10u4+tuxcare.els3">
          <filename>libpython2.7-testsuite_2.7.16-2+deb10u4+tuxcare.els3_all.deb</filename>
          <sum type="sha">9e5c07106c8b6cbd50a49308c0d7cc0310d916db</sum>
        </package>
        <package arch="amd64" name="python2.7" version="2.7.16-2+deb10u4+tuxcare.els3">
          <filename>python2.7_2.7.16-2+deb10u4+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">ec70e5baabdbc1713f4a1d5247ce9ec2169223e4</sum>
        </package>
        <package arch="amd64" name="python2.7-dev" version="2.7.16-2+deb10u4+tuxcare.els3">
          <filename>python2.7-dev_2.7.16-2+deb10u4+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">0cbb9812df00d46448945e17e07d93ed05a85255</sum>
        </package>
        <package arch="all" name="python2.7-doc" version="2.7.16-2+deb10u4+tuxcare.els3">
          <filename>python2.7-doc_2.7.16-2+deb10u4+tuxcare.els3_all.deb</filename>
          <sum type="sha">7be19e8c191e9c72af113e5b66950faa597f2263</sum>
        </package>
        <package arch="all" name="python2.7-examples" version="2.7.16-2+deb10u4+tuxcare.els3">
          <filename>python2.7-examples_2.7.16-2+deb10u4+tuxcare.els3_all.deb</filename>
          <sum type="sha">a2914b6519ca89982299fb7195fcf8a14c2927a8</sum>
        </package>
        <package arch="amd64" name="python2.7-minimal" version="2.7.16-2+deb10u4+tuxcare.els3">
          <filename>python2.7-minimal_2.7.16-2+deb10u4+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">c5664332af33e4dcda4558206d380224bcae9ee7</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1784188935</id>
    <title>Fix CVE(s): CVE-2026-15308</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser via
     repeated unterminated markup declarations
     - debian/patches/CVE-2026-15308.patch: accumulate incrementally fed
       data in a list and only join and rescan it once a growing threshold
       is reached, so an unterminated construct (tag, comment, PI, doctype,
       CDATA, RAWTEXT element) spread across many feed() calls no longer
       makes both the buffer concatenation and the rescan quadratic in the
       input size (backport of upstream commit bcf98ddbc40e, gh-153030 /
       GH-153031).
     - CVE-2026-15308</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser via
     repeated unterminated markup declarations
     - debian/patches/CVE-2026-15308.patch: accumulate incrementally fed
       data in a list and only join and rescan it once a growing threshold
       is reached, so an unterminated construct (tag, comment, PI, doctype,
       CDATA, RAWTEXT element) spread across many feed() calls no longer
       makes both the buffer concatenation and the rescan quadratic in the
       input size (backport of upstream commit bcf98ddbc40e, gh-153030 /
       GH-153031).
     - CVE-2026-15308</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-16 08:02:39 UTC" />
    <updated date="2026-07-16 08:02:39 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1784188935.html" id="CLSA-2026:1784188935" title="CLSA-2026:1784188935" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-15308" id="CVE-2026-15308" title="CVE-2026-15308" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="all" name="idle-python3.7" version="3.7.3-2+deb10u7+tuxcare.els6">
          <filename>idle-python3.7_3.7.3-2+deb10u7+tuxcare.els6_all.deb</filename>
          <sum type="sha">3fefaa52b391749971db566eb049a3780aab8840</sum>
        </package>
        <package arch="amd64" name="libpython3.7" version="3.7.3-2+deb10u7+tuxcare.els6">
          <filename>libpython3.7_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">a5d5389ea819775cf3a517de1d5825132fee0047</sum>
        </package>
        <package arch="amd64" name="libpython3.7-dev" version="3.7.3-2+deb10u7+tuxcare.els6">
          <filename>libpython3.7-dev_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">0f280c10770bdda83094bb28c6724e4e4e9f4d1e</sum>
        </package>
        <package arch="amd64" name="libpython3.7-minimal" version="3.7.3-2+deb10u7+tuxcare.els6">
          <filename>libpython3.7-minimal_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">9d3fd062c7bd96a42337d48d7ba72eaa4930ccde</sum>
        </package>
        <package arch="amd64" name="libpython3.7-stdlib" version="3.7.3-2+deb10u7+tuxcare.els6">
          <filename>libpython3.7-stdlib_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">e021821fa7b0a08190a713f3c6e29769792e8fec</sum>
        </package>
        <package arch="all" name="libpython3.7-testsuite" version="3.7.3-2+deb10u7+tuxcare.els6">
          <filename>libpython3.7-testsuite_3.7.3-2+deb10u7+tuxcare.els6_all.deb</filename>
          <sum type="sha">804ec50a1e56017c006268e1165f048e2d11dfd1</sum>
        </package>
        <package arch="amd64" name="python3.7" version="3.7.3-2+deb10u7+tuxcare.els6">
          <filename>python3.7_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">71f44bba78caf014b95993cc6828a7e172c32883</sum>
        </package>
        <package arch="amd64" name="python3.7-dev" version="3.7.3-2+deb10u7+tuxcare.els6">
          <filename>python3.7-dev_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">2e513a5079a773e896da5d508ee7f074a277a401</sum>
        </package>
        <package arch="all" name="python3.7-doc" version="3.7.3-2+deb10u7+tuxcare.els6">
          <filename>python3.7-doc_3.7.3-2+deb10u7+tuxcare.els6_all.deb</filename>
          <sum type="sha">53ee504e2eb724bf8a033b5e5aed87cd21ae50f7</sum>
        </package>
        <package arch="all" name="python3.7-examples" version="3.7.3-2+deb10u7+tuxcare.els6">
          <filename>python3.7-examples_3.7.3-2+deb10u7+tuxcare.els6_all.deb</filename>
          <sum type="sha">136a424e2735d967c3ddd9a0157240ae7b4f9f55</sum>
        </package>
        <package arch="amd64" name="python3.7-minimal" version="3.7.3-2+deb10u7+tuxcare.els6">
          <filename>python3.7-minimal_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">a5d7948cb3ce492a532bd6abe2fdbdcfc9a14e70</sum>
        </package>
        <package arch="amd64" name="python3.7-venv" version="3.7.3-2+deb10u7+tuxcare.els6">
          <filename>python3.7-venv_3.7.3-2+deb10u7+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">ac688797e5c6719791f324d23628a14eb22d41c9</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1784203659</id>
    <title>Fix CVE(s): CVE-2026-58014, CVE-2026-58015, CVE-2026-58016</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: One-byte heap under-read in GKeyFile locale string list
     - debian/patches/CVE-2026-58014.patch: guard len &gt; 0 before reading
       value[len - 1] when a key has an empty value in
       g_key_file_get_locale_string_list() in glib/gkeyfile.c
     - CVE-2026-58014
   * SECURITY UPDATE: Path traversal via unvalidated D-Bus cookie context
     - debian/patches/CVE-2026-58015.patch: validate the server-supplied
       cookie_context (reject path-traversal characters) and harden cookie_id
       validation in the DBUS_COOKIE_SHA1 client authentication mechanism in
       gio/gdbusauthmechanismsha1.c
     - CVE-2026-58015</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: One-byte heap under-read in GKeyFile locale string list
     - debian/patches/CVE-2026-58014.patch: guard len &gt; 0 before reading
       value[len - 1] when a key has an empty value in
       g_key_file_get_locale_string_list() in glib/gkeyfile.c
     - CVE-2026-58014
   * SECURITY UPDATE: Path traversal via unvalidated D-Bus cookie context
     - debian/patches/CVE-2026-58015.patch: validate the server-supplied
       cookie_context (reject path-traversal characters) and harden cookie_id
       validation in the DBUS_COOKIE_SHA1 client authentication mechanism in
       gio/gdbusauthmechanismsha1.c
     - CVE-2026-58015</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-16 12:08:07 UTC" />
    <updated date="2026-07-16 12:08:07 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1784203659.html" id="CLSA-2026:1784203659" title="CLSA-2026:1784203659" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-58014" id="CVE-2026-58014" title="CVE-2026-58014" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-58015" id="CVE-2026-58015" title="CVE-2026-58015" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-58016" id="CVE-2026-58016" title="CVE-2026-58016" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libglib2.0-0" version="2.58.3-2+deb10u6+tuxcare.els5">
          <filename>libglib2.0-0_2.58.3-2+deb10u6+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">8051c20d6b17c6d82dcf03a2bb67cef5d7956894</sum>
        </package>
        <package arch="amd64" name="libglib2.0-bin" version="2.58.3-2+deb10u6+tuxcare.els5">
          <filename>libglib2.0-bin_2.58.3-2+deb10u6+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">19a339d7c16baa361e7f444106728794765b06d2</sum>
        </package>
        <package arch="all" name="libglib2.0-data" version="2.58.3-2+deb10u6+tuxcare.els5">
          <filename>libglib2.0-data_2.58.3-2+deb10u6+tuxcare.els5_all.deb</filename>
          <sum type="sha">2eb39ed281ffb620804ac03837c25e5cf58f94fd</sum>
        </package>
        <package arch="amd64" name="libglib2.0-dev" version="2.58.3-2+deb10u6+tuxcare.els5">
          <filename>libglib2.0-dev_2.58.3-2+deb10u6+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">8b1021d3999ea419bc9bbf60fb9be22d679c5380</sum>
        </package>
        <package arch="amd64" name="libglib2.0-dev-bin" version="2.58.3-2+deb10u6+tuxcare.els5">
          <filename>libglib2.0-dev-bin_2.58.3-2+deb10u6+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">d81a3a96cbedca5cdb69fe56efa71d2d1151c828</sum>
        </package>
        <package arch="all" name="libglib2.0-doc" version="2.58.3-2+deb10u6+tuxcare.els5">
          <filename>libglib2.0-doc_2.58.3-2+deb10u6+tuxcare.els5_all.deb</filename>
          <sum type="sha">3d2ba524598ef47ec6c429826eb2bd1b835bf9d8</sum>
        </package>
        <package arch="amd64" name="libglib2.0-tests" version="2.58.3-2+deb10u6+tuxcare.els5">
          <filename>libglib2.0-tests_2.58.3-2+deb10u6+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">3434ce59e5f7938ecea9edaca22745d4d15cdc50</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1784368292</id>
    <title>Fix of 5 CVEs</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: off-by-one out-of-bounds read in morphology kernel validation
     - debian/patches/CVE-2026-56361.patch: reject a User Defined kernel origin
       equal to the kernel width/height in magick/morphology.c
     - CVE-2026-56361
   * SECURITY UPDATE: integer overflow leading to heap out-of-bounds read in the PSD/PSB RLE decoder
     - debian/patches/CVE-2026-56367.patch: guard the image-&gt;rows*psd_info-&gt;channels
       allocation size against integer overflow in ReadPSDMergedImage() in coders/psd.c
     - CVE-2026-56367
   * SECURITY UPDATE: memory leak in coders that write raw pixel data
     - debian/patches/CVE-2026-56368.patch: free quantum_info on the OpenBlob
       failure paths in coders/bgr.c, cmyk.c, gray.c, rgb.c and ycbcr.c
     - CVE-2026-56368
   * SECURITY UPDATE: out-of-bounds access in ConnectedComponentsImage()
     - debian/patches/CVE-2026-56370.patch: validate the CLI connected-components:keep
       / :remove indices before indexing object[]/colormap[] in magick/vision.c
     - CVE-2026-56370
   * SECURITY UPDATE: heap out-of-bounds read/write in the PCD decoder
     - debian/patches/CVE-2026-56378.patch: bound the write pointer against a
       per-plane sentinel in DecodeImage() in coders/pcd.c
     - CVE-2026-56378</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: off-by-one out-of-bounds read in morphology kernel validation
     - debian/patches/CVE-2026-56361.patch: reject a User Defined kernel origin
       equal to the kernel width/height in magick/morphology.c
     - CVE-2026-56361
   * SECURITY UPDATE: integer overflow leading to heap out-of-bounds read in the PSD/PSB RLE decoder
     - debian/patches/CVE-2026-56367.patch: guard the image-&gt;rows*psd_info-&gt;channels
       allocation size against integer overflow in ReadPSDMergedImage() in coders/psd.c
     - CVE-2026-56367
   * SECURITY UPDATE: memory leak in coders that write raw pixel data
     - debian/patches/CVE-2026-56368.patch: free quantum_info on the OpenBlob
       failure paths in coders/bgr.c, cmyk.c, gray.c, rgb.c and ycbcr.c
     - CVE-2026-56368
   * SECURITY UPDATE: out-of-bounds access in ConnectedComponentsImage()
     - debian/patches/CVE-2026-56370.patch: validate the CLI connected-components:keep
       / :remove indices before indexing object[]/colormap[] in magick/vision.c
     - CVE-2026-56370
   * SECURITY UPDATE: heap out-of-bounds read/write in the PCD decoder
     - debian/patches/CVE-2026-56378.patch: bound the write pointer against a
       per-plane sentinel in DecodeImage() in coders/pcd.c
     - CVE-2026-56378</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-18 09:52:09 UTC" />
    <updated date="2026-07-18 09:52:09 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1784368292.html" id="CLSA-2026:1784368292" title="CLSA-2026:1784368292" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-56361" id="CVE-2026-56361" title="CVE-2026-56361" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-56367" id="CVE-2026-56367" title="CVE-2026-56367" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-56368" id="CVE-2026-56368" title="CVE-2026-56368" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-56370" id="CVE-2026-56370" title="CVE-2026-56370" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-56378" id="CVE-2026-56378" title="CVE-2026-56378" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="imagemagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>imagemagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">eab512e710dae78db9f2d7d99ad62d1d988a6d23</sum>
        </package>
        <package arch="all" name="imagemagick-6-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>imagemagick-6-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_all.deb</filename>
          <sum type="sha">d4fa87acac534e29b1155b35899a82042233d59e</sum>
        </package>
        <package arch="all" name="imagemagick-6-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>imagemagick-6-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_all.deb</filename>
          <sum type="sha">96a8c8d712c3da0187bf815a7375702d02166c6d</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>imagemagick-6.q16_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">c2994b7b9c54e29e77499c6ddc6e2be472e1b2a6</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16hdri" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>imagemagick-6.q16hdri_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">ae3cc353148cb2f9f3edec13fa32f126ed087a6a</sum>
        </package>
        <package arch="all" name="imagemagick-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>imagemagick-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_all.deb</filename>
          <sum type="sha">0324b99d23be1b118a060be171c4e8d50dc21396</sum>
        </package>
        <package arch="all" name="imagemagick-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>imagemagick-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_all.deb</filename>
          <sum type="sha">30fe5c1f8f1656ec2c31e787582228fc824183f0</sum>
        </package>
        <package arch="all" name="libimage-magick-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libimage-magick-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_all.deb</filename>
          <sum type="sha">660ca15393629e62e73d32e81b8af2b001a87f6f</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libimage-magick-q16-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">dbfb2cc8e80ac83691e5b12980d3c9ece3d5f78c</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16hdri-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libimage-magick-q16hdri-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">688d02cf0935eef859996bfae28b5c50c8c9e7b5</sum>
        </package>
        <package arch="all" name="libmagick++-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libmagick++-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_all.deb</filename>
          <sum type="sha">9139e9fecda8802e4981ee9bd214af8278b99f84</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libmagick++-6.q16-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">d524a25b793d8e17581cc562e71be4b1801b2a6f</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libmagick++-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">7c1d83e51fd01e8fad3ae6209a72353cc401f1fa</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libmagick++-6.q16hdri-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">66531534e92411d58b853efdb23954251c98014d</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libmagick++-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">91f391a91b1385af1ddb6d019d860a6b43eca164</sum>
        </package>
        <package arch="all" name="libmagick++-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libmagick++-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_all.deb</filename>
          <sum type="sha">6047267bd7f8f7878bfb3854d65e91d8aa001e10</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6-arch-config" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libmagickcore-6-arch-config_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">a476ab9d415278ec2c1545fb4b2a41b6b38eb0cf</sum>
        </package>
        <package arch="all" name="libmagickcore-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libmagickcore-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_all.deb</filename>
          <sum type="sha">3af91a195f8cc1221f0c9317316c7dd00ef1d920</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libmagickcore-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">026dc70a449cdc624908407c9775c29defb2e8ff</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libmagickcore-6.q16-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">1473748b38bdd2303fb777e4aa2380e4aad333a4</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libmagickcore-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">7deee922fbfd48836dfab96133a17277e64a7a1a</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libmagickcore-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">c9300b5caf2973330446026f3fb54b9c6dd8e758</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libmagickcore-6.q16hdri-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">a8f3330107ade301104abd52464236b5e7e440a4</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libmagickcore-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">e184f4f6ab8f5e2ea74d4581bb690edf237693f0</sum>
        </package>
        <package arch="all" name="libmagickcore-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libmagickcore-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_all.deb</filename>
          <sum type="sha">4bbcb0d832a3e24e5ae53cb42772cf5f1e63be4b</sum>
        </package>
        <package arch="all" name="libmagickwand-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libmagickwand-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_all.deb</filename>
          <sum type="sha">7c5f59ea219a82795ddc0841317f2cae6c04e81e</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libmagickwand-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">1245324998daa6d6d0fba7c1b5a5c02d87075034</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libmagickwand-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">d5d0d0b88465a675772d73d6fef579395ab2f095</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libmagickwand-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">e37b702274cf8933584f15b66bcc76beda6a1f15</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libmagickwand-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">b2e939637033769d1f0655832384f6dae2b0788d</sum>
        </package>
        <package arch="all" name="libmagickwand-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>libmagickwand-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_all.deb</filename>
          <sum type="sha">42a837db66c060ba57c53ec4ebec4b146a233ee6</sum>
        </package>
        <package arch="all" name="perlmagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13">
          <filename>perlmagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els13_all.deb</filename>
          <sum type="sha">e2d101ef5b79f3c00d0448b459428f7ccd82ed59</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1784710881</id>
    <title>Fix CVE(s): CVE-2026-47729, CVE-2026-50012</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: out-of-bounds read in the FTP gateway directory-listing
     parser when a TypeA/TypeB listing entry date is not followed by a filename
     - debian/patches/CVE-2026-47729.patch: restrict parsing to the input buffer
       in ftpListParseParts() by checking for a NUL byte before strchr(w_space)
       in src/clients/FtpGateway.cc
     - CVE-2026-47729
   * SECURITY UPDATE: heap-based buffer overflow in cache digest reply handling
     when a peer reply's on-the-wire size exceeds the declared mask_size
     - debian/patches/CVE-2026-50012.patch: bound-check mask_offset + size
       against mask_size before memcpy() in peerDigestSwapInMask() and abort the
       fetch on overflow in src/peer_digest.cc
     - CVE-2026-50012</description>
    <severity>Moderate</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: out-of-bounds read in the FTP gateway directory-listing
     parser when a TypeA/TypeB listing entry date is not followed by a filename
     - debian/patches/CVE-2026-47729.patch: restrict parsing to the input buffer
       in ftpListParseParts() by checking for a NUL byte before strchr(w_space)
       in src/clients/FtpGateway.cc
     - CVE-2026-47729
   * SECURITY UPDATE: heap-based buffer overflow in cache digest reply handling
     when a peer reply's on-the-wire size exceeds the declared mask_size
     - debian/patches/CVE-2026-50012.patch: bound-check mask_offset + size
       against mask_size before memcpy() in peerDigestSwapInMask() and abort the
       fetch on overflow in src/peer_digest.cc
     - CVE-2026-50012</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-22 09:01:49 UTC" />
    <updated date="2026-07-22 09:01:49 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1784710881.html" id="CLSA-2026:1784710881" title="CLSA-2026:1784710881" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-47729" id="CVE-2026-47729" title="CVE-2026-47729" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-50012" id="CVE-2026-50012" title="CVE-2026-50012" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="squid" version="4.6-1+deb10u10+tuxcare.els5">
          <filename>squid_4.6-1+deb10u10+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">4423a492ec1eb395a62fb21fd3cb137b34c8af3b</sum>
        </package>
        <package arch="amd64" name="squid-cgi" version="4.6-1+deb10u10+tuxcare.els5">
          <filename>squid-cgi_4.6-1+deb10u10+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">099653c1d9ec386db0217f10d16c30d4be98a986</sum>
        </package>
        <package arch="all" name="squid-common" version="4.6-1+deb10u10+tuxcare.els5">
          <filename>squid-common_4.6-1+deb10u10+tuxcare.els5_all.deb</filename>
          <sum type="sha">7d96106b16a8660a628688dd6f000fb458f8cfc0</sum>
        </package>
        <package arch="amd64" name="squid-purge" version="4.6-1+deb10u10+tuxcare.els5">
          <filename>squid-purge_4.6-1+deb10u10+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">8a13807ae59aebce90cc62694245aa1214acf666</sum>
        </package>
        <package arch="all" name="squid3" version="4.6-1+deb10u10+tuxcare.els5">
          <filename>squid3_4.6-1+deb10u10+tuxcare.els5_all.deb</filename>
          <sum type="sha">180bbe62532dc5b35cbfcfe5ca21b602a6a84cf3</sum>
        </package>
        <package arch="amd64" name="squidclient" version="4.6-1+deb10u10+tuxcare.els5">
          <filename>squidclient_4.6-1+deb10u10+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">e23148d7c07c173b3d37f1ea28ce4d27ab5b1afe</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1784736392</id>
    <title>Fix CVE(s): CVE-2026-60000</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: pre-authentication denial of service via GSSAPI
     - debian/patches/CVE-2026-60000.patch: discard GSSAPI error tokens in
       auth2-gss.c instead of feeding them into the GSSAPI stack, and count
       the failed attempt so GSSAPI auth is subject to MaxAuthTries.
     - CVE-2026-60000</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: pre-authentication denial of service via GSSAPI
     - debian/patches/CVE-2026-60000.patch: discard GSSAPI error tokens in
       auth2-gss.c instead of feeding them into the GSSAPI stack, and count
       the failed attempt so GSSAPI auth is subject to MaxAuthTries.
     - CVE-2026-60000</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-22 16:06:59 UTC" />
    <updated date="2026-07-22 16:06:59 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1784736392.html" id="CLSA-2026:1784736392" title="CLSA-2026:1784736392" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-60000" id="CVE-2026-60000" title="CVE-2026-60000" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="openssh-client" version="1:7.9p1-10+deb10u4+tuxcare.els6">
          <filename>openssh-client_7.9p1-10+deb10u4+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">3535ac92f49284eefebbd58e7d9328581f8c4247</sum>
        </package>
        <package arch="amd64" name="openssh-server" version="1:7.9p1-10+deb10u4+tuxcare.els6">
          <filename>openssh-server_7.9p1-10+deb10u4+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">23ac5f7838a7fa2814e9881ef5ea4af6c665a211</sum>
        </package>
        <package arch="amd64" name="openssh-sftp-server" version="1:7.9p1-10+deb10u4+tuxcare.els6">
          <filename>openssh-sftp-server_7.9p1-10+deb10u4+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">f40ea5b78d355de408c47ffb66f9ca0da0f737d9</sum>
        </package>
        <package arch="amd64" name="openssh-tests" version="1:7.9p1-10+deb10u4+tuxcare.els6">
          <filename>openssh-tests_7.9p1-10+deb10u4+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">160e74019d57dbcaf81a177ed36a9a74ccc7f3ea</sum>
        </package>
        <package arch="all" name="ssh" version="1:7.9p1-10+deb10u4+tuxcare.els6">
          <filename>ssh_7.9p1-10+deb10u4+tuxcare.els6_all.deb</filename>
          <sum type="sha">3d6f541fcd03449d209cb8a0cb5f3078540452a9</sum>
        </package>
        <package arch="amd64" name="ssh-askpass-gnome" version="1:7.9p1-10+deb10u4+tuxcare.els6">
          <filename>ssh-askpass-gnome_7.9p1-10+deb10u4+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">56e71ef64be00e6c2eca0537cdca33736bb30980</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1784803023</id>
    <title>Fix CVE(s): CVE-2026-61863, CVE-2026-61870</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: memory leak in the VIFF encoder on colormap allocation failure
     - debian/patches/CVE-2026-61870.patch: relinquish pixel_info before throwing
       when the colormap allocation fails in WriteVIFFImage() in coders/viff.c
     - CVE-2026-61870
   * SECURITY UPDATE: memory leak in the TIFF encoder when a temporary file cannot be created
     - debian/patches/CVE-2026-61863.patch: destroy huffman_image on the temporary-file
       failure path in WriteGROUP4Image() in coders/tiff.c
     - CVE-2026-61863</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: memory leak in the VIFF encoder on colormap allocation failure
     - debian/patches/CVE-2026-61870.patch: relinquish pixel_info before throwing
       when the colormap allocation fails in WriteVIFFImage() in coders/viff.c
     - CVE-2026-61870
   * SECURITY UPDATE: memory leak in the TIFF encoder when a temporary file cannot be created
     - debian/patches/CVE-2026-61863.patch: destroy huffman_image on the temporary-file
       failure path in WriteGROUP4Image() in coders/tiff.c
     - CVE-2026-61863</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-23 10:37:33 UTC" />
    <updated date="2026-07-23 10:37:33 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1784803023.html" id="CLSA-2026:1784803023" title="CLSA-2026:1784803023" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-61863" id="CVE-2026-61863" title="CVE-2026-61863" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-61870" id="CVE-2026-61870" title="CVE-2026-61870" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="imagemagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>imagemagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">66bb713b164410ffceff96ab7078d9fd859aca8c</sum>
        </package>
        <package arch="all" name="imagemagick-6-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>imagemagick-6-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_all.deb</filename>
          <sum type="sha">7115135b89c7abcfe1e7f8ba00e885188a3b87e6</sum>
        </package>
        <package arch="all" name="imagemagick-6-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>imagemagick-6-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_all.deb</filename>
          <sum type="sha">9fcb22f43e7f878abcceef8ca05b045c8214f174</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>imagemagick-6.q16_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">2b9757d38cf44ee04a4adc2be46eeb48eb20b344</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16hdri" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>imagemagick-6.q16hdri_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">f32f4fa025609778c1257a0f2498129980913130</sum>
        </package>
        <package arch="all" name="imagemagick-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>imagemagick-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_all.deb</filename>
          <sum type="sha">3efcaede79eb138d4d18d609181722363502da4e</sum>
        </package>
        <package arch="all" name="imagemagick-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>imagemagick-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_all.deb</filename>
          <sum type="sha">eb9ee01d227245597dfc09cfa40939716fa87706</sum>
        </package>
        <package arch="all" name="libimage-magick-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libimage-magick-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_all.deb</filename>
          <sum type="sha">9186cd32fac05a21e7740781f7901705d20b0037</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libimage-magick-q16-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">d7c6a3e0affb8d5200181c2682a4a7be3de67666</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16hdri-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libimage-magick-q16hdri-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">3dacd346ef332b0193215b6a6c749d79d5975718</sum>
        </package>
        <package arch="all" name="libmagick++-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libmagick++-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_all.deb</filename>
          <sum type="sha">8a959d575edaf17ba25455f932699aa39e5fba02</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libmagick++-6.q16-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">2a734692afd1cb71467cf3a6476906cbf23d8359</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libmagick++-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">f9c940633830976e5667578a897ea46ac81d040f</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libmagick++-6.q16hdri-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">7b754c9b270665ae5b2d6d676aef6ffe0a122056</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libmagick++-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">14fbb359278819b039c301ea7dbd58e1789de8d5</sum>
        </package>
        <package arch="all" name="libmagick++-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libmagick++-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_all.deb</filename>
          <sum type="sha">a8e2808c6efa3cc2aab258e10da663f7838178d9</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6-arch-config" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libmagickcore-6-arch-config_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">0e674ab11bf8593aae1b2f33582697e39c1b1e1a</sum>
        </package>
        <package arch="all" name="libmagickcore-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libmagickcore-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_all.deb</filename>
          <sum type="sha">9184a81279379f9fe42506c0075efed949c8eb66</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libmagickcore-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">cdb25198a5d242d4c8a5590d1610c4b1503f1c3d</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libmagickcore-6.q16-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">194f39d253b89c25592bb8a08a4d4af129e9ac8a</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libmagickcore-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">05a113b17c5f4a736696f5bd8c85c63006f969a7</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libmagickcore-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">846b2ee2602c9122eaf339acff24ca67a3643341</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libmagickcore-6.q16hdri-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">a173cdda161a8af13eb53cacd23f6817e712b82f</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libmagickcore-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">714348996a157df15bbc75b55e8a63d7ea959162</sum>
        </package>
        <package arch="all" name="libmagickcore-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libmagickcore-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_all.deb</filename>
          <sum type="sha">244ca67e9a087989c2a78a31816b09095051d0b6</sum>
        </package>
        <package arch="all" name="libmagickwand-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libmagickwand-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_all.deb</filename>
          <sum type="sha">3ed0a1e79ee081b6a358df527f5540395796a4c5</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libmagickwand-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">1b66cc3d5f4535b1cb16811ce28e8bce2f59c9f8</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libmagickwand-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">eeffae53f4ab8738593a30c3cfba66a2fca9b15b</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libmagickwand-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">778bbc1985c0560811a27d20bc738399f9c7fc56</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libmagickwand-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_amd64.deb</filename>
          <sum type="sha">6d66b887c7ba7b93cec163caec3e8bf71c80347d</sum>
        </package>
        <package arch="all" name="libmagickwand-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>libmagickwand-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_all.deb</filename>
          <sum type="sha">c80c132794b5a107f19275ad4ac0f7106c71ed62</sum>
        </package>
        <package arch="all" name="perlmagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14">
          <filename>perlmagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els14_all.deb</filename>
          <sum type="sha">e26ce548ad080f672789d4ffcacf4a25701a0b52</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1785309072</id>
    <title>Fix CVE(s): CVE-2026-55957</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: JNDIRealm bypass when configured with GSSAPI
     authentication - HttpServletRequest.login(username, password) calls
     validated credentials via the GSSAPI SASL mechanism instead of a
     plain LDAP bind, silently accepting arbitrary passwords
     - debian/patches/CVE-2026-55957.patch: preserve DirContext
       environment, drop the GSSAPI SECURITY_AUTHENTICATION setting
       before the user-credential bind, and restore it in a finally
       block via the existing restoreEnvironmentParameter() helper
     - CVE-2026-55957</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: JNDIRealm bypass when configured with GSSAPI
     authentication - HttpServletRequest.login(username, password) calls
     validated credentials via the GSSAPI SASL mechanism instead of a
     plain LDAP bind, silently accepting arbitrary passwords
     - debian/patches/CVE-2026-55957.patch: preserve DirContext
       environment, drop the GSSAPI SECURITY_AUTHENTICATION setting
       before the user-credential bind, and restore it in a finally
       block via the existing restoreEnvironmentParameter() helper
     - CVE-2026-55957</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-29 07:11:23 UTC" />
    <updated date="2026-07-29 07:11:23 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1785309072.html" id="CLSA-2026:1785309072" title="CLSA-2026:1785309072" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-55957" id="CVE-2026-55957" title="CVE-2026-55957" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="all" name="libtomcat9-embed-java" version="9.0.31-1~deb10u12+tuxcare.els6">
          <filename>libtomcat9-embed-java_9.0.31-1~deb10u12+tuxcare.els6_all.deb</filename>
          <sum type="sha">19870540dcb7017a6134157c1d62b98a78e36831</sum>
        </package>
        <package arch="all" name="libtomcat9-java" version="9.0.31-1~deb10u12+tuxcare.els6">
          <filename>libtomcat9-java_9.0.31-1~deb10u12+tuxcare.els6_all.deb</filename>
          <sum type="sha">9f39ab437711be2698edc461c382d5ddb6cf7895</sum>
        </package>
        <package arch="all" name="tomcat9" version="9.0.31-1~deb10u12+tuxcare.els6">
          <filename>tomcat9_9.0.31-1~deb10u12+tuxcare.els6_all.deb</filename>
          <sum type="sha">02478f7eac2362c7014545a8226e432c5d150ba5</sum>
        </package>
        <package arch="all" name="tomcat9-admin" version="9.0.31-1~deb10u12+tuxcare.els6">
          <filename>tomcat9-admin_9.0.31-1~deb10u12+tuxcare.els6_all.deb</filename>
          <sum type="sha">e2531a9cd240cf6cc0c3b2eff412dd6c4e7a59e5</sum>
        </package>
        <package arch="all" name="tomcat9-common" version="9.0.31-1~deb10u12+tuxcare.els6">
          <filename>tomcat9-common_9.0.31-1~deb10u12+tuxcare.els6_all.deb</filename>
          <sum type="sha">e7adef00c248c77001451604b6a71a764b9b21e6</sum>
        </package>
        <package arch="all" name="tomcat9-docs" version="9.0.31-1~deb10u12+tuxcare.els6">
          <filename>tomcat9-docs_9.0.31-1~deb10u12+tuxcare.els6_all.deb</filename>
          <sum type="sha">225170ae8bd07716a3a3779008df06ba3eabe9d0</sum>
        </package>
        <package arch="all" name="tomcat9-examples" version="9.0.31-1~deb10u12+tuxcare.els6">
          <filename>tomcat9-examples_9.0.31-1~deb10u12+tuxcare.els6_all.deb</filename>
          <sum type="sha">3538efcb6b33444cfea32eda32cfbce6841c51ab</sum>
        </package>
        <package arch="all" name="tomcat9-user" version="9.0.31-1~deb10u12+tuxcare.els6">
          <filename>tomcat9-user_9.0.31-1~deb10u12+tuxcare.els6_all.deb</filename>
          <sum type="sha">d07acd5afa5fc7d5a0f4d15ea78dd5a660dc1068</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1785317563</id>
    <title>Fix CVE(s): CVE-2026-59999</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: DisableForwarding did not override PermitTunnel
     - debian/patches/CVE-2026-59999.patch: reject tunnel-device forwarding
       requests in server_request_tun() (serverloop.c) when DisableForwarding
       is set, so it takes precedence over PermitTunnel.
     - CVE-2026-59999</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: DisableForwarding did not override PermitTunnel
     - debian/patches/CVE-2026-59999.patch: reject tunnel-device forwarding
       requests in server_request_tun() (serverloop.c) when DisableForwarding
       is set, so it takes precedence over PermitTunnel.
     - CVE-2026-59999</summary>
    <pushcount>0</pushcount>
    <issued date="2026-07-29 09:32:54 UTC" />
    <updated date="2026-07-29 09:32:54 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1785317563.html" id="CLSA-2026:1785317563" title="CLSA-2026:1785317563" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-59999" id="CVE-2026-59999" title="CVE-2026-59999" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="openssh-client" version="1:7.9p1-10+deb10u4+tuxcare.els5">
          <filename>openssh-client_7.9p1-10+deb10u4+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">ca58b3a88c1f8b951ef1525144cd9b988a2f252f</sum>
        </package>
        <package arch="amd64" name="openssh-server" version="1:7.9p1-10+deb10u4+tuxcare.els5">
          <filename>openssh-server_7.9p1-10+deb10u4+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">106239ad28a121b60ad19b5c6de101bc623aeaae</sum>
        </package>
        <package arch="amd64" name="openssh-sftp-server" version="1:7.9p1-10+deb10u4+tuxcare.els5">
          <filename>openssh-sftp-server_7.9p1-10+deb10u4+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">263a677efa79a8a46cbd68b17bd52ebd623a9cf5</sum>
        </package>
        <package arch="amd64" name="openssh-tests" version="1:7.9p1-10+deb10u4+tuxcare.els5">
          <filename>openssh-tests_7.9p1-10+deb10u4+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">be97e0eb21ad783f3f2ac2107246f9fbcfdffb71</sum>
        </package>
        <package arch="all" name="ssh" version="1:7.9p1-10+deb10u4+tuxcare.els5">
          <filename>ssh_7.9p1-10+deb10u4+tuxcare.els5_all.deb</filename>
          <sum type="sha">7002641ca4496c4bdcce35efd1be46fff528716f</sum>
        </package>
        <package arch="amd64" name="ssh-askpass-gnome" version="1:7.9p1-10+deb10u4+tuxcare.els5">
          <filename>ssh-askpass-gnome_7.9p1-10+deb10u4+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">2a3a0b5212c1bc7950a9565e69fc272db657af2c</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1785845612</id>
    <title>Fix CVE(s): CVE-2026-42055</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Heap buffer overflow in ngx_http_grpc_module when
     proxying oversized headers to a gRPC/HTTP/2 upstream
     - debian/patches/CVE-2026-42055.patch: reject request line and header
       fields longer than NGX_HTTP_V2_MAX_FIELD in
       ngx_http_grpc_create_request to prevent buffer overrun when
       large_client_header_buffers exceeds 2 megabytes and
       ignore_invalid_headers is off
     - CVE-2026-42055</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Heap buffer overflow in ngx_http_grpc_module when
     proxying oversized headers to a gRPC/HTTP/2 upstream
     - debian/patches/CVE-2026-42055.patch: reject request line and header
       fields longer than NGX_HTTP_V2_MAX_FIELD in
       ngx_http_grpc_create_request to prevent buffer overrun when
       large_client_header_buffers exceeds 2 megabytes and
       ignore_invalid_headers is off
     - CVE-2026-42055</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-04 12:13:44 UTC" />
    <updated date="2026-08-04 12:13:44 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1785845612.html" id="CLSA-2026:1785845612" title="CLSA-2026:1785845612" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-42055" id="CVE-2026-42055" title="CVE-2026-42055" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libnginx-mod-http-auth-pam" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>libnginx-mod-http-auth-pam_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">38954498ed6719cb122a7af7b10c7d010a26f5cb</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-cache-purge" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>libnginx-mod-http-cache-purge_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">6709c72ededd5dd7216c840fac73b5e25cc17eda</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-dav-ext" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>libnginx-mod-http-dav-ext_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">38ff4727765774fe9c41fd923e000ab18a79417d</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-echo" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>libnginx-mod-http-echo_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">20479a21cb162273736481b90704d18e6c88e8f8</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-fancyindex" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>libnginx-mod-http-fancyindex_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">eddcea0bbf88638bc38f5a23554529b36ffeb87e</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-geoip" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>libnginx-mod-http-geoip_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">fd058a14455a890370bef14252859af56c5f40d8</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-headers-more-filter" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>libnginx-mod-http-headers-more-filter_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">9921d5d8ced0afe9cfbadf2f6e7c9aa2fdd44364</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-image-filter" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>libnginx-mod-http-image-filter_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">a72dac315813cf099decbce74d34be742ddf2f74</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-lua" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>libnginx-mod-http-lua_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">25dc53b69f65675a8d0cd4ec7a87f5fa2580cfb5</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-ndk" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>libnginx-mod-http-ndk_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">13e0d87c5e3de9567fe47865a70698f68d78258c</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-perl" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>libnginx-mod-http-perl_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">068737687d36e7a2899963e4866b6339866e6174</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-subs-filter" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>libnginx-mod-http-subs-filter_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">423e8213f6c4663153880aeeb0192b28c4470c90</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-uploadprogress" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>libnginx-mod-http-uploadprogress_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">5c9456d4140c52ddebe5d69dbcc15b7571bc10ed</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-upstream-fair" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>libnginx-mod-http-upstream-fair_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">9419da098fe6b681adbc823f202933a68da2e0a8</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-http-xslt-filter" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>libnginx-mod-http-xslt-filter_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">e51ce5bb438377163779fe02025c09da91682bc7</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-mail" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>libnginx-mod-mail_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">7e340c0b02fe234dbab9c3ca8054324d43cf69da</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-nchan" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>libnginx-mod-nchan_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">1bb2196014abdfddc083a08ccdc7c1e24737e390</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-rtmp" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>libnginx-mod-rtmp_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">e9ced65fbb418b205e429af9f77338eae0094d65</sum>
        </package>
        <package arch="amd64" name="libnginx-mod-stream" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>libnginx-mod-stream_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">fe72f27268c93d2775346d7c53543c52002f2e4e</sum>
        </package>
        <package arch="all" name="nginx" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>nginx_1.14.2-2+deb10u5+tuxcare.els4_all.deb</filename>
          <sum type="sha">297ffe18fca29860c6e201afe9b0277b96fc6787</sum>
        </package>
        <package arch="all" name="nginx-common" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>nginx-common_1.14.2-2+deb10u5+tuxcare.els4_all.deb</filename>
          <sum type="sha">cf731ba643ce11b73e6da3aed78db44c13256ce7</sum>
        </package>
        <package arch="all" name="nginx-doc" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>nginx-doc_1.14.2-2+deb10u5+tuxcare.els4_all.deb</filename>
          <sum type="sha">9a81b45f11cf89b9f6e503e83e02148ec84797a1</sum>
        </package>
        <package arch="amd64" name="nginx-extras" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>nginx-extras_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">acc8a1746e5128fae1480dcbb235ebe216f0486e</sum>
        </package>
        <package arch="amd64" name="nginx-full" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>nginx-full_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">7061ac923d25d1e24d672dbb71a30fd1c659e997</sum>
        </package>
        <package arch="amd64" name="nginx-light" version="1.14.2-2+deb10u5+tuxcare.els4">
          <filename>nginx-light_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">2cdc5a221068acef28509ff45cb7f28386f8a64c</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1786033252</id>
    <title>Fix CVE(s): CVE-2025-58060</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix authentication bypass in cupsd caused by
     dispatching on the client-supplied Authorization scheme without
     checking it against the configured AuthType.
     - debian/patches/CVE-2025-58060.patch: reject "Authorization: Basic"
       unless the effective AuthType is CUPSD_AUTH_BASIC and
       "Authorization: Negotiate" unless it is CUPSD_AUTH_NEGOTIATE in
       cupsdAuthorize() in scheduler/auth.c.
     - CVE-2025-58060.
   * Fix cupsd failing to start with "cupsdDoSelect() failed - Bad address!"
     on hosts whose RLIMIT_NOFILE hard limit is very large but not
     RLIM_INFINITY, where the epoll event array allocation fails.
     - debian/patches/maxfds-limit.patch: cap MaxFDs at 65535 in
       scheduler/main.c, backported from upstream Issue #989.</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix authentication bypass in cupsd caused by
     dispatching on the client-supplied Authorization scheme without
     checking it against the configured AuthType.
     - debian/patches/CVE-2025-58060.patch: reject "Authorization: Basic"
       unless the effective AuthType is CUPSD_AUTH_BASIC and
       "Authorization: Negotiate" unless it is CUPSD_AUTH_NEGOTIATE in
       cupsdAuthorize() in scheduler/auth.c.
     - CVE-2025-58060.
   * Fix cupsd failing to start with "cupsdDoSelect() failed - Bad address!"
     on hosts whose RLIMIT_NOFILE hard limit is very large but not
     RLIM_INFINITY, where the epoll event array allocation fails.
     - debian/patches/maxfds-limit.patch: cap MaxFDs at 65535 in
       scheduler/main.c, backported from upstream Issue #989.</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-06 16:21:02 UTC" />
    <updated date="2026-08-06 16:21:02 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1786033252.html" id="CLSA-2026:1786033252" title="CLSA-2026:1786033252" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-58060" id="CVE-2025-58060" title="CVE-2025-58060" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="cups" version="2.2.10-6+deb10u10+tuxcare.els4">
          <filename>cups_2.2.10-6+deb10u10+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">52feda24496e030d0e3d58620706256939a6e35e</sum>
        </package>
        <package arch="amd64" name="cups-bsd" version="2.2.10-6+deb10u10+tuxcare.els4">
          <filename>cups-bsd_2.2.10-6+deb10u10+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">6b37ff6af095e729426ff3a718f95902b7043f06</sum>
        </package>
        <package arch="amd64" name="cups-client" version="2.2.10-6+deb10u10+tuxcare.els4">
          <filename>cups-client_2.2.10-6+deb10u10+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">822f24005075fd320ec58f73eaea4ee5f218e158</sum>
        </package>
        <package arch="all" name="cups-common" version="2.2.10-6+deb10u10+tuxcare.els4">
          <filename>cups-common_2.2.10-6+deb10u10+tuxcare.els4_all.deb</filename>
          <sum type="sha">0a3c749c35873c74399181d4b6eadddc98025bd7</sum>
        </package>
        <package arch="amd64" name="cups-core-drivers" version="2.2.10-6+deb10u10+tuxcare.els4">
          <filename>cups-core-drivers_2.2.10-6+deb10u10+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">e3872c0314d5480adb2abb395199c741c2f51ff6</sum>
        </package>
        <package arch="amd64" name="cups-daemon" version="2.2.10-6+deb10u10+tuxcare.els4">
          <filename>cups-daemon_2.2.10-6+deb10u10+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">9f1b09ee19b84a54680c8a3ef39761fb1b270ecd</sum>
        </package>
        <package arch="amd64" name="cups-ipp-utils" version="2.2.10-6+deb10u10+tuxcare.els4">
          <filename>cups-ipp-utils_2.2.10-6+deb10u10+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">8859f5ca8e5cbee09db6fd0471360c690b4da83c</sum>
        </package>
        <package arch="amd64" name="cups-ppdc" version="2.2.10-6+deb10u10+tuxcare.els4">
          <filename>cups-ppdc_2.2.10-6+deb10u10+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">7b3985abe9f1bc4e10df0a9daf83dc745114e73d</sum>
        </package>
        <package arch="all" name="cups-server-common" version="2.2.10-6+deb10u10+tuxcare.els4">
          <filename>cups-server-common_2.2.10-6+deb10u10+tuxcare.els4_all.deb</filename>
          <sum type="sha">c55f08ab4de5ed90e4388810c5b41f6da458431a</sum>
        </package>
        <package arch="amd64" name="libcups2" version="2.2.10-6+deb10u10+tuxcare.els4">
          <filename>libcups2_2.2.10-6+deb10u10+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">611140c394894e4bc805ee935be02152abf26179</sum>
        </package>
        <package arch="amd64" name="libcups2-dev" version="2.2.10-6+deb10u10+tuxcare.els4">
          <filename>libcups2-dev_2.2.10-6+deb10u10+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">acd7675f9748fcc412a3cb610965a6e0083115ed</sum>
        </package>
        <package arch="amd64" name="libcupsimage2" version="2.2.10-6+deb10u10+tuxcare.els4">
          <filename>libcupsimage2_2.2.10-6+deb10u10+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">43aea40402813faaafe0a1c3485049e2b591f88b</sum>
        </package>
        <package arch="amd64" name="libcupsimage2-dev" version="2.2.10-6+deb10u10+tuxcare.els4">
          <filename>libcupsimage2-dev_2.2.10-6+deb10u10+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">e3b139d9b06f097342ab3ebb135013ee6a4958e5</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2025:1761312327</id>
    <title>Fix of 6 CVEs</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: uncontrolled recursion leading to stack overflow via
     crafted XPath expressions
     - debian/patches/CVE-2025-9714.patch: Make XPath depth check work with
       recursive invocations to prevent stack overflows
     - CVE-2025-9714</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: uncontrolled recursion leading to stack overflow via
     crafted XPath expressions
     - debian/patches/CVE-2025-9714.patch: Make XPath depth check work with
       recursive invocations to prevent stack overflows
     - CVE-2025-9714</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-07 08:51:58 UTC" />
    <updated date="2026-08-07 08:51:58 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1761312327.html" id="CLSA-2025:1761312327" title="CLSA-2025:1761312327" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2022-49043" id="CVE-2022-49043" title="CVE-2022-49043" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-25062" id="CVE-2024-25062" title="CVE-2024-25062" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-27113" id="CVE-2025-27113" title="CVE-2025-27113" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-32414" id="CVE-2025-32414" title="CVE-2025-32414" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-32415" id="CVE-2025-32415" title="CVE-2025-32415" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-6021" id="CVE-2025-6021" title="CVE-2025-6021" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libxml2" version="2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els5">
          <filename>libxml2_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">317bd104d239b122a0a29bf9f70020d870992af0</sum>
        </package>
        <package arch="amd64" name="libxml2-dev" version="2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els5">
          <filename>libxml2-dev_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">d1ef5bd1e72e679c4c74a59ad69dd207059f7815</sum>
        </package>
        <package arch="all" name="libxml2-doc" version="2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els5">
          <filename>libxml2-doc_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els5_all.deb</filename>
          <sum type="sha">140c92602c8e67e187ce8dae5d5f31e98e353ea5</sum>
        </package>
        <package arch="amd64" name="libxml2-utils" version="2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els5">
          <filename>libxml2-utils_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">55f08507432e2e1dcfdaf464848b768891f8cf9e</sum>
        </package>
        <package arch="amd64" name="python-libxml2" version="2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els5">
          <filename>python-libxml2_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">6d3ff48185210215e9414e1c638bc29756ec149d</sum>
        </package>
        <package arch="amd64" name="python3-libxml2" version="2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els5">
          <filename>python3-libxml2_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">de825856ea3a676f20d2083c50c792674bb6aec1</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1786093276</id>
    <title>Fix CVE(s): CVE-2026-25749, CVE-2026-34982, CVE-2026-41411</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Heap buffer overflow in get_tagfname() in src/tag.c: the user-settable 'helpfile' option value is copied into a fixed MAXPATHL+1-sized heap buffer with an unbounded STRCPY() when help-file tags are resolved, so a 'helpfile' path longer than MAXPATHL writes past the end of the buffer
     - debian/patches/CVE-2026-25749.patch: replace the unbounded STRCPY(buf, p_hf) in get_tagfname() with a bounded vim_strncpy() that also leaves room for the "tags" tail appended by the following STRCPY(gettail(buf), "tags"), so the 'helpfile' value can no longer be copied past the end of the caller's MAXPATHL-sized buffer
     - CVE-2026-25749
   * SECURITY UPDATE: Modeline sandbox bypass allowing arbitrary OS command execution when a crafted file is opened: the 'complete', 'guitabtooltip' and 'printheader' options are missing the P_MLE flag, so a modeline can set them to expressions that are evaluated outside the 'modelineexpr' guard
     - debian/patches/CVE-2026-34982.patch: add the P_MLE flag to the 'complete', 'guitabtooltip' and 'printheader' entries of the option table in src/option.c so a modeline can no longer set them while 'modelineexpr' is off; the upstream mapset() hunk is dropped as mapset() does not exist in 8.1.0875
     - CVE-2026-34982
   * SECURITY UPDATE: Command injection during tag resolution in expand_tag_fname() in src/tag.c: the filename field read from a tags file is passed to ExpandOne() for wildcard and environment-variable expansion, so a crafted tags file containing backtick syntax makes vim execute the embedded command through the shell with the user's privileges
     - debian/patches/CVE-2026-41411.patch: guard the wildcard expansion in expand_tag_fname() with vim_strchr(fname, '`') == NULL so a tags-file filename field containing backticks is never handed to ExpandOne() and can no longer reach the shell
     - CVE-2026-41411</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Heap buffer overflow in get_tagfname() in src/tag.c: the user-settable 'helpfile' option value is copied into a fixed MAXPATHL+1-sized heap buffer with an unbounded STRCPY() when help-file tags are resolved, so a 'helpfile' path longer than MAXPATHL writes past the end of the buffer
     - debian/patches/CVE-2026-25749.patch: replace the unbounded STRCPY(buf, p_hf) in get_tagfname() with a bounded vim_strncpy() that also leaves room for the "tags" tail appended by the following STRCPY(gettail(buf), "tags"), so the 'helpfile' value can no longer be copied past the end of the caller's MAXPATHL-sized buffer
     - CVE-2026-25749
   * SECURITY UPDATE: Modeline sandbox bypass allowing arbitrary OS command execution when a crafted file is opened: the 'complete', 'guitabtooltip' and 'printheader' options are missing the P_MLE flag, so a modeline can set them to expressions that are evaluated outside the 'modelineexpr' guard
     - debian/patches/CVE-2026-34982.patch: add the P_MLE flag to the 'complete', 'guitabtooltip' and 'printheader' entries of the option table in src/option.c so a modeline can no longer set them while 'modelineexpr' is off; the upstream mapset() hunk is dropped as mapset() does not exist in 8.1.0875
     - CVE-2026-34982
   * SECURITY UPDATE: Command injection during tag resolution in expand_tag_fname() in src/tag.c: the filename field read from a tags file is passed to ExpandOne() for wildcard and environment-variable expansion, so a crafted tags file containing backtick syntax makes vim execute the embedded command through the shell with the user's privileges
     - debian/patches/CVE-2026-41411.patch: guard the wildcard expansion in expand_tag_fname() with vim_strchr(fname, '`') == NULL so a tags-file filename field containing backticks is never handed to ExpandOne() and can no longer reach the shell
     - CVE-2026-41411</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-07 09:01:28 UTC" />
    <updated date="2026-08-07 09:01:28 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1786093276.html" id="CLSA-2026:1786093276" title="CLSA-2026:1786093276" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-25749" id="CVE-2026-25749" title="CVE-2026-25749" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-34982" id="CVE-2026-34982" title="CVE-2026-34982" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-41411" id="CVE-2026-41411" title="CVE-2026-41411" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="vim" version="2:8.1.0875-5+deb10u6+tuxcare.els26">
          <filename>vim_8.1.0875-5+deb10u6+tuxcare.els26_amd64.deb</filename>
          <sum type="sha">9c9e0223093a730f7fe1bd92aaa434eadeba87f7</sum>
        </package>
        <package arch="amd64" name="vim-athena" version="2:8.1.0875-5+deb10u6+tuxcare.els26">
          <filename>vim-athena_8.1.0875-5+deb10u6+tuxcare.els26_amd64.deb</filename>
          <sum type="sha">c879a5f7c6e26b2af53fc82f6784c07554215d8d</sum>
        </package>
        <package arch="all" name="vim-common" version="2:8.1.0875-5+deb10u6+tuxcare.els26">
          <filename>vim-common_8.1.0875-5+deb10u6+tuxcare.els26_all.deb</filename>
          <sum type="sha">de16431e5f8910ca7b156b9a299d266a17ad3d5a</sum>
        </package>
        <package arch="all" name="vim-doc" version="2:8.1.0875-5+deb10u6+tuxcare.els26">
          <filename>vim-doc_8.1.0875-5+deb10u6+tuxcare.els26_all.deb</filename>
          <sum type="sha">dc61997c3042f6cec01198a58ffaa4fbab8dfb89</sum>
        </package>
        <package arch="amd64" name="vim-gtk" version="2:8.1.0875-5+deb10u6+tuxcare.els26">
          <filename>vim-gtk_8.1.0875-5+deb10u6+tuxcare.els26_amd64.deb</filename>
          <sum type="sha">17e0f1c42dc9f8602b2f97046055aca286ebbaa9</sum>
        </package>
        <package arch="amd64" name="vim-gtk3" version="2:8.1.0875-5+deb10u6+tuxcare.els26">
          <filename>vim-gtk3_8.1.0875-5+deb10u6+tuxcare.els26_amd64.deb</filename>
          <sum type="sha">2c2de57dacebaf5e04d9bfcf1171327bb28d92e2</sum>
        </package>
        <package arch="all" name="vim-gui-common" version="2:8.1.0875-5+deb10u6+tuxcare.els26">
          <filename>vim-gui-common_8.1.0875-5+deb10u6+tuxcare.els26_all.deb</filename>
          <sum type="sha">01213da52ba9f6f5796d3b485610b14a2bbacd68</sum>
        </package>
        <package arch="amd64" name="vim-nox" version="2:8.1.0875-5+deb10u6+tuxcare.els26">
          <filename>vim-nox_8.1.0875-5+deb10u6+tuxcare.els26_amd64.deb</filename>
          <sum type="sha">0686f42f4cacc43bb0207942d836b3322ff1112b</sum>
        </package>
        <package arch="all" name="vim-runtime" version="2:8.1.0875-5+deb10u6+tuxcare.els26">
          <filename>vim-runtime_8.1.0875-5+deb10u6+tuxcare.els26_all.deb</filename>
          <sum type="sha">6934428a32fb8c5e8e70f0c3448bf3216e6ac6e7</sum>
        </package>
        <package arch="amd64" name="vim-tiny" version="2:8.1.0875-5+deb10u6+tuxcare.els26">
          <filename>vim-tiny_8.1.0875-5+deb10u6+tuxcare.els26_amd64.deb</filename>
          <sum type="sha">0f1ffbf0ceda53bcf57722a81b6b176ececdd319</sum>
        </package>
        <package arch="amd64" name="xxd" version="2:8.1.0875-5+deb10u6+tuxcare.els26">
          <filename>xxd_8.1.0875-5+deb10u6+tuxcare.els26_amd64.deb</filename>
          <sum type="sha">7a6c9b7d2e2dee7882a3d9b0f686e75d89071f9c</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1786093474</id>
    <title>Fix of 6 CVEs</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: potential SSRF in mod_rewrite via RewriteRule
     substitutions that produce a scheme-like target
     - debian/patches/CVE-2024-39573.patch: add the previously stripped
       per-directory prefix, or an implicit '/' root prefix, to the
       substituted URI before the query args are split in
       apply_rewrite_rule() in modules/mappers/mod_rewrite.c; otherwise a
       rule such as "RewriteRule ^/some/path(.*) $1" turns
       "/some/pathscheme:..." into the fully qualified URL "scheme:...",
       which mod_proxy then handles. Upstream fix
       93aec0e3ca451bcc97f6d91c14d5399d13a73365 (SVN r1918600).
     - CVE-2024-39573
   * SECURITY UPDATE: insufficient escaping of mod_ssl variables written to
     the log by CustomLog
     - debian/patches/CVE-2024-47252.patch: pass the results of
       ssl_var_log_handler_c() and ssl_var_log_handler_x() through
       ap_escape_logitem() in modules/ssl/ssl_engine_vars.c, so an untrusted
       TLS client can no longer insert escape characters into log files
       through the %{varname}c and %{varname}x formats logging mod_ssl
       variables such as SSL_TLS_SNI. Upstream fix
       c01e60707048be14a510f0a92128a5227923215c (SVN r1927042).
     - CVE-2024-47252
   * SECURITY UPDATE: access control bypass by trusted clients through TLS
     1.3 session resumption in mod_ssl
     - debian/patches/CVE-2025-23048.patch: move the ssl_server_compatible()
       check in ssl_hook_ReadReq() in modules/ssl/ssl_engine_kernel.c out of
       the SNI-present branch, so the handshake virtual host and the request
       virtual host are compared even when the client sent no SNI, as happens
       on a resumed TLS 1.3 session; previously such a request could reach a
       virtual host with different client certificate restrictions when
       SSLStrictSNIVHostCheck was off. Upstream fix
       c4cfa50c9068e8b8134c530ab21674e77d1278a2 (SVN r1927043).
     - CVE-2025-23048
   * SECURITY UPDATE: denial of service through an assertion failure in
     mod_proxy_http2
     - debian/patches/CVE-2025-49630.patch: fall back to the server hostname
       when ProxyPreserveHost is on but the incoming request carried no Host:
       header, in open_stream() in modules/http2/h2_proxy_session.c, instead
       of passing a NULL authority on to the HTTP/2 backend and tripping an
       assertion. Upstream fix 88304321841a2fe8bd5eacc70e69418b0b545ca5 (SVN
       r1927044).
     - CVE-2025-49630
   * SECURITY UPDATE: query string passed by mod_cgid to Server Side Includes
     #exec cmd= commands
     - debian/patches/CVE-2025-58098.patch: pass NULL instead of r-&gt;args to
       create_argv() for SSI_REQ requests in cgid_server(), and tolerate a
       NULL args in create_argv(), in modules/generators/mod_cgid.c;
       otherwise the shell-escaped query string is appended as arguments to
       the command line of an SSI "#exec cmd=..." directive. Upstream fix
       ecc1b8f3817e3dcab9c1f24f905752d3c0a279af (SVN r1930161).
     - CVE-2025-58098
   * SECURITY UPDATE: integer overflow in the mod_md ACME renewal backoff
     timer
     - debian/patches/CVE-2025-55753.patch: double the retry delay step by
       step with an overflow and cap check in md_job_delay_on_errors() in
       modules/md/md_status.c instead of shifting job-&gt;min_delay left by
       err_count-1 in one go; otherwise after roughly 30 days of consecutive
       renewal failures the shift wraps the signed apr_time_t, the backoff
       collapses to 0 and the server retries against the ACME CA in a tight
       loop. Upstream fix 20666cfb765b8ad14efa3d97bc92d344b9395c89 (SVN
       r1929515).
     - CVE-2025-55753</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: potential SSRF in mod_rewrite via RewriteRule
     substitutions that produce a scheme-like target
     - debian/patches/CVE-2024-39573.patch: add the previously stripped
       per-directory prefix, or an implicit '/' root prefix, to the
       substituted URI before the query args are split in
       apply_rewrite_rule() in modules/mappers/mod_rewrite.c; otherwise a
       rule such as "RewriteRule ^/some/path(.*) $1" turns
       "/some/pathscheme:..." into the fully qualified URL "scheme:...",
       which mod_proxy then handles. Upstream fix
       93aec0e3ca451bcc97f6d91c14d5399d13a73365 (SVN r1918600).
     - CVE-2024-39573
   * SECURITY UPDATE: insufficient escaping of mod_ssl variables written to
     the log by CustomLog
     - debian/patches/CVE-2024-47252.patch: pass the results of
       ssl_var_log_handler_c() and ssl_var_log_handler_x() through
       ap_escape_logitem() in modules/ssl/ssl_engine_vars.c, so an untrusted
       TLS client can no longer insert escape characters into log files
       through the %{varname}c and %{varname}x formats logging mod_ssl
       variables such as SSL_TLS_SNI. Upstream fix
       c01e60707048be14a510f0a92128a5227923215c (SVN r1927042).
     - CVE-2024-47252
   * SECURITY UPDATE: access control bypass by trusted clients through TLS
     1.3 session resumption in mod_ssl
     - debian/patches/CVE-2025-23048.patch: move the ssl_server_compatible()
       check in ssl_hook_ReadReq() in modules/ssl/ssl_engine_kernel.c out of
       the SNI-present branch, so the handshake virtual host and the request
       virtual host are compared even when the client sent no SNI, as happens
       on a resumed TLS 1.3 session; previously such a request could reach a
       virtual host with different client certificate restrictions when
       SSLStrictSNIVHostCheck was off. Upstream fix
       c4cfa50c9068e8b8134c530ab21674e77d1278a2 (SVN r1927043).
     - CVE-2025-23048
   * SECURITY UPDATE: denial of service through an assertion failure in
     mod_proxy_http2
     - debian/patches/CVE-2025-49630.patch: fall back to the server hostname
       when ProxyPreserveHost is on but the incoming request carried no Host:
       header, in open_stream() in modules/http2/h2_proxy_session.c, instead
       of passing a NULL authority on to the HTTP/2 backend and tripping an
       assertion. Upstream fix 88304321841a2fe8bd5eacc70e69418b0b545ca5 (SVN
       r1927044).
     - CVE-2025-49630
   * SECURITY UPDATE: query string passed by mod_cgid to Server Side Includes
     #exec cmd= commands
     - debian/patches/CVE-2025-58098.patch: pass NULL instead of r-&gt;args to
       create_argv() for SSI_REQ requests in cgid_server(), and tolerate a
       NULL args in create_argv(), in modules/generators/mod_cgid.c;
       otherwise the shell-escaped query string is appended as arguments to
       the command line of an SSI "#exec cmd=..." directive. Upstream fix
       ecc1b8f3817e3dcab9c1f24f905752d3c0a279af (SVN r1930161).
     - CVE-2025-58098
   * SECURITY UPDATE: integer overflow in the mod_md ACME renewal backoff
     timer
     - debian/patches/CVE-2025-55753.patch: double the retry delay step by
       step with an overflow and cap check in md_job_delay_on_errors() in
       modules/md/md_status.c instead of shifting job-&gt;min_delay left by
       err_count-1 in one go; otherwise after roughly 30 days of consecutive
       renewal failures the shift wraps the signed apr_time_t, the backoff
       collapses to 0 and the server retries against the ACME CA in a tight
       loop. Upstream fix 20666cfb765b8ad14efa3d97bc92d344b9395c89 (SVN
       r1929515).
     - CVE-2025-55753</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-07 09:04:47 UTC" />
    <updated date="2026-08-07 09:04:47 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1786093474.html" id="CLSA-2026:1786093474" title="CLSA-2026:1786093474" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-39573" id="CVE-2024-39573" title="CVE-2024-39573" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-47252" id="CVE-2024-47252" title="CVE-2024-47252" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-23048" id="CVE-2025-23048" title="CVE-2025-23048" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-49630" id="CVE-2025-49630" title="CVE-2025-49630" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-55753" id="CVE-2025-55753" title="CVE-2025-55753" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-58098" id="CVE-2025-58098" title="CVE-2025-58098" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="apache2" version="2.4.59-1~deb10u1+tuxcare.els12">
          <filename>apache2_2.4.59-1~deb10u1+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">b830c01e9f7482b84bbd245fe783efdc40b2a1d4</sum>
        </package>
        <package arch="amd64" name="apache2-bin" version="2.4.59-1~deb10u1+tuxcare.els12">
          <filename>apache2-bin_2.4.59-1~deb10u1+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">bfdfe7ac103eed8b40df63c85d23a6291aaba470</sum>
        </package>
        <package arch="all" name="apache2-data" version="2.4.59-1~deb10u1+tuxcare.els12">
          <filename>apache2-data_2.4.59-1~deb10u1+tuxcare.els12_all.deb</filename>
          <sum type="sha">c8a5cece95610164b39a32bc1b6c1a7f0564b243</sum>
        </package>
        <package arch="amd64" name="apache2-dev" version="2.4.59-1~deb10u1+tuxcare.els12">
          <filename>apache2-dev_2.4.59-1~deb10u1+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">bf339dd169a9a5a29ba07d83a1dfe97a53763278</sum>
        </package>
        <package arch="all" name="apache2-doc" version="2.4.59-1~deb10u1+tuxcare.els12">
          <filename>apache2-doc_2.4.59-1~deb10u1+tuxcare.els12_all.deb</filename>
          <sum type="sha">f84504cec024da6df73ca3336a732d2843a2abbf</sum>
        </package>
        <package arch="amd64" name="apache2-ssl-dev" version="2.4.59-1~deb10u1+tuxcare.els12">
          <filename>apache2-ssl-dev_2.4.59-1~deb10u1+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">3ad98d2e0d3255c873817b2b1b0b812816432ed8</sum>
        </package>
        <package arch="amd64" name="apache2-suexec-custom" version="2.4.59-1~deb10u1+tuxcare.els12">
          <filename>apache2-suexec-custom_2.4.59-1~deb10u1+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">31c2acdf5031448c1929934aa014bfed96ae9263</sum>
        </package>
        <package arch="amd64" name="apache2-suexec-pristine" version="2.4.59-1~deb10u1+tuxcare.els12">
          <filename>apache2-suexec-pristine_2.4.59-1~deb10u1+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">f4fbe1b9b53d64d951a1e06e1d3fa8df05b084c5</sum>
        </package>
        <package arch="amd64" name="apache2-utils" version="2.4.59-1~deb10u1+tuxcare.els12">
          <filename>apache2-utils_2.4.59-1~deb10u1+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">2bd22ca6ad2c3b2284d04f788900612b52d4b294</sum>
        </package>
        <package arch="amd64" name="libapache2-mod-md" version="2.4.59-1~deb10u1+tuxcare.els12">
          <filename>libapache2-mod-md_2.4.59-1~deb10u1+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">dfca6714edc3939a8b066c4615488f80426ffc33</sum>
        </package>
        <package arch="amd64" name="libapache2-mod-proxy-uwsgi" version="2.4.59-1~deb10u1+tuxcare.els12">
          <filename>libapache2-mod-proxy-uwsgi_2.4.59-1~deb10u1+tuxcare.els12_amd64.deb</filename>
          <sum type="sha">bb16601c22a1f6d6d71a3f3941a30e4626aee933</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1786352989</id>
    <title>Fix CVE(s): CVE-2026-59083</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Security constraint bypass in the RewriteValve - the
     decoded and normalized request URI used for subsequent security
     constraint matching was produced with java.net.URLDecoder.decode(),
     which applies form-encoding rules and converts '+' to a space instead
     of performing proper URI percent-decoding
     - debian/patches/CVE-2026-59083.patch: use Tomcat's UDecoder.URLDecode()
       (already imported and used elsewhere in the class) instead of
       java.net.URLDecoder.decode() to build the decoded request URI
     - CVE-2026-59083</description>
    <severity>Moderate</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Security constraint bypass in the RewriteValve - the
     decoded and normalized request URI used for subsequent security
     constraint matching was produced with java.net.URLDecoder.decode(),
     which applies form-encoding rules and converts '+' to a space instead
     of performing proper URI percent-decoding
     - debian/patches/CVE-2026-59083.patch: use Tomcat's UDecoder.URLDecode()
       (already imported and used elsewhere in the class) instead of
       java.net.URLDecoder.decode() to build the decoded request URI
     - CVE-2026-59083</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-10 09:09:59 UTC" />
    <updated date="2026-08-10 09:09:59 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1786352989.html" id="CLSA-2026:1786352989" title="CLSA-2026:1786352989" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-59083" id="CVE-2026-59083" title="CVE-2026-59083" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="all" name="libtomcat9-embed-java" version="9.0.31-1~deb10u12+tuxcare.els7">
          <filename>libtomcat9-embed-java_9.0.31-1~deb10u12+tuxcare.els7_all.deb</filename>
          <sum type="sha">9c2e795e234da0c126de6dd799860f35885f74f1</sum>
        </package>
        <package arch="all" name="libtomcat9-java" version="9.0.31-1~deb10u12+tuxcare.els7">
          <filename>libtomcat9-java_9.0.31-1~deb10u12+tuxcare.els7_all.deb</filename>
          <sum type="sha">784f57a117fd056f21a65c9f719c785997af32de</sum>
        </package>
        <package arch="all" name="tomcat9" version="9.0.31-1~deb10u12+tuxcare.els7">
          <filename>tomcat9_9.0.31-1~deb10u12+tuxcare.els7_all.deb</filename>
          <sum type="sha">3d0bd84f880e15a50c5a574671e074e641ce8adc</sum>
        </package>
        <package arch="all" name="tomcat9-admin" version="9.0.31-1~deb10u12+tuxcare.els7">
          <filename>tomcat9-admin_9.0.31-1~deb10u12+tuxcare.els7_all.deb</filename>
          <sum type="sha">22e44c8187f207c498692cd7f19a88d64cdaaf70</sum>
        </package>
        <package arch="all" name="tomcat9-common" version="9.0.31-1~deb10u12+tuxcare.els7">
          <filename>tomcat9-common_9.0.31-1~deb10u12+tuxcare.els7_all.deb</filename>
          <sum type="sha">2941768d2dad38baf1c031d5cec65e5cca9e9db6</sum>
        </package>
        <package arch="all" name="tomcat9-docs" version="9.0.31-1~deb10u12+tuxcare.els7">
          <filename>tomcat9-docs_9.0.31-1~deb10u12+tuxcare.els7_all.deb</filename>
          <sum type="sha">ac020c46dfa112cb1f22d63e9f754263eb3439f5</sum>
        </package>
        <package arch="all" name="tomcat9-examples" version="9.0.31-1~deb10u12+tuxcare.els7">
          <filename>tomcat9-examples_9.0.31-1~deb10u12+tuxcare.els7_all.deb</filename>
          <sum type="sha">88817701f4fffbb1f9073b5d987a8fa987660082</sum>
        </package>
        <package arch="all" name="tomcat9-user" version="9.0.31-1~deb10u12+tuxcare.els7">
          <filename>tomcat9-user_9.0.31-1~deb10u12+tuxcare.els7_all.deb</filename>
          <sum type="sha">8fc4e8a9265caff22fc079ca5e4272da7589b844</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1786357657</id>
    <title>Fix CVE(s): CVE-2026-0864, CVE-2026-11972</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: configuration file injection via carriage returns in
     written option values
     - debian/patches/CVE-2026-0864.patch: normalise CR and CRLF, and not
       only LF, into '\n\t' continuation lines when writing option values in
       RawConfigParser.write() in Lib/ConfigParser.py, so that an
       attacker-controlled value can no longer inject additional sections,
       keys and values into the written file
     - CVE-2026-0864
   * SECURITY UPDATE: CPU denial-of-service in tarfile streaming mode via a
     member size declared past the end of the stream
     - debian/patches/CVE-2026-11972.patch: stop _Stream.seek() at the first
       empty read instead of looping once per attacker-declared block against
       an already-exhausted stream in Lib/tarfile.py
     - CVE-2026-11972</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: configuration file injection via carriage returns in
     written option values
     - debian/patches/CVE-2026-0864.patch: normalise CR and CRLF, and not
       only LF, into '\n\t' continuation lines when writing option values in
       RawConfigParser.write() in Lib/ConfigParser.py, so that an
       attacker-controlled value can no longer inject additional sections,
       keys and values into the written file
     - CVE-2026-0864
   * SECURITY UPDATE: CPU denial-of-service in tarfile streaming mode via a
     member size declared past the end of the stream
     - debian/patches/CVE-2026-11972.patch: stop _Stream.seek() at the first
       empty read instead of looping once per attacker-declared block against
       an already-exhausted stream in Lib/tarfile.py
     - CVE-2026-11972</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-10 10:27:49 UTC" />
    <updated date="2026-08-10 10:27:49 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1786357657.html" id="CLSA-2026:1786357657" title="CLSA-2026:1786357657" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-0864" id="CVE-2026-0864" title="CVE-2026-0864" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-11972" id="CVE-2026-11972" title="CVE-2026-11972" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="all" name="idle-python2.7" version="2.7.16-2+deb10u4+tuxcare.els4">
          <filename>idle-python2.7_2.7.16-2+deb10u4+tuxcare.els4_all.deb</filename>
          <sum type="sha">64d44ec3f988f36c019ca22bb22cc26905d51024</sum>
        </package>
        <package arch="amd64" name="libpython2.7" version="2.7.16-2+deb10u4+tuxcare.els4">
          <filename>libpython2.7_2.7.16-2+deb10u4+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">f2151e1383e5ad5f017a980ddeb18b273992706d</sum>
        </package>
        <package arch="amd64" name="libpython2.7-dev" version="2.7.16-2+deb10u4+tuxcare.els4">
          <filename>libpython2.7-dev_2.7.16-2+deb10u4+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">037ccc64d081a6d206eda8ff766720d2567f0899</sum>
        </package>
        <package arch="amd64" name="libpython2.7-minimal" version="2.7.16-2+deb10u4+tuxcare.els4">
          <filename>libpython2.7-minimal_2.7.16-2+deb10u4+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">d5010b1aaa8e3e2c2ed63502bd7a20fbb1f8da15</sum>
        </package>
        <package arch="amd64" name="libpython2.7-stdlib" version="2.7.16-2+deb10u4+tuxcare.els4">
          <filename>libpython2.7-stdlib_2.7.16-2+deb10u4+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">7fd75aa1c667255af7f69e63009ee2d7c8908add</sum>
        </package>
        <package arch="all" name="libpython2.7-testsuite" version="2.7.16-2+deb10u4+tuxcare.els4">
          <filename>libpython2.7-testsuite_2.7.16-2+deb10u4+tuxcare.els4_all.deb</filename>
          <sum type="sha">fb06504d2e431ca82462f28c5325bb6e2093118d</sum>
        </package>
        <package arch="amd64" name="python2.7" version="2.7.16-2+deb10u4+tuxcare.els4">
          <filename>python2.7_2.7.16-2+deb10u4+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">d5e14d154116d837a73508df86c6c7d465a7e9bc</sum>
        </package>
        <package arch="amd64" name="python2.7-dev" version="2.7.16-2+deb10u4+tuxcare.els4">
          <filename>python2.7-dev_2.7.16-2+deb10u4+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">ce00b364688f426a3a83726989682e0c26f721e4</sum>
        </package>
        <package arch="all" name="python2.7-doc" version="2.7.16-2+deb10u4+tuxcare.els4">
          <filename>python2.7-doc_2.7.16-2+deb10u4+tuxcare.els4_all.deb</filename>
          <sum type="sha">fa22faf3ab64825a2592c61d08a7cff2d938cadf</sum>
        </package>
        <package arch="all" name="python2.7-examples" version="2.7.16-2+deb10u4+tuxcare.els4">
          <filename>python2.7-examples_2.7.16-2+deb10u4+tuxcare.els4_all.deb</filename>
          <sum type="sha">26f32860caa06bdd7c41f29791bdae147982ef7a</sum>
        </package>
        <package arch="amd64" name="python2.7-minimal" version="2.7.16-2+deb10u4+tuxcare.els4">
          <filename>python2.7-minimal_2.7.16-2+deb10u4+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">498b562a6d0a02885e5b2ac4c3721c0b1dff94cd</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1786358668</id>
    <title>Fix CVE(s): CVE-2026-6846</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: heap-based buffer overflow in xcoff_link_add_symbols
     (bfd/xcofflink.c) triggered by a crafted XCOFF object file
     - debian/patches/CVE-2026-6846.patch: size the reloc_info array by the
       highest section target_index rather than by section_count, which the
       XCOFF overflow-header handling decrements
     - CVE-2026-6846</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: heap-based buffer overflow in xcoff_link_add_symbols
     (bfd/xcofflink.c) triggered by a crafted XCOFF object file
     - debian/patches/CVE-2026-6846.patch: size the reloc_info array by the
       highest section target_index rather than by section_count, which the
       XCOFF overflow-header handling decrements
     - CVE-2026-6846</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-10 10:48:22 UTC" />
    <updated date="2026-08-10 10:48:22 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1786358668.html" id="CLSA-2026:1786358668" title="CLSA-2026:1786358668" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-6846" id="CVE-2026-6846" title="CVE-2026-6846" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="binutils" version="2.31.1-16+tuxcare.els13">
          <filename>binutils_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">70d9bf1d17319603f4b4fe13df4737ea533b2de6</sum>
        </package>
        <package arch="amd64" name="binutils-aarch64-linux-gnu" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-aarch64-linux-gnu_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">f01e14bff11947d2bea1ea10ee13c50e6a6605f0</sum>
        </package>
        <package arch="amd64" name="binutils-alpha-linux-gnu" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-alpha-linux-gnu_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">331be55844b3b307cffccbff329095d98bb79f97</sum>
        </package>
        <package arch="amd64" name="binutils-arm-linux-gnueabi" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-arm-linux-gnueabi_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">5d160f7a797aac0e3b47c5a23433299883720fc8</sum>
        </package>
        <package arch="amd64" name="binutils-arm-linux-gnueabihf" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-arm-linux-gnueabihf_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">0d0559de6f77eccd0af01635a8cacf40c016e4b9</sum>
        </package>
        <package arch="amd64" name="binutils-common" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-common_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">1990d349e384e8d556583fd3cd6d53a19ac02f2b</sum>
        </package>
        <package arch="amd64" name="binutils-dev" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-dev_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">e6ab91d662da83894ba29aaebeabde1f6714bdb6</sum>
        </package>
        <package arch="all" name="binutils-doc" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-doc_2.31.1-16+tuxcare.els13_all.deb</filename>
          <sum type="sha">295a9fde1b65a3cddf0ed6e22c1de008f0a597f2</sum>
        </package>
        <package arch="all" name="binutils-for-build" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-for-build_2.31.1-16+tuxcare.els13_all.deb</filename>
          <sum type="sha">908669f0672d219195bd9cd96c0f817e1019d77b</sum>
        </package>
        <package arch="amd64" name="binutils-for-host" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-for-host_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">2c1f7ea7d7f2997565e89bbb5d7f98a6189cba76</sum>
        </package>
        <package arch="amd64" name="binutils-hppa-linux-gnu" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-hppa-linux-gnu_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">0c6ea0b9f6776032e70e405a7a38fd4d0fdf637a</sum>
        </package>
        <package arch="amd64" name="binutils-hppa64-linux-gnu" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-hppa64-linux-gnu_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">62e7ff8935de1263268d7b3d3a1bd1c4eb22bf49</sum>
        </package>
        <package arch="amd64" name="binutils-i686-gnu" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-i686-gnu_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">18c3acd74abbdc3bffe33c107fceecd0e12c42b0</sum>
        </package>
        <package arch="amd64" name="binutils-i686-kfreebsd-gnu" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-i686-kfreebsd-gnu_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">8e16b5ef602b9cf474d2fb33c324ccd276f79542</sum>
        </package>
        <package arch="amd64" name="binutils-i686-linux-gnu" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-i686-linux-gnu_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">e26c3675af717d8b5fb5c1c795b5bee3fb2a1b21</sum>
        </package>
        <package arch="amd64" name="binutils-ia64-linux-gnu" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-ia64-linux-gnu_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">6a426e75ed7d66cffca118daf5346ef0754e9a9a</sum>
        </package>
        <package arch="amd64" name="binutils-m68k-linux-gnu" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-m68k-linux-gnu_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">2b21dd721df97330227cd47b654f293306a316c4</sum>
        </package>
        <package arch="amd64" name="binutils-mips-linux-gnu" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-mips-linux-gnu_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">d26221337e69d81e0414b5094de9ac239662595c</sum>
        </package>
        <package arch="amd64" name="binutils-mips64el-linux-gnuabi64" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-mips64el-linux-gnuabi64_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">2334926d1f08b135a6d7252b0014e2a7fcb92a11</sum>
        </package>
        <package arch="amd64" name="binutils-mipsel-linux-gnu" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-mipsel-linux-gnu_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">62c593a02cf8d9dc2ebd7be1ef12734aaaa1ac8d</sum>
        </package>
        <package arch="amd64" name="binutils-multiarch" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-multiarch_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">7f7937baba71152e7bae9a1db0b4a64f12ee089d</sum>
        </package>
        <package arch="amd64" name="binutils-multiarch-dev" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-multiarch-dev_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">0f4beaa971adc5d3db91c3a7b4f05d0ac41bba57</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc-linux-gnu" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-powerpc-linux-gnu_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">4f5c78e6db0b6746f86e75b7e741b4718c8ba536</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc-linux-gnuspe" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-powerpc-linux-gnuspe_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">fd08840672df36f50365ab2b0cd597f4bad7de52</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc64-linux-gnu" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-powerpc64-linux-gnu_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">4b4cca94498c5a75b28297c3d2b57b97ddce2bb3</sum>
        </package>
        <package arch="amd64" name="binutils-powerpc64le-linux-gnu" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-powerpc64le-linux-gnu_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">c15ed836c58dfe606a1da8be53a0274909da9c60</sum>
        </package>
        <package arch="amd64" name="binutils-riscv64-linux-gnu" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-riscv64-linux-gnu_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">1529258503f0e61426a969d28272412cec97b148</sum>
        </package>
        <package arch="amd64" name="binutils-s390x-linux-gnu" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-s390x-linux-gnu_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">abafa1b6c8f80729efd2169688c0af360b56a4b2</sum>
        </package>
        <package arch="amd64" name="binutils-sh4-linux-gnu" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-sh4-linux-gnu_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">ed11ab19fb885d16753050cc4a9c00bd9ac18dab</sum>
        </package>
        <package arch="all" name="binutils-source" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-source_2.31.1-16+tuxcare.els13_all.deb</filename>
          <sum type="sha">5ef76bce38ea959a08a96204a2bd26197a420442</sum>
        </package>
        <package arch="amd64" name="binutils-sparc64-linux-gnu" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-sparc64-linux-gnu_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">e9179d741ec59b2dd0129be1b72ac4f46dde8e4e</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-kfreebsd-gnu" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-x86-64-kfreebsd-gnu_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">ed95095a5d8596ac95107c9cc3fb97138fd93241</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-linux-gnu" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-x86-64-linux-gnu_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">005f3e073a084c6020fce7a46af2e3551024f122</sum>
        </package>
        <package arch="amd64" name="binutils-x86-64-linux-gnux32" version="2.31.1-16+tuxcare.els13">
          <filename>binutils-x86-64-linux-gnux32_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">244f22511c1f2a2c2fe6e4f791d83294e78a0d3f</sum>
        </package>
        <package arch="amd64" name="libbinutils" version="2.31.1-16+tuxcare.els13">
          <filename>libbinutils_2.31.1-16+tuxcare.els13_amd64.deb</filename>
          <sum type="sha">e68d010164b1b9bfff37629c901741d0709d5fc1</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1786451206</id>
    <title>Fix CVE(s): CVE-2026-56407, CVE-2026-56408, CVE-2026-56409</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Integer overflow in doProlog related to
     storeEntityValue and entity textLen (libexpat before 2.8.2)
     - debian/patches/CVE-2026-56407.patch: cap the entity value pool
       length at INT_MAX before assigning it to the signed
       ENTITY::textLen in doProlog
     - CVE-2026-56407
   * SECURITY UPDATE: Integer overflow in copyString (libexpat before
     2.8.2)
     - debian/patches/CVE-2026-56408.patch: reject lengths above
       SIZE_MAX / sizeof(XML_Char) before sizing the copy, closing the
       multiplication overflow in wide-character (libexpatw) builds
     - CVE-2026-56408
   * SECURITY UPDATE: Integer overflow for the output filename in xmlwf
     when -d outputDir is used (libexpat before 2.8.2)
     - debian/patches/CVE-2026-56409.patch: check the output path join
       for addition and multiplication overflow, and check the malloc
       result, before writing the joined path
     - CVE-2026-56409</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Integer overflow in doProlog related to
     storeEntityValue and entity textLen (libexpat before 2.8.2)
     - debian/patches/CVE-2026-56407.patch: cap the entity value pool
       length at INT_MAX before assigning it to the signed
       ENTITY::textLen in doProlog
     - CVE-2026-56407
   * SECURITY UPDATE: Integer overflow in copyString (libexpat before
     2.8.2)
     - debian/patches/CVE-2026-56408.patch: reject lengths above
       SIZE_MAX / sizeof(XML_Char) before sizing the copy, closing the
       multiplication overflow in wide-character (libexpatw) builds
     - CVE-2026-56408
   * SECURITY UPDATE: Integer overflow for the output filename in xmlwf
     when -d outputDir is used (libexpat before 2.8.2)
     - debian/patches/CVE-2026-56409.patch: check the output path join
       for addition and multiplication overflow, and check the malloc
       result, before writing the joined path
     - CVE-2026-56409</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-11 12:26:59 UTC" />
    <updated date="2026-08-11 12:26:59 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1786451206.html" id="CLSA-2026:1786451206" title="CLSA-2026:1786451206" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-56407" id="CVE-2026-56407" title="CVE-2026-56407" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-56408" id="CVE-2026-56408" title="CVE-2026-56408" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-56409" id="CVE-2026-56409" title="CVE-2026-56409" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="expat" version="2.2.6-2+deb10u7+tuxcare.els7">
          <filename>expat_2.2.6-2+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">2af011dd0737524aa45277b59e3d3d6411e21935</sum>
        </package>
        <package arch="amd64" name="libexpat1" version="2.2.6-2+deb10u7+tuxcare.els7">
          <filename>libexpat1_2.2.6-2+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">8c71dc6c66fb00d3a59c56d4dcb30bc965ba6045</sum>
        </package>
        <package arch="amd64" name="libexpat1-dev" version="2.2.6-2+deb10u7+tuxcare.els7">
          <filename>libexpat1-dev_2.2.6-2+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">5bdeae0ff990a8e8259284230f73595e5c82ff8f</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1786454415</id>
    <title>Fix CVE(s): CVE-2024-12085</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: information leak of uninitialized stack memory via an
     attacker-controlled checksum length (s2length) in hash_search():
     - debian/patches/els/0008-CVE-2024-12085.patch: zero the local sum2
       buffer on entry to hash_search().
     - CVE-2024-12085.</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: information leak of uninitialized stack memory via an
     attacker-controlled checksum length (s2length) in hash_search():
     - debian/patches/els/0008-CVE-2024-12085.patch: zero the local sum2
       buffer on entry to hash_search().
     - CVE-2024-12085.</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-11 13:20:26 UTC" />
    <updated date="2026-08-11 13:20:26 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1786454415.html" id="CLSA-2026:1786454415" title="CLSA-2026:1786454415" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-12085" id="CVE-2024-12085" title="CVE-2024-12085" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="rsync" version="3.1.3-6+tuxcare.els4">
          <filename>rsync_3.1.3-6+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">3e275efdd87629e7519653c66d19699692053865</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1786471358</id>
    <title>Fix CVE(s): CVE-2026-42496, CVE-2026-48962</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Archive::Tar extracted symlinks and hardlinks with
     attacker-controlled targets outside the extraction directory
     - debian/patches/fixes/CVE-2026-42496.patch: reject absolute and
       '..'-traversing link targets in Archive::Tar::_make_special_file()
       unless $Archive::Tar::INSECURE_EXTRACT_MODE is set
     - CVE-2026-42496
   * SECURITY UPDATE: arbitrary code execution in File::GlobMapper via an
     attacker-controlled output glob
     - debian/patches/fixes/CVE-2026-48962.patch: replace the eval STRING in
       File::GlobMapper::_getFiles() with explicit substitution of internal
       wildcard markers, so no part of the output glob is evaluated as Perl
     - CVE-2026-48962</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Archive::Tar extracted symlinks and hardlinks with
     attacker-controlled targets outside the extraction directory
     - debian/patches/fixes/CVE-2026-42496.patch: reject absolute and
       '..'-traversing link targets in Archive::Tar::_make_special_file()
       unless $Archive::Tar::INSECURE_EXTRACT_MODE is set
     - CVE-2026-42496
   * SECURITY UPDATE: arbitrary code execution in File::GlobMapper via an
     attacker-controlled output glob
     - debian/patches/fixes/CVE-2026-48962.patch: replace the eval STRING in
       File::GlobMapper::_getFiles() with explicit substitution of internal
       wildcard markers, so no part of the output glob is evaluated as Perl
     - CVE-2026-48962</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-11 18:02:48 UTC" />
    <updated date="2026-08-11 18:02:48 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1786471358.html" id="CLSA-2026:1786471358" title="CLSA-2026:1786471358" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-42496" id="CVE-2026-42496" title="CVE-2026-42496" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-48962" id="CVE-2026-48962" title="CVE-2026-48962" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libperl-dev" version="5.28.1-6+deb10u1+tuxcare.els5">
          <filename>libperl-dev_5.28.1-6+deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">a8bd684b2a0af46f791d2b902014bdaa92e30347</sum>
        </package>
        <package arch="amd64" name="libperl5.28" version="5.28.1-6+deb10u1+tuxcare.els5">
          <filename>libperl5.28_5.28.1-6+deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">d92800f7d04dc0f59116e618c29bd49e6e1557fd</sum>
        </package>
        <package arch="amd64" name="perl" version="5.28.1-6+deb10u1+tuxcare.els5">
          <filename>perl_5.28.1-6+deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">125891dfc7c7c0e733c71d658c5c7030001c3860</sum>
        </package>
        <package arch="amd64" name="perl-base" version="5.28.1-6+deb10u1+tuxcare.els5">
          <filename>perl-base_5.28.1-6+deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">54c6604fb6801dc0c19e8730c8ea31384a6b1cea</sum>
        </package>
        <package arch="amd64" name="perl-debug" version="5.28.1-6+deb10u1+tuxcare.els5">
          <filename>perl-debug_5.28.1-6+deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">ba1767963e28c5eea20710a299e866abed4ffe45</sum>
        </package>
        <package arch="all" name="perl-doc" version="5.28.1-6+deb10u1+tuxcare.els5">
          <filename>perl-doc_5.28.1-6+deb10u1+tuxcare.els5_all.deb</filename>
          <sum type="sha">1f569c824680ba8fcee1b9bca8d76e05358ee8de</sum>
        </package>
        <package arch="all" name="perl-modules-5.28" version="5.28.1-6+deb10u1+tuxcare.els5">
          <filename>perl-modules-5.28_5.28.1-6+deb10u1+tuxcare.els5_all.deb</filename>
          <sum type="sha">426cd7b599f65503f2d573d5167d407ce02dd6ec</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1786477676</id>
    <title>Fix CVE(s): CVE-2026-6949</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: out-of-bounds write in the internal DNS server via a
     TSIG-signed packet using DNS name compression
     - debian/patches/CVE-2026-6949.patch: record the start offset of each
       dns_res_rec while pulling it and use the last additional record's
       offset to truncate the buffer for TSIG verification, instead of
       subtracting a re-pushed TSIG record length that can exceed the packet
       and underflow packet_len into a huge memcpy() size
     - CVE-2026-6949</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: out-of-bounds write in the internal DNS server via a
     TSIG-signed packet using DNS name compression
     - debian/patches/CVE-2026-6949.patch: record the start offset of each
       dns_res_rec while pulling it and use the last additional record's
       offset to truncate the buffer for TSIG verification, instead of
       subtracting a re-pushed TSIG record length that can exceed the packet
       and underflow packet_len into a huge memcpy() size
     - CVE-2026-6949</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-11 19:48:07 UTC" />
    <updated date="2026-08-11 19:48:07 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1786477676.html" id="CLSA-2026:1786477676" title="CLSA-2026:1786477676" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-6949" id="CVE-2026-6949" title="CVE-2026-6949" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="ctdb" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els9">
          <filename>ctdb_4.9.5+dfsg-5+deb10u5+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">267f066f02c0742bacacb86b0a256f72ac7ebf31</sum>
        </package>
        <package arch="amd64" name="libnss-winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els9">
          <filename>libnss-winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">08a6994cc893876e962a4974333457e471387416</sum>
        </package>
        <package arch="amd64" name="libpam-winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els9">
          <filename>libpam-winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">3fac595a987db4dc0b4ec5a37753a66c5bd18fa2</sum>
        </package>
        <package arch="amd64" name="libsmbclient" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els9">
          <filename>libsmbclient_4.9.5+dfsg-5+deb10u5+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">ca8a6ecf1ccf27be6e2a466db2d8c18eb9ac913e</sum>
        </package>
        <package arch="amd64" name="libsmbclient-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els9">
          <filename>libsmbclient-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">fb2bb4db773a68a36980d9e01349507cf57cf76c</sum>
        </package>
        <package arch="amd64" name="libwbclient-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els9">
          <filename>libwbclient-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">8749a719e61925e3c4ef61144140ef447d788abe</sum>
        </package>
        <package arch="amd64" name="libwbclient0" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els9">
          <filename>libwbclient0_4.9.5+dfsg-5+deb10u5+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">6a601aa0cac2ed33cc4740b12ad5853409c54be7</sum>
        </package>
        <package arch="amd64" name="python-samba" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els9">
          <filename>python-samba_4.9.5+dfsg-5+deb10u5+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">d621ab16139b7a75b030d432a6471be82f7c3914</sum>
        </package>
        <package arch="amd64" name="registry-tools" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els9">
          <filename>registry-tools_4.9.5+dfsg-5+deb10u5+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">75e9d6eec10ea500a1ce3e36ebc9cef4e430ea4d</sum>
        </package>
        <package arch="amd64" name="samba" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els9">
          <filename>samba_4.9.5+dfsg-5+deb10u5+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">28cd88d8084d6d6b1b94ade6b304341ea7638807</sum>
        </package>
        <package arch="all" name="samba-common" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els9">
          <filename>samba-common_4.9.5+dfsg-5+deb10u5+tuxcare.els9_all.deb</filename>
          <sum type="sha">2df7ac02de101ce8ab261212b71069867f63898f</sum>
        </package>
        <package arch="amd64" name="samba-common-bin" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els9">
          <filename>samba-common-bin_4.9.5+dfsg-5+deb10u5+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">cd4a6d9ec8edb1dadd43692698b1402d7a2cd970</sum>
        </package>
        <package arch="amd64" name="samba-dev" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els9">
          <filename>samba-dev_4.9.5+dfsg-5+deb10u5+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">601dbbf34b2ecf1c0dacfa2cd697f54513b379c1</sum>
        </package>
        <package arch="amd64" name="samba-dsdb-modules" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els9">
          <filename>samba-dsdb-modules_4.9.5+dfsg-5+deb10u5+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">c89b955fb245bb1e8daecea96c27b1ad14a9310d</sum>
        </package>
        <package arch="amd64" name="samba-libs" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els9">
          <filename>samba-libs_4.9.5+dfsg-5+deb10u5+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">c575ff6a3499bbefec1037537d66248a1811f4af</sum>
        </package>
        <package arch="amd64" name="samba-testsuite" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els9">
          <filename>samba-testsuite_4.9.5+dfsg-5+deb10u5+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">ad32e0da3187841985fff5a4525912375d1079a7</sum>
        </package>
        <package arch="amd64" name="samba-vfs-modules" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els9">
          <filename>samba-vfs-modules_4.9.5+dfsg-5+deb10u5+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">b066717537b174f7cb86140db991cb6a7189c37a</sum>
        </package>
        <package arch="amd64" name="smbclient" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els9">
          <filename>smbclient_4.9.5+dfsg-5+deb10u5+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">9742458843efeea9e88076b823b5a2b07ebb7842</sum>
        </package>
        <package arch="amd64" name="winbind" version="2:4.9.5+dfsg-5+deb10u5+tuxcare.els9">
          <filename>winbind_4.9.5+dfsg-5+deb10u5+tuxcare.els9_amd64.deb</filename>
          <sum type="sha">903b4b6c38e6e087f561d1bf77ff2be2b4f7b77a</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1786492830</id>
    <title>Fix CVE(s): CVE-2026-13221, CVE-2026-57432</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * Fix armel build under qemu-user emulation: skip process-title and
     threaded directory-handle tests that cannot pass under qemu-arm-static
     - debian/patches/debian/armel-skip-qemu-emulation-tests.diff: guard the
       argv[0]/$0 assertions in t/op/magic.t and dist/threads/t/join.t and the
       cloned-dir-iterator assertion in t/op/threads-dirh.t on the armel
       archname (arm-linux-gnueabi*), so amd64/arm64 keep running them</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * Fix armel build under qemu-user emulation: skip process-title and
     threaded directory-handle tests that cannot pass under qemu-arm-static
     - debian/patches/debian/armel-skip-qemu-emulation-tests.diff: guard the
       argv[0]/$0 assertions in t/op/magic.t and dist/threads/t/join.t and the
       cloned-dir-iterator assertion in t/op/threads-dirh.t on the armel
       archname (arm-linux-gnueabi*), so amd64/arm64 keep running them</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-12 00:00:41 UTC" />
    <updated date="2026-08-12 00:00:41 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1786492830.html" id="CLSA-2026:1786492830" title="CLSA-2026:1786492830" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-13221" id="CVE-2026-13221" title="CVE-2026-13221" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-57432" id="CVE-2026-57432" title="CVE-2026-57432" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libperl-dev" version="5.28.1-6+deb10u1+tuxcare.els4">
          <filename>libperl-dev_5.28.1-6+deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">d8f6752a40dbeed39b539ecf59200dfa982ca0ab</sum>
        </package>
        <package arch="amd64" name="libperl5.28" version="5.28.1-6+deb10u1+tuxcare.els4">
          <filename>libperl5.28_5.28.1-6+deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">bef9b210224e999f1de329897a54877ea6a5b82d</sum>
        </package>
        <package arch="amd64" name="perl" version="5.28.1-6+deb10u1+tuxcare.els4">
          <filename>perl_5.28.1-6+deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">4e2f3021b15b5718b1ac25115e3fd7b06abaf5a7</sum>
        </package>
        <package arch="amd64" name="perl-base" version="5.28.1-6+deb10u1+tuxcare.els4">
          <filename>perl-base_5.28.1-6+deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">074bd38d2271d38c0996282081b055eff130f457</sum>
        </package>
        <package arch="amd64" name="perl-debug" version="5.28.1-6+deb10u1+tuxcare.els4">
          <filename>perl-debug_5.28.1-6+deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">cde5621083e52391e6bf77d1afbb1ff405399e6b</sum>
        </package>
        <package arch="all" name="perl-doc" version="5.28.1-6+deb10u1+tuxcare.els4">
          <filename>perl-doc_5.28.1-6+deb10u1+tuxcare.els4_all.deb</filename>
          <sum type="sha">fbf51baf24b6d4879c401b5861b2cfc7a056cd88</sum>
        </package>
        <package arch="all" name="perl-modules-5.28" version="5.28.1-6+deb10u1+tuxcare.els4">
          <filename>perl-modules-5.28_5.28.1-6+deb10u1+tuxcare.els4_all.deb</filename>
          <sum type="sha">dfad6d1598368e7a3a37ca60f8fb7b71079d950e</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1786495354</id>
    <title>Fix CVE(s): CVE-2026-12996</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Use-after-free of a pending dedicated ACK buffer when a
     TLS session is freed during session promotion or expiry
     - debian/patches/CVE-2026-12996.patch: add the check_session_buf_not_used()
       safeguard, including its ks-&gt;ack_write_buf check, and call it before
       every site in tls_multi_process() that frees or resets a session
     - CVE-2026-12996
     - the safeguard does not exist in 2.4.7, so it is introduced here already
       in its post-CVE-2026-12996 form; as a result this patch also fixes
       CVE-2026-40215, which shares the same safeguard</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Use-after-free of a pending dedicated ACK buffer when a
     TLS session is freed during session promotion or expiry
     - debian/patches/CVE-2026-12996.patch: add the check_session_buf_not_used()
       safeguard, including its ks-&gt;ack_write_buf check, and call it before
       every site in tls_multi_process() that frees or resets a session
     - CVE-2026-12996
     - the safeguard does not exist in 2.4.7, so it is introduced here already
       in its post-CVE-2026-12996 form; as a result this patch also fixes
       CVE-2026-40215, which shares the same safeguard</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-12 00:42:45 UTC" />
    <updated date="2026-08-12 00:42:45 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1786495354.html" id="CLSA-2026:1786495354" title="CLSA-2026:1786495354" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-12996" id="CVE-2026-12996" title="CVE-2026-12996" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="openvpn" version="2.4.7-1+deb10u1+tuxcare.els2">
          <filename>openvpn_2.4.7-1+deb10u1+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">c64544a8bf93472cdfd2c6af597358f4e5dc37b5</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1786553162</id>
    <title>Fix of 7 CVEs</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Denial of service in HTTP/2 - a stream could be
     removed from the count of active streams more than once, driving the
     count below the real value, so an infinite connection timeout was
     applied and connections that should have been closed stayed open
     - debian/patches/CVE-2024-34750.patch: guard each stream with an
       AtomicBoolean so that it is removed from the active stream count at
       most once, and route the decrements through the new
       decrementActiveRemoteStreamCount(Stream) helper
     - CVE-2024-34750
   * SECURITY UPDATE: Remote code execution via the write enabled default
     servlet - on a case insensitive file system a race between a read and
     a concurrent write for the same path allowed an uploaded file to be
     picked up and compiled as a JSP
     - debian/patches/CVE-2024-50379.patch: add the WebResourceLockSet
       interface and serialise reads and writes for the same resource path
       in DirResourceSet and FileResource through a per-path read/write
       lock
     - CVE-2024-50379
   * SECURITY UPDATE: Authentication bypass when a custom Jakarta
     Authentication component throws an exception without setting an HTTP
     status, leaving the response status at 200
     - debian/patches/CVE-2024-52316.patch: explicitly set a 500 status in
       authenticateJaspic() when validateRequest() throws an AuthException
     - CVE-2024-52316
   * SECURITY UPDATE: Remote code execution via the write enabled default
     servlet - the mitigation for CVE-2024-50379 was incomplete because
     the JVM global canonical file name cache could still return a stale
     result for the concurrently written path
     - debian/patches/CVE-2024-56337.patch: disable the canonical file
       name cache before a potentially exposed WebResourceSet starts and
       refuse to start it if that cannot be confirmed, add Jre12Compat and
       Jre21Compat for the per Java version cache behaviour, and pass
       -Dsun.io.useCanonCaches=false from catalina.sh
     - CVE-2024-56337
   * SECURITY UPDATE: Denial of service in HTTP/2 (MadeYouReset) - frames
     that make the server reset a stream were not counted against the
     connection overhead budget, so the CVE-2023-44487 mitigation never
     triggered
     - debian/patches/CVE-2025-48989.patch: count every RST_STREAM frame
       Tomcat sends using overheadResetFactor
     - CVE-2025-48989
   * SECURITY UPDATE: Directory traversal via the RewriteValve, with
     possible remote code execution if PUT is enabled - the rewritten URL
     was normalized while still percent encoded, so an encoded ../
     survived normalization and was decoded afterwards, letting the
     request escape into /WEB-INF/ or /META-INF/
     - debian/patches/CVE-2025-55752.patch: decode the rewritten URL
       before normalizing it, and reject the request with a 400 when
       normalization reports that the path escapes root
     - CVE-2025-55752
   * SECURITY UPDATE: Padding oracle in the cluster EncryptInterceptor -
     the interceptor accepted cipher mode and padding combinations that
     offer no protection, and the CBC modes it accepted are malleable and
     open to a padding oracle
     - debian/patches/CVE-2026-29146.patch: reject the cipher mode and
       padding combinations that offer no protection, warn for the CBC,
       CFB and OFB modes with PKCS5Padding that are kept for
       compatibility, and recognise GCM/NoPadding as the recommended
       transformation. The patch also carries the upstream partial revert
       776e12b3, without which the fix would reintroduce CVE-2026-34486
       by passing messages that failed to decrypt up the interceptor
       chain with their raw bytes. Note that, as upstream, explicit
       EncryptInterceptor configurations using a mode that offers no
       protection (NONE, ECB, PCBC, CTS, KW, KWP, CTR, and CBC, CFB or OFB
       with NoPadding) are now rejected at startup. The default
       AES/CBC/PKCS5Padding keeps working and only logs a recommendation
       to switch to AES/GCM/NoPadding
     - CVE-2026-29146</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Denial of service in HTTP/2 - a stream could be
     removed from the count of active streams more than once, driving the
     count below the real value, so an infinite connection timeout was
     applied and connections that should have been closed stayed open
     - debian/patches/CVE-2024-34750.patch: guard each stream with an
       AtomicBoolean so that it is removed from the active stream count at
       most once, and route the decrements through the new
       decrementActiveRemoteStreamCount(Stream) helper
     - CVE-2024-34750
   * SECURITY UPDATE: Remote code execution via the write enabled default
     servlet - on a case insensitive file system a race between a read and
     a concurrent write for the same path allowed an uploaded file to be
     picked up and compiled as a JSP
     - debian/patches/CVE-2024-50379.patch: add the WebResourceLockSet
       interface and serialise reads and writes for the same resource path
       in DirResourceSet and FileResource through a per-path read/write
       lock
     - CVE-2024-50379
   * SECURITY UPDATE: Authentication bypass when a custom Jakarta
     Authentication component throws an exception without setting an HTTP
     status, leaving the response status at 200
     - debian/patches/CVE-2024-52316.patch: explicitly set a 500 status in
       authenticateJaspic() when validateRequest() throws an AuthException
     - CVE-2024-52316
   * SECURITY UPDATE: Remote code execution via the write enabled default
     servlet - the mitigation for CVE-2024-50379 was incomplete because
     the JVM global canonical file name cache could still return a stale
     result for the concurrently written path
     - debian/patches/CVE-2024-56337.patch: disable the canonical file
       name cache before a potentially exposed WebResourceSet starts and
       refuse to start it if that cannot be confirmed, add Jre12Compat and
       Jre21Compat for the per Java version cache behaviour, and pass
       -Dsun.io.useCanonCaches=false from catalina.sh
     - CVE-2024-56337
   * SECURITY UPDATE: Denial of service in HTTP/2 (MadeYouReset) - frames
     that make the server reset a stream were not counted against the
     connection overhead budget, so the CVE-2023-44487 mitigation never
     triggered
     - debian/patches/CVE-2025-48989.patch: count every RST_STREAM frame
       Tomcat sends using overheadResetFactor
     - CVE-2025-48989
   * SECURITY UPDATE: Directory traversal via the RewriteValve, with
     possible remote code execution if PUT is enabled - the rewritten URL
     was normalized while still percent encoded, so an encoded ../
     survived normalization and was decoded afterwards, letting the
     request escape into /WEB-INF/ or /META-INF/
     - debian/patches/CVE-2025-55752.patch: decode the rewritten URL
       before normalizing it, and reject the request with a 400 when
       normalization reports that the path escapes root
     - CVE-2025-55752
   * SECURITY UPDATE: Padding oracle in the cluster EncryptInterceptor -
     the interceptor accepted cipher mode and padding combinations that
     offer no protection, and the CBC modes it accepted are malleable and
     open to a padding oracle
     - debian/patches/CVE-2026-29146.patch: reject the cipher mode and
       padding combinations that offer no protection, warn for the CBC,
       CFB and OFB modes with PKCS5Padding that are kept for
       compatibility, and recognise GCM/NoPadding as the recommended
       transformation. The patch also carries the upstream partial revert
       776e12b3, without which the fix would reintroduce CVE-2026-34486
       by passing messages that failed to decrypt up the interceptor
       chain with their raw bytes. Note that, as upstream, explicit
       EncryptInterceptor configurations using a mode that offers no
       protection (NONE, ECB, PCBC, CTS, KW, KWP, CTR, and CBC, CFB or OFB
       with NoPadding) are now rejected at startup. The default
       AES/CBC/PKCS5Padding keeps working and only logs a recommendation
       to switch to AES/GCM/NoPadding
     - CVE-2026-29146</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-12 16:46:19 UTC" />
    <updated date="2026-08-12 16:46:19 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1786553162.html" id="CLSA-2026:1786553162" title="CLSA-2026:1786553162" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-34750" id="CVE-2024-34750" title="CVE-2024-34750" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-50379" id="CVE-2024-50379" title="CVE-2024-50379" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-52316" id="CVE-2024-52316" title="CVE-2024-52316" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-56337" id="CVE-2024-56337" title="CVE-2024-56337" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-48989" id="CVE-2025-48989" title="CVE-2025-48989" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-55752" id="CVE-2025-55752" title="CVE-2025-55752" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-29146" id="CVE-2026-29146" title="CVE-2026-29146" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="all" name="libtomcat9-embed-java" version="9.0.31-1~deb10u12+tuxcare.els8">
          <filename>libtomcat9-embed-java_9.0.31-1~deb10u12+tuxcare.els8_all.deb</filename>
          <sum type="sha">347f35742c54669e43e58f5e728026fcef0b35b9</sum>
        </package>
        <package arch="all" name="libtomcat9-java" version="9.0.31-1~deb10u12+tuxcare.els8">
          <filename>libtomcat9-java_9.0.31-1~deb10u12+tuxcare.els8_all.deb</filename>
          <sum type="sha">9da20f5a402191711734e11029147025779019a3</sum>
        </package>
        <package arch="all" name="tomcat9" version="9.0.31-1~deb10u12+tuxcare.els8">
          <filename>tomcat9_9.0.31-1~deb10u12+tuxcare.els8_all.deb</filename>
          <sum type="sha">2c4690dcca1fc8109b48bd6e81d32ed640322b03</sum>
        </package>
        <package arch="all" name="tomcat9-admin" version="9.0.31-1~deb10u12+tuxcare.els8">
          <filename>tomcat9-admin_9.0.31-1~deb10u12+tuxcare.els8_all.deb</filename>
          <sum type="sha">7b2abaeb4ae4970c2c538605be4550ae5aa573db</sum>
        </package>
        <package arch="all" name="tomcat9-common" version="9.0.31-1~deb10u12+tuxcare.els8">
          <filename>tomcat9-common_9.0.31-1~deb10u12+tuxcare.els8_all.deb</filename>
          <sum type="sha">2fe5ef567d77ee972baa2216827d3b5be000fb52</sum>
        </package>
        <package arch="all" name="tomcat9-docs" version="9.0.31-1~deb10u12+tuxcare.els8">
          <filename>tomcat9-docs_9.0.31-1~deb10u12+tuxcare.els8_all.deb</filename>
          <sum type="sha">6a849c5a3000461d482af69d499845f7d56212d6</sum>
        </package>
        <package arch="all" name="tomcat9-examples" version="9.0.31-1~deb10u12+tuxcare.els8">
          <filename>tomcat9-examples_9.0.31-1~deb10u12+tuxcare.els8_all.deb</filename>
          <sum type="sha">295038a9cd820f1281f67bb75288b22b6dc2678e</sum>
        </package>
        <package arch="all" name="tomcat9-user" version="9.0.31-1~deb10u12+tuxcare.els8">
          <filename>tomcat9-user_9.0.31-1~deb10u12+tuxcare.els8_all.deb</filename>
          <sum type="sha">c60a6d436bbf3b5abe34b3de40f030bd311421bf</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1786119141</id>
    <title>Fix of 5 CVEs</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: stale custom cookie host causes cookie leak
     - debian/patches/CVE-2026-6276.patch: clear the remembered custom
       Host: name at the start of every request in lib/http.c.
     - CVE-2026-6276
   * SECURITY UPDATE: wrong STARTTLS connection reuse
     - debian/patches/CVE-2026-8286.patch: require a matching SSL
       configuration when reusing a connection for a transfer that may
       upgrade to TLS in lib/url.c.
     - CVE-2026-8286
   * SECURITY UPDATE: env-set cross-proxy Digest auth state leak
     - debian/patches/CVE-2026-8927.patch: flush the proxy Digest state
       when the proxy read from the environment changes in lib/url.c,
       lib/urldata.h.
     - CVE-2026-8927
   * SECURITY UPDATE: incomplete mTLS config in connection reuse and TLS
     session cache
     - debian/patches/CVE-2026-8932.patch: include the client private key
       options in the primary SSL config so connection reuse and the TLS
       session cache compare them in lib/url.c, lib/urldata.h,
       lib/vtls/vtls.c.
     - CVE-2026-8932
   * SECURITY UPDATE: HTTP/2 push headers memory leak
     - debian/patches/CVE-2024-2398.patch: free the whole set of push
       headers on the array-growth failure path in lib/http2.c.
     - CVE-2024-2398</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: stale custom cookie host causes cookie leak
     - debian/patches/CVE-2026-6276.patch: clear the remembered custom
       Host: name at the start of every request in lib/http.c.
     - CVE-2026-6276
   * SECURITY UPDATE: wrong STARTTLS connection reuse
     - debian/patches/CVE-2026-8286.patch: require a matching SSL
       configuration when reusing a connection for a transfer that may
       upgrade to TLS in lib/url.c.
     - CVE-2026-8286
   * SECURITY UPDATE: env-set cross-proxy Digest auth state leak
     - debian/patches/CVE-2026-8927.patch: flush the proxy Digest state
       when the proxy read from the environment changes in lib/url.c,
       lib/urldata.h.
     - CVE-2026-8927
   * SECURITY UPDATE: incomplete mTLS config in connection reuse and TLS
     session cache
     - debian/patches/CVE-2026-8932.patch: include the client private key
       options in the primary SSL config so connection reuse and the TLS
       session cache compare them in lib/url.c, lib/urldata.h,
       lib/vtls/vtls.c.
     - CVE-2026-8932
   * SECURITY UPDATE: HTTP/2 push headers memory leak
     - debian/patches/CVE-2024-2398.patch: free the whole set of push
       headers on the array-growth failure path in lib/http2.c.
     - CVE-2024-2398</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-13 02:39:13 UTC" />
    <updated date="2026-08-13 02:39:13 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1786119141.html" id="CLSA-2026:1786119141" title="CLSA-2026:1786119141" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-2398" id="CVE-2024-2398" title="CVE-2024-2398" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-6276" id="CVE-2026-6276" title="CVE-2026-6276" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-8286" id="CVE-2026-8286" title="CVE-2026-8286" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-8927" id="CVE-2026-8927" title="CVE-2026-8927" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-8932" id="CVE-2026-8932" title="CVE-2026-8932" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="curl" version="7.64.0-4+deb10u9+tuxcare.els5">
          <filename>curl_7.64.0-4+deb10u9+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">4cf573e65b96ff075057021602dde1579b7f8f2b</sum>
        </package>
        <package arch="amd64" name="libcurl3-gnutls" version="7.64.0-4+deb10u9+tuxcare.els5">
          <filename>libcurl3-gnutls_7.64.0-4+deb10u9+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">8d37a066d5fa3ba729fdd16a928d76ad8f49ff54</sum>
        </package>
        <package arch="amd64" name="libcurl3-nss" version="7.64.0-4+deb10u9+tuxcare.els5">
          <filename>libcurl3-nss_7.64.0-4+deb10u9+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">6e2c5cb910e3ef1284b435dbdb09f7ecd4f9658e</sum>
        </package>
        <package arch="amd64" name="libcurl4" version="7.64.0-4+deb10u9+tuxcare.els5">
          <filename>libcurl4_7.64.0-4+deb10u9+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">6296d6e0c09caae5bc19ad03dd1e38543f0c3193</sum>
        </package>
        <package arch="all" name="libcurl4-doc" version="7.64.0-4+deb10u9+tuxcare.els5">
          <filename>libcurl4-doc_7.64.0-4+deb10u9+tuxcare.els5_all.deb</filename>
          <sum type="sha">3220ab7988a68ce62cfb9e939e2e6c6355d4b6b2</sum>
        </package>
        <package arch="amd64" name="libcurl4-gnutls-dev" version="7.64.0-4+deb10u9+tuxcare.els5">
          <filename>libcurl4-gnutls-dev_7.64.0-4+deb10u9+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">ee410e6915c253059d9a920f18c96b26bc5efc0b</sum>
        </package>
        <package arch="amd64" name="libcurl4-nss-dev" version="7.64.0-4+deb10u9+tuxcare.els5">
          <filename>libcurl4-nss-dev_7.64.0-4+deb10u9+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">f4c2ccc07d1f1319c04998703cc07852e1ffd9b3</sum>
        </package>
        <package arch="amd64" name="libcurl4-openssl-dev" version="7.64.0-4+deb10u9+tuxcare.els5">
          <filename>libcurl4-openssl-dev_7.64.0-4+deb10u9+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">bf677f47222a3712beb9e48a440a73632dd70407</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1786603529</id>
    <title>Fix CVE(s): CVE-2026-17543, CVE-2026-7260</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: unbounded recursion via circular symlinks in phar archives
     - debian/patches/CVE-2026-7260.patch: unbounded recursion via circular symlinks in phar archives
     - CVE-2026-7260
   * SECURITY UPDATE: SQL injection in ext/pgsql via E'...' backslash breakout
     - debian/patches/CVE-2026-17543.patch: SQL injection in ext/pgsql via E'...' backslash breakout
     - CVE-2026-17543</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: unbounded recursion via circular symlinks in phar archives
     - debian/patches/CVE-2026-7260.patch: unbounded recursion via circular symlinks in phar archives
     - CVE-2026-7260
   * SECURITY UPDATE: SQL injection in ext/pgsql via E'...' backslash breakout
     - debian/patches/CVE-2026-17543.patch: SQL injection in ext/pgsql via E'...' backslash breakout
     - CVE-2026-17543</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-13 06:45:40 UTC" />
    <updated date="2026-08-13 06:45:40 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1786603529.html" id="CLSA-2026:1786603529" title="CLSA-2026:1786603529" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-17543" id="CVE-2026-17543" title="CVE-2026-17543" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-7260" id="CVE-2026-7260" title="CVE-2026-7260" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libapache2-mod-php7.3" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>libapache2-mod-php7.3_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">e4f6aa8ea9360e0d42906b98bea7137fcc17c7c5</sum>
        </package>
        <package arch="amd64" name="libphp7.3-embed" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>libphp7.3-embed_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">1e20d4d82136f1a29fcc999b2f4b7004528ce5b0</sum>
        </package>
        <package arch="all" name="php7.3" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3_7.3.31-1~deb10u7+tuxcare.els8_all.deb</filename>
          <sum type="sha">43da86a29bc35dec9a455cd514f2a9f23e0130cc</sum>
        </package>
        <package arch="amd64" name="php7.3-bcmath" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-bcmath_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">84c1979ede1b50203e45c0d14522324c58c2cb0b</sum>
        </package>
        <package arch="amd64" name="php7.3-bz2" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-bz2_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">382976960f7b148104ec89d499a92f38b0b554d7</sum>
        </package>
        <package arch="amd64" name="php7.3-cgi" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-cgi_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">c03d0012ec2efdc84b8c3e94f0c0bf0bc81a7adc</sum>
        </package>
        <package arch="amd64" name="php7.3-cli" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-cli_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">81844e3c0263ca0f6171f0787a6c7c8285feda2c</sum>
        </package>
        <package arch="amd64" name="php7.3-common" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-common_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">9ba0d011e7de23a03901d07ca3d1850b572b8abf</sum>
        </package>
        <package arch="amd64" name="php7.3-curl" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-curl_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">30e7bbacda72f391cd3483a22e117a4b60100e07</sum>
        </package>
        <package arch="amd64" name="php7.3-dba" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-dba_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">249329f2f0fb419ad6e5098318e9f556974aba5f</sum>
        </package>
        <package arch="amd64" name="php7.3-dev" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-dev_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">78487dbcd0eba041d542305b8dc40fe2f3dc4602</sum>
        </package>
        <package arch="amd64" name="php7.3-enchant" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-enchant_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">b490b53fb318a6a4b9254cb009511a1dcb1bf4bc</sum>
        </package>
        <package arch="amd64" name="php7.3-fpm" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-fpm_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">11c87d93bfa1cd22c20d67940c11e4f5e2b6225b</sum>
        </package>
        <package arch="amd64" name="php7.3-gd" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-gd_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">f9969798bc908bf127da6c513da192bd70e1c4ed</sum>
        </package>
        <package arch="amd64" name="php7.3-gmp" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-gmp_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">3d080c8f94b7d4616fc8d6333664b577abeeca14</sum>
        </package>
        <package arch="amd64" name="php7.3-imap" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-imap_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">0493308126ba0edb9e6b8de384f25e295aa0d12e</sum>
        </package>
        <package arch="amd64" name="php7.3-interbase" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-interbase_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">bf0e4a8647f586acecf14453c04dfefa3bb55569</sum>
        </package>
        <package arch="amd64" name="php7.3-intl" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-intl_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">184f5eea05e5779c5cfdb6b843573e3177549b70</sum>
        </package>
        <package arch="amd64" name="php7.3-json" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-json_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">68dd1f4d85c58ff0bffd8ff335c09736412c53de</sum>
        </package>
        <package arch="amd64" name="php7.3-ldap" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-ldap_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">824a93989160eee22786f4031868e0743630d5a3</sum>
        </package>
        <package arch="amd64" name="php7.3-mbstring" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-mbstring_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">26a59ea73096786ca7016fac78bb192ee0a892e7</sum>
        </package>
        <package arch="amd64" name="php7.3-mysql" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-mysql_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">eb1b90037696ef2b792ea4e1a0a62ac9c40975ee</sum>
        </package>
        <package arch="amd64" name="php7.3-odbc" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-odbc_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">ec58a3e28da8d49f6fb2d48a66a295944e084be0</sum>
        </package>
        <package arch="amd64" name="php7.3-opcache" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-opcache_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">2627ace5021db050e5a7db4977cec5e96f2b674c</sum>
        </package>
        <package arch="amd64" name="php7.3-pgsql" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-pgsql_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">5d52112664a7514f3ab316516274c9af4ec59f45</sum>
        </package>
        <package arch="amd64" name="php7.3-phpdbg" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-phpdbg_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">3ccf5d7d00e46db5af1e6d6db7162a077077f726</sum>
        </package>
        <package arch="amd64" name="php7.3-pspell" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-pspell_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">ca5424ccca05f942b3bb00dde5154a8715f71076</sum>
        </package>
        <package arch="amd64" name="php7.3-readline" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-readline_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">6eb42b143aedd3986f6ace24973510093c1d8db9</sum>
        </package>
        <package arch="amd64" name="php7.3-recode" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-recode_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">d9ce651c511df5787d117c0736bcece63d0cf086</sum>
        </package>
        <package arch="amd64" name="php7.3-snmp" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-snmp_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">a57333869c4efbe605a8195421256ba931019f4f</sum>
        </package>
        <package arch="amd64" name="php7.3-soap" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-soap_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">deac9dda580547445d2b337e14238ef774c9c25b</sum>
        </package>
        <package arch="amd64" name="php7.3-sqlite3" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-sqlite3_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">d92d705276129b4b6d5402e2aa5c8f89f3860887</sum>
        </package>
        <package arch="amd64" name="php7.3-sybase" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-sybase_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">0cfd1f46e2bd86ff4ecea11f13df938d2a0e35c3</sum>
        </package>
        <package arch="amd64" name="php7.3-tidy" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-tidy_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">2cdaeea27b1bcebf617a84a4a9d3139b4c6372c4</sum>
        </package>
        <package arch="amd64" name="php7.3-xml" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-xml_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">52eadd52259772a7b71714b6a131b0de4198fce4</sum>
        </package>
        <package arch="amd64" name="php7.3-xmlrpc" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-xmlrpc_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">47df60f8d85cb2d581458c898d1346aca9fc2e7b</sum>
        </package>
        <package arch="all" name="php7.3-xsl" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-xsl_7.3.31-1~deb10u7+tuxcare.els8_all.deb</filename>
          <sum type="sha">708639bb90d315c71a523c7e63ab468e6ac638ae</sum>
        </package>
        <package arch="amd64" name="php7.3-zip" version="7.3.31-1~deb10u7+tuxcare.els8">
          <filename>php7.3-zip_7.3.31-1~deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">082577f19a84a8d085a36af4ad6231668bc715da</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1786976393</id>
    <title>Fix CVE(s): CVE-2026-72522</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Out-of-bounds read and resultant infinite loop
     because low surrogates are treated the same as high surrogates in
     the *_toUtf16 functions (libexpat before 2.8.3)
     - debian/patches/CVE-2026-72522.patch: mask the high byte with 0xFC
       instead of 0xF8 so the split-surrogate guard in
       DEFINE_UTF16_TO_UTF16 matches only genuine high surrogates
       (0xD800-0xDBFF) and no longer accepts low ones (0xDC00-0xDFFF);
       also carries upstream's regression test into tests/runtests.c
       (2.2.6 has no tests/misc_tests.c), which exercises the wide
       -DXML_UNICODE build only
     - CVE-2026-72522</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Out-of-bounds read and resultant infinite loop
     because low surrogates are treated the same as high surrogates in
     the *_toUtf16 functions (libexpat before 2.8.3)
     - debian/patches/CVE-2026-72522.patch: mask the high byte with 0xFC
       instead of 0xF8 so the split-surrogate guard in
       DEFINE_UTF16_TO_UTF16 matches only genuine high surrogates
       (0xD800-0xDBFF) and no longer accepts low ones (0xDC00-0xDFFF);
       also carries upstream's regression test into tests/runtests.c
       (2.2.6 has no tests/misc_tests.c), which exercises the wide
       -DXML_UNICODE build only
     - CVE-2026-72522</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-17 14:20:05 UTC" />
    <updated date="2026-08-17 14:20:05 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1786976393.html" id="CLSA-2026:1786976393" title="CLSA-2026:1786976393" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-72522" id="CVE-2026-72522" title="CVE-2026-72522" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="expat" version="2.2.6-2+deb10u7+tuxcare.els8">
          <filename>expat_2.2.6-2+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">2111f5b6848cefc25fae6380fa9897d55a01c2e8</sum>
        </package>
        <package arch="amd64" name="libexpat1" version="2.2.6-2+deb10u7+tuxcare.els8">
          <filename>libexpat1_2.2.6-2+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">74717f1b2f56f78ec94de50463c43b7f1f040c81</sum>
        </package>
        <package arch="amd64" name="libexpat1-dev" version="2.2.6-2+deb10u7+tuxcare.els8">
          <filename>libexpat1-dev_2.2.6-2+deb10u7+tuxcare.els8_amd64.deb</filename>
          <sum type="sha">aa6f6ba27598366ed9a72bbc548ad89341970ef9</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1787062482</id>
    <title>Fix CVE(s): CVE-2026-38753, CVE-2026-38754</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: use-after-free in the awk sub()/gsub()/gensub()
     replacement string
     - debian/patches/CVE-2026-38753.patch: awk: copy the replacement string
       before evaluating the regex argument in awk_sub()
     - CVE-2026-38753
   * SECURITY UPDATE: out-of-bounds read in the ash IFS splitting code
     - debian/patches/CVE-2026-38754.patch: ash: release stale IFS region
       state when an expansion error is caught in redirectsafe()
     - CVE-2026-38754</description>
    <severity>Moderate</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: use-after-free in the awk sub()/gsub()/gensub()
     replacement string
     - debian/patches/CVE-2026-38753.patch: awk: copy the replacement string
       before evaluating the regex argument in awk_sub()
     - CVE-2026-38753
   * SECURITY UPDATE: out-of-bounds read in the ash IFS splitting code
     - debian/patches/CVE-2026-38754.patch: ash: release stale IFS region
       state when an expansion error is caught in redirectsafe()
     - CVE-2026-38754</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-18 14:14:55 UTC" />
    <updated date="2026-08-18 14:14:55 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1787062482.html" id="CLSA-2026:1787062482" title="CLSA-2026:1787062482" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-38753" id="CVE-2026-38753" title="CVE-2026-38753" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-38754" id="CVE-2026-38754" title="CVE-2026-38754" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="busybox" version="1:1.30.1-4+tuxcare.els4">
          <filename>busybox_1.30.1-4+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">3b62e01b41ae44d2ed81ebf9ef452af8af5aa16e</sum>
        </package>
        <package arch="amd64" name="busybox-static" version="1:1.30.1-4+tuxcare.els4">
          <filename>busybox-static_1.30.1-4+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">b0bc97bbf1e0d75bb8fe7f88d77b2062f9d5f404</sum>
        </package>
        <package arch="all" name="busybox-syslogd" version="1:1.30.1-4+tuxcare.els4">
          <filename>busybox-syslogd_1.30.1-4+tuxcare.els4_all.deb</filename>
          <sum type="sha">0d9610d0bbd788f87e2f8a7c10abe7d260373dd9</sum>
        </package>
        <package arch="amd64" name="udhcpc" version="1:1.30.1-4+tuxcare.els4">
          <filename>udhcpc_1.30.1-4+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">0d15d15ce5d2852b9b859b2abbe5ddf9094fcced</sum>
        </package>
        <package arch="amd64" name="udhcpd" version="1:1.30.1-4+tuxcare.els4">
          <filename>udhcpd_1.30.1-4+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">0833b8442e38fa1f6a74ca0887cbaaabfbfef5fd</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1787063229</id>
    <title>Fix CVE(s): CVE-2025-8732, CVE-2026-0989, CVE-2026-0990, CVE-2026-0992</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: uncontrolled recursion in SGML catalog parsing
     - debian/patches/CVE-2025-8732.patch: thread a depth counter through
       xmlParseSGMLCatalog() and xmlExpandCatalog() in catalog.c and bail out
       past MAX_CATAL_DEPTH, and register expanded catalog filenames in the
       SGML hash table before recursing so a repeated CATALOG directive is
       only followed once, to prevent stack exhaustion and exponential
       re-parsing on self-referencing SGML CATALOG entries. Add test files
       result/catalogs/recursive, test/catalogs/recursive.script and
       test/catalogs/recursive.sgml
     - CVE-2025-8732
   * SECURITY UPDATE: uncontrolled recursion in the RelaxNG parser via nested
     schema includes
     - debian/patches/CVE-2026-0989.patch: add an include depth limit to the
       RelaxNG parser context in relaxng.c, defaulting to 1000 and overridable
       via the RNG_INCLUDE_LIMIT environment variable or the new
       xmlRelaxParserSetIncLImit() entry point in include/libxml/relaxng.h, and
       make xmlRelaxNGIncludePush() failures propagate. Add coverage in
       runtest.c and test/relaxng/include/include-limit*.rng
     - debian/libxml2.symbols: add the new xmlRelaxParserSetIncLImit symbol
     - CVE-2026-0989
   * SECURITY UPDATE: uncontrolled recursion in XML catalog URI resolution
     - debian/patches/CVE-2026-0990.patch: add a MAX_CATAL_DEPTH guard to
       xmlCatalogListXMLResolveURI() in catalog.c and stop clobbering the
       catalog entry used for depth bookkeeping while walking the entry list,
       to prevent stack exhaustion on a self-referencing delegateURI entry
     - CVE-2026-0990
   * SECURITY UPDATE: uncontrolled resource consumption via repeated
     nextCatalog entries
     - debian/patches/CVE-2026-0992.patch: ignore duplicate nextCatalog
       entries in xmlParseXMLCatalogNode() in catalog.c, to prevent redundant
       exponential traversal of catalog chains. Guard the new loop against a
       NULL entry so a nextCatalog element without a 'catalog' attribute is
       still skipped with an error instead of crashing
     - CVE-2026-0992</description>
    <severity>Moderate</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: uncontrolled recursion in SGML catalog parsing
     - debian/patches/CVE-2025-8732.patch: thread a depth counter through
       xmlParseSGMLCatalog() and xmlExpandCatalog() in catalog.c and bail out
       past MAX_CATAL_DEPTH, and register expanded catalog filenames in the
       SGML hash table before recursing so a repeated CATALOG directive is
       only followed once, to prevent stack exhaustion and exponential
       re-parsing on self-referencing SGML CATALOG entries. Add test files
       result/catalogs/recursive, test/catalogs/recursive.script and
       test/catalogs/recursive.sgml
     - CVE-2025-8732
   * SECURITY UPDATE: uncontrolled recursion in the RelaxNG parser via nested
     schema includes
     - debian/patches/CVE-2026-0989.patch: add an include depth limit to the
       RelaxNG parser context in relaxng.c, defaulting to 1000 and overridable
       via the RNG_INCLUDE_LIMIT environment variable or the new
       xmlRelaxParserSetIncLImit() entry point in include/libxml/relaxng.h, and
       make xmlRelaxNGIncludePush() failures propagate. Add coverage in
       runtest.c and test/relaxng/include/include-limit*.rng
     - debian/libxml2.symbols: add the new xmlRelaxParserSetIncLImit symbol
     - CVE-2026-0989
   * SECURITY UPDATE: uncontrolled recursion in XML catalog URI resolution
     - debian/patches/CVE-2026-0990.patch: add a MAX_CATAL_DEPTH guard to
       xmlCatalogListXMLResolveURI() in catalog.c and stop clobbering the
       catalog entry used for depth bookkeeping while walking the entry list,
       to prevent stack exhaustion on a self-referencing delegateURI entry
     - CVE-2026-0990
   * SECURITY UPDATE: uncontrolled resource consumption via repeated
     nextCatalog entries
     - debian/patches/CVE-2026-0992.patch: ignore duplicate nextCatalog
       entries in xmlParseXMLCatalogNode() in catalog.c, to prevent redundant
       exponential traversal of catalog chains. Guard the new loop against a
       NULL entry so a nextCatalog element without a 'catalog' attribute is
       still skipped with an error instead of crashing
     - CVE-2026-0992</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-18 14:27:22 UTC" />
    <updated date="2026-08-18 14:27:22 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1787063229.html" id="CLSA-2026:1787063229" title="CLSA-2026:1787063229" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-8732" id="CVE-2025-8732" title="CVE-2025-8732" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-0989" id="CVE-2026-0989" title="CVE-2026-0989" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-0990" id="CVE-2026-0990" title="CVE-2026-0990" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-0992" id="CVE-2026-0992" title="CVE-2026-0992" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libxml2" version="2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els7">
          <filename>libxml2_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">6cd3ff1e8c408b493a74d7151ce10e7b57e9801b</sum>
        </package>
        <package arch="amd64" name="libxml2-dev" version="2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els7">
          <filename>libxml2-dev_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">24fe054a0289a0cd27c7f26f997afbc76ebb1b8c</sum>
        </package>
        <package arch="all" name="libxml2-doc" version="2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els7">
          <filename>libxml2-doc_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els7_all.deb</filename>
          <sum type="sha">700b824d2f9dbf56636ebf179a60b2ed4f6de4b4</sum>
        </package>
        <package arch="amd64" name="libxml2-utils" version="2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els7">
          <filename>libxml2-utils_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">e653e8149b7b0c222b0a6046a73e4902d454b9b9</sum>
        </package>
        <package arch="amd64" name="python-libxml2" version="2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els7">
          <filename>python-libxml2_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">772763a25ba179b4083a478b46c1d3173addd604</sum>
        </package>
        <package arch="amd64" name="python3-libxml2" version="2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els7">
          <filename>python3-libxml2_2.9.10+dfsg-5ubuntu0.20.04.10+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">08f71130fb7dde6e2926dd23e23c0892386e2f33</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1787064466</id>
    <title>Fix CVE(s): CVE-2026-40176, CVE-2026-40261</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * Non-maintainer upload by the TuxCare ELS team.
   * CVE-2026-40261: Prevent a command injection vulnerability in
     Perforce::syncCodeBase(), which appended the source reference to the
     'p4 sync -f' command without escaping. Package metadata served by a
     malicious or compromised Composer repository could inject shell
     metacharacters, leading to command execution even when Perforce is not
     installed.
     - debian/patches/0018-CVE-2026-40261.patch
   * CVE-2026-40176: Prevent a command injection vulnerability in
     Perforce::generateP4Command(), which interpolated the Perforce
     connection parameters (user, client, port) into the 'p4' command line
     without escaping. A malicious composer.json declaring a Perforce VCS
     repository could inject shell metacharacters, leading to command
     execution even when Perforce is not installed. Also backport the
     prerequisite upstream fix for Perforce::connectClient(), which passed
     the client spec path through the shell redirection of the same command
     line with only spaces escaped.
     - debian/patches/0019-CVE-2026-40176.patch</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * Non-maintainer upload by the TuxCare ELS team.
   * CVE-2026-40261: Prevent a command injection vulnerability in
     Perforce::syncCodeBase(), which appended the source reference to the
     'p4 sync -f' command without escaping. Package metadata served by a
     malicious or compromised Composer repository could inject shell
     metacharacters, leading to command execution even when Perforce is not
     installed.
     - debian/patches/0018-CVE-2026-40261.patch
   * CVE-2026-40176: Prevent a command injection vulnerability in
     Perforce::generateP4Command(), which interpolated the Perforce
     connection parameters (user, client, port) into the 'p4' command line
     without escaping. A malicious composer.json declaring a Perforce VCS
     repository could inject shell metacharacters, leading to command
     execution even when Perforce is not installed. Also backport the
     prerequisite upstream fix for Perforce::connectClient(), which passed
     the client spec path through the shell redirection of the same command
     line with only spaces escaped.
     - debian/patches/0019-CVE-2026-40176.patch</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-18 14:47:57 UTC" />
    <updated date="2026-08-18 14:47:57 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1787064466.html" id="CLSA-2026:1787064466" title="CLSA-2026:1787064466" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-40176" id="CVE-2026-40176" title="CVE-2026-40176" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-40261" id="CVE-2026-40261" title="CVE-2026-40261" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="all" name="composer" version="1.8.4-1+deb10u4+tuxcare.els1">
          <filename>composer_1.8.4-1+deb10u4+tuxcare.els1_all.deb</filename>
          <sum type="sha">8a4cc08e4fa3b5b6b4284a4fd2a9183b375028f0</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1787093019</id>
    <title>Fix CVE(s): CVE-2026-1519</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: a resolver performing DNSSEC validation could consume excessive CPU on a maliciously crafted zone (unbounded NSEC3 iterations when validating referrals to unsigned delegations)
     - debian/patches/CVE-2026-1519.patch: a resolver performing DNSSEC validation could consume excessive CPU on a maliciously crafted zone (unbounded NSEC3 iterations when validating referrals to unsigned delegations)
     - CVE-2026-1519
   * Build the lib/dns "gen" host tool with large-file support to fix an
     armel FTBFS: "gen" scans the rdata directories with a non-LFS readdir(),
     which aborts with EOVERFLOW on 64-bit inodes/offsets on 32-bit
     architectures.  next_file() in lib/dns/gen-unix.h treats the resulting
     NULL as end-of-directory, so the scan was silently truncated and "gen"
     emitted an incomplete include/dns/rdatastruct.h.
     - debian/patches/gen-build-largefile-source.patch</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: a resolver performing DNSSEC validation could consume excessive CPU on a maliciously crafted zone (unbounded NSEC3 iterations when validating referrals to unsigned delegations)
     - debian/patches/CVE-2026-1519.patch: a resolver performing DNSSEC validation could consume excessive CPU on a maliciously crafted zone (unbounded NSEC3 iterations when validating referrals to unsigned delegations)
     - CVE-2026-1519
   * Build the lib/dns "gen" host tool with large-file support to fix an
     armel FTBFS: "gen" scans the rdata directories with a non-LFS readdir(),
     which aborts with EOVERFLOW on 64-bit inodes/offsets on 32-bit
     architectures.  next_file() in lib/dns/gen-unix.h treats the resulting
     NULL as end-of-directory, so the scan was silently truncated and "gen"
     emitted an incomplete include/dns/rdatastruct.h.
     - debian/patches/gen-build-largefile-source.patch</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-18 22:43:49 UTC" />
    <updated date="2026-08-18 22:43:49 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1787093019.html" id="CLSA-2026:1787093019" title="CLSA-2026:1787093019" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-1519" id="CVE-2026-1519" title="CVE-2026-1519" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="bind9" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4">
          <filename>bind9_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">feb6bc6049d2a0f086de002192db9dbb47dc0d4c</sum>
        </package>
        <package arch="all" name="bind9-doc" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4">
          <filename>bind9-doc_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4_all.deb</filename>
          <sum type="sha">21557f844ce7774c74704b5b15e7b1c18eb5a0d5</sum>
        </package>
        <package arch="amd64" name="bind9-host" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4">
          <filename>bind9-host_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">bb4017ecf3475487e0ca3a5fb310fa0323a78d7b</sum>
        </package>
        <package arch="amd64" name="bind9utils" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4">
          <filename>bind9utils_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">cccf3b76ab728fee6931d1f1f21475684583d2f7</sum>
        </package>
        <package arch="amd64" name="dnsutils" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4">
          <filename>dnsutils_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">b2b6804885646561480c72fb241ffaffd2389df6</sum>
        </package>
        <package arch="amd64" name="libbind-dev" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4">
          <filename>libbind-dev_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">fe7d63d3536b0bfbbd77e4ab9a51f8f3c1d30b64</sum>
        </package>
        <package arch="amd64" name="libbind-export-dev" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4">
          <filename>libbind-export-dev_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">39fa7aec9cd76101f5e4018598b1f9aeba6a2c70</sum>
        </package>
        <package arch="amd64" name="libbind9-161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4">
          <filename>libbind9-161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">8c175788966255f03b433f5808ad0b3a223ab24d</sum>
        </package>
        <package arch="amd64" name="libdns-export1104" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4">
          <filename>libdns-export1104_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">82c1eb6d7da49935410c14815a4414cc1ed88d10</sum>
        </package>
        <package arch="amd64" name="libdns1104" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4">
          <filename>libdns1104_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">ddc324ed011c5d57f4c2ff666d4e34695b1cd707</sum>
        </package>
        <package arch="amd64" name="libirs-export161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4">
          <filename>libirs-export161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">506836dc789a2dd08d490f9dfeabf43875f9cd81</sum>
        </package>
        <package arch="amd64" name="libirs161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4">
          <filename>libirs161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">a9b3cec1ba4051a358967e47178240b8087e9449</sum>
        </package>
        <package arch="amd64" name="libisc-export1100" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4">
          <filename>libisc-export1100_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">b37f129c8479c41d521c085958c451d3a49579cc</sum>
        </package>
        <package arch="amd64" name="libisc1100" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4">
          <filename>libisc1100_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">c374e2f9b1c4b3207adb9cd0515267867f40b16e</sum>
        </package>
        <package arch="amd64" name="libisccc-export161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4">
          <filename>libisccc-export161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">6359692cf2e5e97ff6e1f961ef08eabaf321f9e0</sum>
        </package>
        <package arch="amd64" name="libisccc161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4">
          <filename>libisccc161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">364100ff231e3be5239d2c641abf4a7dc0bae3a0</sum>
        </package>
        <package arch="amd64" name="libisccfg-export163" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4">
          <filename>libisccfg-export163_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">a8f20d742327962e261cdff9e8234ec26a7ecab0</sum>
        </package>
        <package arch="amd64" name="libisccfg163" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4">
          <filename>libisccfg163_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">cf1334ba3ebd0f2009e23122273629122d55525d</sum>
        </package>
        <package arch="amd64" name="liblwres161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4">
          <filename>liblwres161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">aceb16908be04702e38f02cce805a202597a01b0</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1787062977</id>
    <title>Fix of 6 CVEs</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Single-byte buffer overflow in SOCKSv4a connect messages (SOCKS4_CONN_MSG_LEN did not account for the trailing NUL in gio/gsocks4aproxy.c)
     - debian/patches/CVE-2024-52533.patch: Single-byte buffer overflow in SOCKSv4a connect messages (SOCKS4_CONN_MSG_LEN did not account for the trailing NUL in gio/gsocks4aproxy.c)
     - CVE-2024-52533
   * SECURITY UPDATE: Heap buffer overflow via integer overflow in the escaped-length calculation in g_escape_uri_string() in glib/gconvert.c
     - debian/patches/CVE-2025-13601.patch: Heap buffer overflow via integer overflow in the escaped-length calculation in g_escape_uri_string() in glib/gconvert.c
     - CVE-2025-13601</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Single-byte buffer overflow in SOCKSv4a connect messages (SOCKS4_CONN_MSG_LEN did not account for the trailing NUL in gio/gsocks4aproxy.c)
     - debian/patches/CVE-2024-52533.patch: Single-byte buffer overflow in SOCKSv4a connect messages (SOCKS4_CONN_MSG_LEN did not account for the trailing NUL in gio/gsocks4aproxy.c)
     - CVE-2024-52533
   * SECURITY UPDATE: Heap buffer overflow via integer overflow in the escaped-length calculation in g_escape_uri_string() in glib/gconvert.c
     - debian/patches/CVE-2025-13601.patch: Heap buffer overflow via integer overflow in the escaped-length calculation in g_escape_uri_string() in glib/gconvert.c
     - CVE-2025-13601</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-19 18:24:40 UTC" />
    <updated date="2026-08-19 18:24:40 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1787062977.html" id="CLSA-2026:1787062977" title="CLSA-2026:1787062977" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-52533" id="CVE-2024-52533" title="CVE-2024-52533" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-13601" id="CVE-2025-13601" title="CVE-2025-13601" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-58010" id="CVE-2026-58010" title="CVE-2026-58010" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-58011" id="CVE-2026-58011" title="CVE-2026-58011" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-58012" id="CVE-2026-58012" title="CVE-2026-58012" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-58013" id="CVE-2026-58013" title="CVE-2026-58013" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libglib2.0-0" version="2.58.3-2+deb10u6+tuxcare.els6">
          <filename>libglib2.0-0_2.58.3-2+deb10u6+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">4c28648f384ee804f90e7cb2c8a806faa3bd7bd3</sum>
        </package>
        <package arch="amd64" name="libglib2.0-bin" version="2.58.3-2+deb10u6+tuxcare.els6">
          <filename>libglib2.0-bin_2.58.3-2+deb10u6+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">715f34d494e103db1d8b4ca25de797437f617748</sum>
        </package>
        <package arch="all" name="libglib2.0-data" version="2.58.3-2+deb10u6+tuxcare.els6">
          <filename>libglib2.0-data_2.58.3-2+deb10u6+tuxcare.els6_all.deb</filename>
          <sum type="sha">bc4f67cdde6aebf850b289446f0ced07d3df28ae</sum>
        </package>
        <package arch="amd64" name="libglib2.0-dev" version="2.58.3-2+deb10u6+tuxcare.els6">
          <filename>libglib2.0-dev_2.58.3-2+deb10u6+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">e7c2da5ef24ff20ee752e6a6acad733b2e4eab82</sum>
        </package>
        <package arch="amd64" name="libglib2.0-dev-bin" version="2.58.3-2+deb10u6+tuxcare.els6">
          <filename>libglib2.0-dev-bin_2.58.3-2+deb10u6+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">05ff46997f5fc8615a27901dbc119818bf99cfee</sum>
        </package>
        <package arch="all" name="libglib2.0-doc" version="2.58.3-2+deb10u6+tuxcare.els6">
          <filename>libglib2.0-doc_2.58.3-2+deb10u6+tuxcare.els6_all.deb</filename>
          <sum type="sha">1f0d94c18c203c6a6cf811de0a26b8e7ecdc58dc</sum>
        </package>
        <package arch="amd64" name="libglib2.0-tests" version="2.58.3-2+deb10u6+tuxcare.els6">
          <filename>libglib2.0-tests_2.58.3-2+deb10u6+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">134cb7a3e4c5571f5da7a102cc83bb213ef33464</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1787213464</id>
    <title>Fix CVE(s): CVE-2025-4802</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: static setuid binary dlopen may incorrectly search
     LD_LIBRARY_PATH
     - debian/patches/all/git-CVE-2025-4802-elf-Ignore-LD_LIBRARY_PATH-and-debug-env-var-for-setu.patch:
       elf: Ignore LD_LIBRARY_PATH and debug env var for setuid for static
     - CVE-2025-4802</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: static setuid binary dlopen may incorrectly search
     LD_LIBRARY_PATH
     - debian/patches/all/git-CVE-2025-4802-elf-Ignore-LD_LIBRARY_PATH-and-debug-env-var-for-setu.patch:
       elf: Ignore LD_LIBRARY_PATH and debug env var for setuid for static
     - CVE-2025-4802</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-20 08:11:15 UTC" />
    <updated date="2026-08-20 08:11:15 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1787213464.html" id="CLSA-2026:1787213464" title="CLSA-2026:1787213464" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-4802" id="CVE-2025-4802" title="CVE-2025-4802" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="all" name="glibc-doc" version="2.28-10+deb10u4+tuxcare.els1">
          <filename>glibc-doc_2.28-10+deb10u4+tuxcare.els1_all.deb</filename>
          <sum type="sha">46d62280c4e4545fc4d6dca29aa4f68fde5eb7da</sum>
        </package>
        <package arch="all" name="glibc-source" version="2.28-10+deb10u4+tuxcare.els1">
          <filename>glibc-source_2.28-10+deb10u4+tuxcare.els1_all.deb</filename>
          <sum type="sha">a4721d26a66b2e64a7b3a97a2afa13e89d1ad893</sum>
        </package>
        <package arch="amd64" name="libc-bin" version="2.28-10+deb10u4+tuxcare.els1">
          <filename>libc-bin_2.28-10+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">31ad07af5cd53ffd0e08c01ce8ece91564c41092</sum>
        </package>
        <package arch="amd64" name="libc-dev-bin" version="2.28-10+deb10u4+tuxcare.els1">
          <filename>libc-dev-bin_2.28-10+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">9f0ce234489f7d342e3a537b4d5d0b6fdbe7524a</sum>
        </package>
        <package arch="all" name="libc-l10n" version="2.28-10+deb10u4+tuxcare.els1">
          <filename>libc-l10n_2.28-10+deb10u4+tuxcare.els1_all.deb</filename>
          <sum type="sha">aa9af765b27371cb0546aeca8e598e2c1c8d63e2</sum>
        </package>
        <package arch="amd64" name="libc6" version="2.28-10+deb10u4+tuxcare.els1">
          <filename>libc6_2.28-10+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">90b6666c7175b2704dd6c2fa8e6a4bf82866ee4c</sum>
        </package>
        <package arch="amd64" name="libc6-dev" version="2.28-10+deb10u4+tuxcare.els1">
          <filename>libc6-dev_2.28-10+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">3613c2a71d390416a78d7d1b6513ba33dc94f84e</sum>
        </package>
        <package arch="amd64" name="libc6-dev-i386" version="2.28-10+deb10u4+tuxcare.els1">
          <filename>libc6-dev-i386_2.28-10+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">69b7c2669ce439b6dcb5482ed4a223d14ae66bbe</sum>
        </package>
        <package arch="amd64" name="libc6-dev-x32" version="2.28-10+deb10u4+tuxcare.els1">
          <filename>libc6-dev-x32_2.28-10+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">a15acdc8749a7812d26c11c63173a23c6dfd3434</sum>
        </package>
        <package arch="amd64" name="libc6-i386" version="2.28-10+deb10u4+tuxcare.els1">
          <filename>libc6-i386_2.28-10+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">49063376da2bfd5ae73be5a3e00e81c766cbae5b</sum>
        </package>
        <package arch="amd64" name="libc6-pic" version="2.28-10+deb10u4+tuxcare.els1">
          <filename>libc6-pic_2.28-10+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">8fdfb72cd8da528d6c97203d26a3ebff0f35f6e1</sum>
        </package>
        <package arch="amd64" name="libc6-x32" version="2.28-10+deb10u4+tuxcare.els1">
          <filename>libc6-x32_2.28-10+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">90f514637408b5a4edae40a65362512fe72ab6fb</sum>
        </package>
        <package arch="all" name="locales" version="2.28-10+deb10u4+tuxcare.els1">
          <filename>locales_2.28-10+deb10u4+tuxcare.els1_all.deb</filename>
          <sum type="sha">f03b78fa25f87220820ac2318e8eec47917ac2ba</sum>
        </package>
        <package arch="amd64" name="locales-all" version="2.28-10+deb10u4+tuxcare.els1">
          <filename>locales-all_2.28-10+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">d1be1e997d8984978532200f606a12ce12535b98</sum>
        </package>
        <package arch="amd64" name="multiarch-support" version="2.28-10+deb10u4+tuxcare.els1">
          <filename>multiarch-support_2.28-10+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">bf3bb29319f8f05a0c834af3ff904b5d80dafc30</sum>
        </package>
        <package arch="amd64" name="nscd" version="2.28-10+deb10u4+tuxcare.els1">
          <filename>nscd_2.28-10+deb10u4+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">c3b22de2640d5382ddf01105447661de51e8df07</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1786477142</id>
    <title>Fix of 6 CVEs</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: integer overflow in the TIM reader leading to an
     out-of-bounds read on 32-bit systems
     - debian/patches/CVE-2025-66628.patch: compute image_size through
       HeapOverflowSanityCheckGetSize() and reject a size larger than the
       blob in ReadTIMImage() in coders/tim.c
     - CVE-2025-66628
   * SECURITY UPDATE: infinite loop in the PCD decoder when the file has no
     valid Sync marker
     - debian/patches/CVE-2026-24485.patch: check the ReadBlob() return value
       in the PCDGetBits() macro and break out of the Sync-marker search on a
       short read in DecodeImage() in coders/pcd.c
     - CVE-2026-24485
   * SECURITY UPDATE: stack buffer overflow when parsing an over-long
     morphology kernel specification
     - debian/patches/CVE-2026-28494.patch: clamp the geometry substring
       length to sizeof(token)-1 in ParseKernelArray() and ParseKernelName()
       in magick/morphology.c
     - CVE-2026-28494
   * SECURITY UPDATE: uninitialized pointer dereference in the JBIG decoder
     on a truncated or corrupt stream
     - debian/patches/CVE-2026-28691.patch: throw a corrupt image exception
       when the decode loop does not finish with JBG_EOK in ReadJBIGImage()
       in coders/jbig.c
     - CVE-2026-28691
   * SECURITY UPDATE: integer overflow in the DIB coder leading to an
     out-of-bounds read or write
     - debian/patches/CVE-2026-28693.patch: compute bytes_per_line and length
       through HeapOverflowSanityCheckGetSize() and make the blob-size check
       overflow-free in ReadDIBImage() and WriteDIBImage() in coders/dib.c
     - CVE-2026-28693</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: integer overflow in the TIM reader leading to an
     out-of-bounds read on 32-bit systems
     - debian/patches/CVE-2025-66628.patch: compute image_size through
       HeapOverflowSanityCheckGetSize() and reject a size larger than the
       blob in ReadTIMImage() in coders/tim.c
     - CVE-2025-66628
   * SECURITY UPDATE: infinite loop in the PCD decoder when the file has no
     valid Sync marker
     - debian/patches/CVE-2026-24485.patch: check the ReadBlob() return value
       in the PCDGetBits() macro and break out of the Sync-marker search on a
       short read in DecodeImage() in coders/pcd.c
     - CVE-2026-24485
   * SECURITY UPDATE: stack buffer overflow when parsing an over-long
     morphology kernel specification
     - debian/patches/CVE-2026-28494.patch: clamp the geometry substring
       length to sizeof(token)-1 in ParseKernelArray() and ParseKernelName()
       in magick/morphology.c
     - CVE-2026-28494
   * SECURITY UPDATE: uninitialized pointer dereference in the JBIG decoder
     on a truncated or corrupt stream
     - debian/patches/CVE-2026-28691.patch: throw a corrupt image exception
       when the decode loop does not finish with JBG_EOK in ReadJBIGImage()
       in coders/jbig.c
     - CVE-2026-28691
   * SECURITY UPDATE: integer overflow in the DIB coder leading to an
     out-of-bounds read or write
     - debian/patches/CVE-2026-28693.patch: compute bytes_per_line and length
       through HeapOverflowSanityCheckGetSize() and make the blob-size check
       overflow-free in ReadDIBImage() and WriteDIBImage() in coders/dib.c
     - CVE-2026-28693</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-20 12:36:04 UTC" />
    <updated date="2026-08-20 12:36:04 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1786477142.html" id="CLSA-2026:1786477142" title="CLSA-2026:1786477142" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-66628" id="CVE-2025-66628" title="CVE-2025-66628" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-24485" id="CVE-2026-24485" title="CVE-2026-24485" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-28494" id="CVE-2026-28494" title="CVE-2026-28494" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-28691" id="CVE-2026-28691" title="CVE-2026-28691" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-28693" id="CVE-2026-28693" title="CVE-2026-28693" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-61866" id="CVE-2026-61866" title="CVE-2026-61866" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="imagemagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>imagemagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">5768582133fb29db873e0db59b4480deaf22af34</sum>
        </package>
        <package arch="all" name="imagemagick-6-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>imagemagick-6-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_all.deb</filename>
          <sum type="sha">4fa1cce9d1ec52cd18e3696a7a99d257f075e3cf</sum>
        </package>
        <package arch="all" name="imagemagick-6-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>imagemagick-6-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_all.deb</filename>
          <sum type="sha">7373c34c7b99b8691581292694c8b815d4871fe4</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>imagemagick-6.q16_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">f97c8d1ef0e3db305ef662819607e4f1f17a995c</sum>
        </package>
        <package arch="amd64" name="imagemagick-6.q16hdri" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>imagemagick-6.q16hdri_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">fdc23518d3a89826b7d35c0a8e58bda693081e87</sum>
        </package>
        <package arch="all" name="imagemagick-common" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>imagemagick-common_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_all.deb</filename>
          <sum type="sha">b06f1ef0db203f1a4895bdf243329048eda82a49</sum>
        </package>
        <package arch="all" name="imagemagick-doc" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>imagemagick-doc_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_all.deb</filename>
          <sum type="sha">3cabefbba75856a0812dba6162cb1514d8cfb918</sum>
        </package>
        <package arch="all" name="libimage-magick-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libimage-magick-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_all.deb</filename>
          <sum type="sha">eeb40fdb7cd66fa8bab1661c937eec029379989b</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libimage-magick-q16-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">0e81425ecf7b918764fecfab34443f4f41a4e0ba</sum>
        </package>
        <package arch="amd64" name="libimage-magick-q16hdri-perl" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libimage-magick-q16hdri-perl_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">03e3aa137426cea66336a21dc2c23cf8a738e255</sum>
        </package>
        <package arch="all" name="libmagick++-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libmagick++-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_all.deb</filename>
          <sum type="sha">7c771c1a8a8189da013558b6a6d15d57300a36e4</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libmagick++-6.q16-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">e38a9f107844d9ff14a60c383567a5cb7870b60e</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libmagick++-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">0accb3769cd89ca4888ff6366eff387691547d1d</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-8" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libmagick++-6.q16hdri-8_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">7dc2640324c0703d5826cc00ac6ab7290d854878</sum>
        </package>
        <package arch="amd64" name="libmagick++-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libmagick++-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">3b31e6586993f8daa354a3a1e8af245c44e9abd8</sum>
        </package>
        <package arch="all" name="libmagick++-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libmagick++-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_all.deb</filename>
          <sum type="sha">478e12ad1cc080f57f9cff2c37aae761a0215288</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6-arch-config" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libmagickcore-6-arch-config_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">33b85ddd8e79dd053ed21fda6f06cdc6ddf4fcd3</sum>
        </package>
        <package arch="all" name="libmagickcore-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libmagickcore-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_all.deb</filename>
          <sum type="sha">75f1a09e510e1f97085b62449925fef88262be19</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libmagickcore-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">a1d39a0cb393407d7a9866b489269ae4162208f2</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libmagickcore-6.q16-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">07c692c4b654f6c747e8b24959fafa9daaf8cf73</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libmagickcore-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">5e605e13fc37fa3b8322095798a58a3a74cc0ed3</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libmagickcore-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">9f775536d33d241949db07f12d208ac52bc2b44f</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-6-extra" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libmagickcore-6.q16hdri-6-extra_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">c504872386f0d8f5634d184141595c0b20a23cd5</sum>
        </package>
        <package arch="amd64" name="libmagickcore-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libmagickcore-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">779dd264fce7845d187be0054989a072518469bc</sum>
        </package>
        <package arch="all" name="libmagickcore-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libmagickcore-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_all.deb</filename>
          <sum type="sha">b304dbeb377c045f25fbf5d09d0af6620b27d0e5</sum>
        </package>
        <package arch="all" name="libmagickwand-6-headers" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libmagickwand-6-headers_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_all.deb</filename>
          <sum type="sha">ee9dd1c2e7433e0aca2a67174a26f1678c205ffc</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libmagickwand-6.q16-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">698c301f01dae80fa2cd4339803617c4adf2f78a</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libmagickwand-6.q16-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">38071fee706f313181d053c3414908372789d52f</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-6" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libmagickwand-6.q16hdri-6_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">1a6463eaf54b8a73d3e073a670e1c96b45480438</sum>
        </package>
        <package arch="amd64" name="libmagickwand-6.q16hdri-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libmagickwand-6.q16hdri-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_amd64.deb</filename>
          <sum type="sha">acc7346066f3397b0b9f579bf8a19198d9d44f28</sum>
        </package>
        <package arch="all" name="libmagickwand-dev" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>libmagickwand-dev_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_all.deb</filename>
          <sum type="sha">5ee33f03f34794fe0d26ede14b749be0a5493f87</sum>
        </package>
        <package arch="all" name="perlmagick" version="8:6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16">
          <filename>perlmagick_6.9.10.23+dfsg-2.1+deb10u7+tuxcare.els16_all.deb</filename>
          <sum type="sha">113a29a44772f65fc7124321752c4b1a9c455239</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1787229627</id>
    <title>Fix CVE(s): CVE-2026-34180, CVE-2026-42766</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: fix ASN.1 decoder length truncation causing heap buffer over-read (tasn_dec.c)
     - debian/patches/CVE-2026-34180.patch: fix ASN.1 decoder length truncation causing heap buffer over-read (tasn_dec.c)
     - CVE-2026-34180
   * SECURITY UPDATE: NULL check pwri-&gt;keyDerivationAlgorithm in cms_RecipientInfo_pwri_crypt() (cms_pwri.c)
     - debian/patches/CVE-2026-42766.patch: NULL check pwri-&gt;keyDerivationAlgorithm in cms_RecipientInfo_pwri_crypt() (cms_pwri.c)
     - CVE-2026-42766</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: fix ASN.1 decoder length truncation causing heap buffer over-read (tasn_dec.c)
     - debian/patches/CVE-2026-34180.patch: fix ASN.1 decoder length truncation causing heap buffer over-read (tasn_dec.c)
     - CVE-2026-34180
   * SECURITY UPDATE: NULL check pwri-&gt;keyDerivationAlgorithm in cms_RecipientInfo_pwri_crypt() (cms_pwri.c)
     - debian/patches/CVE-2026-42766.patch: NULL check pwri-&gt;keyDerivationAlgorithm in cms_RecipientInfo_pwri_crypt() (cms_pwri.c)
     - CVE-2026-42766</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-20 12:40:39 UTC" />
    <updated date="2026-08-20 12:40:39 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1787229627.html" id="CLSA-2026:1787229627" title="CLSA-2026:1787229627" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-34180" id="CVE-2026-34180" title="CVE-2026-34180" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-42766" id="CVE-2026-42766" title="CVE-2026-42766" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libssl-dev" version="1.1.1n-0+deb10u6+tuxcare.els5">
          <filename>libssl-dev_1.1.1n-0+deb10u6+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">6fbbbcc01bc9f14d1349abed4ef4181758fc647d</sum>
        </package>
        <package arch="all" name="libssl-doc" version="1.1.1n-0+deb10u6+tuxcare.els5">
          <filename>libssl-doc_1.1.1n-0+deb10u6+tuxcare.els5_all.deb</filename>
          <sum type="sha">fbba17b12f417620e08717b0cbe2927f372adb39</sum>
        </package>
        <package arch="amd64" name="libssl1.1" version="1.1.1n-0+deb10u6+tuxcare.els5">
          <filename>libssl1.1_1.1.1n-0+deb10u6+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">41924f621e7a630c7c348862e75d54bb0436b124</sum>
        </package>
        <package arch="amd64" name="openssl" version="1.1.1n-0+deb10u6+tuxcare.els5">
          <filename>openssl_1.1.1n-0+deb10u6+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">80a18c4226477f16aba2fcc10279e89d5fd89917</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1787230283</id>
    <title>Fix CVE(s): CVE-2023-39417, CVE-2023-5869, CVE-2024-0985</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Reject substituting extension schemas containing quoting-relevant characters, preventing SQL injection via @extschema@ in extension scripts
     - debian/patches/CVE-2023-39417.patch: Reject substituting extension schemas containing quoting-relevant characters, preventing SQL injection via @extschema@ in extension scripts
     - CVE-2023-39417
   * SECURITY UPDATE: Detect integer overflow while computing new array dimensions in array_set_element(), array_set_element_expanded() and array_set_slice()
     - debian/patches/CVE-2023-5869.patch: Detect integer overflow while computing new array dimensions in array_set_element(), array_set_element_expanded() and array_set_slice()
     - CVE-2023-5869
   * SECURITY UPDATE: Run REFRESH MATERIALIZED VIEW CONCURRENTLY in the right security context when creating the temporary diff table
     - debian/patches/CVE-2024-0985.patch: Run REFRESH MATERIALIZED VIEW CONCURRENTLY in the right security context when creating the temporary diff table
     - CVE-2024-0985</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Reject substituting extension schemas containing quoting-relevant characters, preventing SQL injection via @extschema@ in extension scripts
     - debian/patches/CVE-2023-39417.patch: Reject substituting extension schemas containing quoting-relevant characters, preventing SQL injection via @extschema@ in extension scripts
     - CVE-2023-39417
   * SECURITY UPDATE: Detect integer overflow while computing new array dimensions in array_set_element(), array_set_element_expanded() and array_set_slice()
     - debian/patches/CVE-2023-5869.patch: Detect integer overflow while computing new array dimensions in array_set_element(), array_set_element_expanded() and array_set_slice()
     - CVE-2023-5869
   * SECURITY UPDATE: Run REFRESH MATERIALIZED VIEW CONCURRENTLY in the right security context when creating the temporary diff table
     - debian/patches/CVE-2024-0985.patch: Run REFRESH MATERIALIZED VIEW CONCURRENTLY in the right security context when creating the temporary diff table
     - CVE-2024-0985</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-20 12:51:35 UTC" />
    <updated date="2026-08-20 12:51:35 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1787230283.html" id="CLSA-2026:1787230283" title="CLSA-2026:1787230283" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2023-39417" id="CVE-2023-39417" title="CVE-2023-39417" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2023-5869" id="CVE-2023-5869" title="CVE-2023-5869" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-0985" id="CVE-2024-0985" title="CVE-2024-0985" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libecpg-compat3-9.6" version="9.6.24-0+deb10u1+tuxcare.els3">
          <filename>libecpg-compat3-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">dfadf48c275013a8e91be1bdd498de47a3c050b4</sum>
        </package>
        <package arch="amd64" name="libecpg-dev-9.6" version="9.6.24-0+deb10u1+tuxcare.els3">
          <filename>libecpg-dev-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">3ab3246d63de509b84f17c754259c21b36487b06</sum>
        </package>
        <package arch="amd64" name="libecpg6-9.6" version="9.6.24-0+deb10u1+tuxcare.els3">
          <filename>libecpg6-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">369f079addb94ad1979138c80e1f59edf2b25c97</sum>
        </package>
        <package arch="amd64" name="libpgtypes3-9.6" version="9.6.24-0+deb10u1+tuxcare.els3">
          <filename>libpgtypes3-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">76131ec08b7ac640f10b6eae9b348075db303054</sum>
        </package>
        <package arch="amd64" name="libpq-dev-9.6" version="9.6.24-0+deb10u1+tuxcare.els3">
          <filename>libpq-dev-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">67cd8b5f5be35f92012c7902f2aa0979c8d2b87e</sum>
        </package>
        <package arch="amd64" name="libpq5-9.6" version="9.6.24-0+deb10u1+tuxcare.els3">
          <filename>libpq5-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">d015cf08078573beb8f5ef0a485f6b21f8580355</sum>
        </package>
        <package arch="amd64" name="postgresql-9.6" version="9.6.24-0+deb10u1+tuxcare.els3">
          <filename>postgresql-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">a2ae82833db1a0c11448dbeae3ea9d2b62ff59d3</sum>
        </package>
        <package arch="amd64" name="postgresql-client-9.6" version="9.6.24-0+deb10u1+tuxcare.els3">
          <filename>postgresql-client-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">2cf1b52da099c1b0d9c90d3117a624068813dc10</sum>
        </package>
        <package arch="amd64" name="postgresql-contrib-9.6" version="9.6.24-0+deb10u1+tuxcare.els3">
          <filename>postgresql-contrib-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">306b84d2e3cdc0e70775a46ae9f1589af458c6ba</sum>
        </package>
        <package arch="all" name="postgresql-doc-9.6" version="9.6.24-0+deb10u1+tuxcare.els3">
          <filename>postgresql-doc-9.6_9.6.24-0+deb10u1+tuxcare.els3_all.deb</filename>
          <sum type="sha">a5ad56dc061a121c057ac1ef786c3ce79e94c0a8</sum>
        </package>
        <package arch="amd64" name="postgresql-plperl-9.6" version="9.6.24-0+deb10u1+tuxcare.els3">
          <filename>postgresql-plperl-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">b0761cd5b69de1928f356a6744ab5b01df39ab8d</sum>
        </package>
        <package arch="amd64" name="postgresql-plpython-9.6" version="9.6.24-0+deb10u1+tuxcare.els3">
          <filename>postgresql-plpython-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">d6e6816676b1c090529d6f1cceeff41ebbec865f</sum>
        </package>
        <package arch="amd64" name="postgresql-plpython3-9.6" version="9.6.24-0+deb10u1+tuxcare.els3">
          <filename>postgresql-plpython3-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">2c253bfed9df191498d5df2b3378417f7aa7e7ee</sum>
        </package>
        <package arch="amd64" name="postgresql-pltcl-9.6" version="9.6.24-0+deb10u1+tuxcare.els3">
          <filename>postgresql-pltcl-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">b5054d2ea3eaed8d474e9a79571fe633c1044358</sum>
        </package>
        <package arch="amd64" name="postgresql-server-dev-9.6" version="9.6.24-0+deb10u1+tuxcare.els3">
          <filename>postgresql-server-dev-9.6_9.6.24-0+deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">be1766671b2f8fdbd85aea5368ded08c2fdc611a</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1787303674</id>
    <title>Fix CVE(s): CVE-2026-27135</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: assertion failure in nghttp2 HTTP/2 frame processing
     - debian/patches/CVE-2026-27135-1.patch: add missing iframe-&gt;state
       validations in nghttp2_session_mem_recv so that reception stops once
       the session has been terminated, avoiding an assertion failure on a
       subsequent malformed frame
     - debian/patches/CVE-2026-27135-2.patch: add the same validation after
       session_after_header_block_received and after
       session_process_data_frame, which upstream carries since 1.67.0 and
       which the fix above therefore does not touch
     - CVE-2026-27135</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: assertion failure in nghttp2 HTTP/2 frame processing
     - debian/patches/CVE-2026-27135-1.patch: add missing iframe-&gt;state
       validations in nghttp2_session_mem_recv so that reception stops once
       the session has been terminated, avoiding an assertion failure on a
       subsequent malformed frame
     - debian/patches/CVE-2026-27135-2.patch: add the same validation after
       session_after_header_block_received and after
       session_process_data_frame, which upstream carries since 1.67.0 and
       which the fix above therefore does not touch
     - CVE-2026-27135</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-21 09:14:44 UTC" />
    <updated date="2026-08-21 09:14:44 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1787303674.html" id="CLSA-2026:1787303674" title="CLSA-2026:1787303674" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-27135" id="CVE-2026-27135" title="CVE-2026-27135" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libnghttp2-14" version="1.36.0-2+deb10u3+tuxcare.els2">
          <filename>libnghttp2-14_1.36.0-2+deb10u3+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">47a59394be48fd54f841a8437f2749f23c466e07</sum>
        </package>
        <package arch="amd64" name="libnghttp2-dev" version="1.36.0-2+deb10u3+tuxcare.els2">
          <filename>libnghttp2-dev_1.36.0-2+deb10u3+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">a542debb23ac59b850f643e7ec785154e8ed7d86</sum>
        </package>
        <package arch="all" name="libnghttp2-doc" version="1.36.0-2+deb10u3+tuxcare.els2">
          <filename>libnghttp2-doc_1.36.0-2+deb10u3+tuxcare.els2_all.deb</filename>
          <sum type="sha">bd3a40897750d150f9ab20100b9b1aa4282488c8</sum>
        </package>
        <package arch="all" name="nghttp2" version="1.36.0-2+deb10u3+tuxcare.els2">
          <filename>nghttp2_1.36.0-2+deb10u3+tuxcare.els2_all.deb</filename>
          <sum type="sha">8537dcd58d25d49113c7debd48424e4e74f70683</sum>
        </package>
        <package arch="amd64" name="nghttp2-client" version="1.36.0-2+deb10u3+tuxcare.els2">
          <filename>nghttp2-client_1.36.0-2+deb10u3+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">bef46b2dddd2b2c9a958714f0d2c3a42a74bc54f</sum>
        </package>
        <package arch="amd64" name="nghttp2-proxy" version="1.36.0-2+deb10u3+tuxcare.els2">
          <filename>nghttp2-proxy_1.36.0-2+deb10u3+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">4edb94d1908c6d8d2bdea4ce2a20127af173d239</sum>
        </package>
        <package arch="amd64" name="nghttp2-server" version="1.36.0-2+deb10u3+tuxcare.els2">
          <filename>nghttp2-server_1.36.0-2+deb10u3+tuxcare.els2_amd64.deb</filename>
          <sum type="sha">e75c18a54bf39d10c5f5be793ca4ccdaaec05b89</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1787401059</id>
    <title>Fix CVE(s): CVE-2023-6516</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: named running as a recursive resolver could be driven to exceed the configured max-cache-size, and exhaust available memory, because tree-pruning cleanup events were queued faster than they were processed
     - debian/patches/CVE-2023-6516.patch: limit isc_task_send() overhead for tree pruning (upstream c3377cbfaa)
     - debian/patches/CVE-2023-6516-lock-contention.patch: reduce lock contention during RBTDB tree pruning (upstream 801e888d03)
     - debian/patches/CVE-2023-6516-prune-guards.patch: guard re-queueing a node for pruning (upstream f6289ad931, 4b6fc97af6, 7d9be24bb1)
     - debian/patches/CVE-2023-6516-final-design.patch: the pruning design upstream settled on in 9.16.49, GL #4621 (upstream a548312191, eba7fb5f9f, 5f98eba608); adds dns_db_setprunetask() rather than changing the dns_db_settask() ABI
     - debian/libdns1104.symbols: record the three entry points the last patch adds
     - CVE-2023-6516</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: named running as a recursive resolver could be driven to exceed the configured max-cache-size, and exhaust available memory, because tree-pruning cleanup events were queued faster than they were processed
     - debian/patches/CVE-2023-6516.patch: limit isc_task_send() overhead for tree pruning (upstream c3377cbfaa)
     - debian/patches/CVE-2023-6516-lock-contention.patch: reduce lock contention during RBTDB tree pruning (upstream 801e888d03)
     - debian/patches/CVE-2023-6516-prune-guards.patch: guard re-queueing a node for pruning (upstream f6289ad931, 4b6fc97af6, 7d9be24bb1)
     - debian/patches/CVE-2023-6516-final-design.patch: the pruning design upstream settled on in 9.16.49, GL #4621 (upstream a548312191, eba7fb5f9f, 5f98eba608); adds dns_db_setprunetask() rather than changing the dns_db_settask() ABI
     - debian/libdns1104.symbols: record the three entry points the last patch adds
     - CVE-2023-6516</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-22 12:22:33 UTC" />
    <updated date="2026-08-22 12:22:33 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1787401059.html" id="CLSA-2026:1787401059" title="CLSA-2026:1787401059" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2023-6516" id="CVE-2023-6516" title="CVE-2023-6516" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="bind9" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5">
          <filename>bind9_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">356ac99ebab2069f9b0dbf01385799f499610b94</sum>
        </package>
        <package arch="all" name="bind9-doc" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5">
          <filename>bind9-doc_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5_all.deb</filename>
          <sum type="sha">ac9cb6e808b620fc29cc34dd4a15634ad922e5be</sum>
        </package>
        <package arch="amd64" name="bind9-host" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5">
          <filename>bind9-host_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">d4cbf6f3df7d0975ab3e4955375a5a3bfac6b9d1</sum>
        </package>
        <package arch="amd64" name="bind9utils" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5">
          <filename>bind9utils_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">050a4fe04ca707c3d8a6c2591303f5b95a69ae89</sum>
        </package>
        <package arch="amd64" name="dnsutils" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5">
          <filename>dnsutils_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">2b15b053ae4698bfa586301959e40e9a9f8249a8</sum>
        </package>
        <package arch="amd64" name="libbind-dev" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5">
          <filename>libbind-dev_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">391653c551840b2c64ebf207b4d9c298c50580d2</sum>
        </package>
        <package arch="amd64" name="libbind-export-dev" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5">
          <filename>libbind-export-dev_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">952c77364691e4313d268f9b37214d8df911a9c1</sum>
        </package>
        <package arch="amd64" name="libbind9-161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5">
          <filename>libbind9-161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">d72d3c3e3fa2cf2ad4a2ea6a3c09c1fe425859b7</sum>
        </package>
        <package arch="amd64" name="libdns-export1104" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5">
          <filename>libdns-export1104_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">7409639960454b71bb02f5b4e0983af6ef158830</sum>
        </package>
        <package arch="amd64" name="libdns1104" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5">
          <filename>libdns1104_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">71b73cb2ad7e7d98a678734c45f254f54e6f0efa</sum>
        </package>
        <package arch="amd64" name="libirs-export161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5">
          <filename>libirs-export161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">974fa8e11160e8bc59941681f17326078dbe576f</sum>
        </package>
        <package arch="amd64" name="libirs161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5">
          <filename>libirs161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">23bc7501160ce968c6baf13207a9421da43a61b0</sum>
        </package>
        <package arch="amd64" name="libisc-export1100" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5">
          <filename>libisc-export1100_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">dd0d7ea739e94570aca6d42d63cf8c0d9be11234</sum>
        </package>
        <package arch="amd64" name="libisc1100" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5">
          <filename>libisc1100_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">90bb3d3f8aecae95b0dd987069bcfe721f3eaaf3</sum>
        </package>
        <package arch="amd64" name="libisccc-export161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5">
          <filename>libisccc-export161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">aac7b2f52d611eaf406388bf7f4d719ce8b56ee7</sum>
        </package>
        <package arch="amd64" name="libisccc161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5">
          <filename>libisccc161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">86a3e187e374ca71d5c9bd3c1ab1efe528c271da</sum>
        </package>
        <package arch="amd64" name="libisccfg-export163" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5">
          <filename>libisccfg-export163_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">f7eddd315d234bd2f6ddaef33226e3c63d27cdc9</sum>
        </package>
        <package arch="amd64" name="libisccfg163" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5">
          <filename>libisccfg163_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">0b121186e75c1a6bc4b068bacc2aa0d72a091bb5</sum>
        </package>
        <package arch="amd64" name="liblwres161" version="1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5">
          <filename>liblwres161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">b132fb3619d197779e7c0276ace8d01c41cfdef5</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1787401254</id>
    <title>Fix CVE(s): CVE-2026-29111</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * CVE-2026-29111: validate the GetUnitByControlGroup cgroup path
     - debian/patches/CVE-2026-29111.patch: an unprivileged D-Bus caller
       could hand PID 1 a cgroup path that is neither absolute nor
       normalized via the GetUnitByControlGroup method, which on v249 and
       older overwrites stack memory with attacker-controlled content.
       Validate with path_is_absolute() and path_is_normalized() before
       manager_get_unit_by_cgroup().
   * test: skip the meson suite on armel
     - debian/rules: the debian10-els armel worker runs under qemu-user
       (TCG) rather than native ARM hardware, so nine tests abort and two
       time out on interfaces qemu does not emulate (raw clone(),
       PR_SET_MM_ARG_*, SO_ATTACH_FILTER, netlink, netns, SIGBUS), and
       test-capability crashes the emulator itself.  None of it is
       reachable from the package source.  The full suite still runs on
       amd64 and arm64.
   * test: fix two test failures on the current build nodes
     - debian/patches/test-seccomp-accept-ENOSYS-from-sysctl-2-too.patch:
       _sysctl(2) was removed from the kernel and now fails with ENOSYS
       rather than EFAULT, so test_protect_sysctl() aborted (upstream
       commit 0af05e485a3a).
     - debian/patches/fs-util-do-not-chmod-symlinks-in-touch_file.patch:
       touch_file() chmod()ed symlinks through /proc/self/fd, which newer
       kernels reject, so test_touch_file() aborted. Skip the chmod() for
       symlinks as upstream does in fchmod_and_chown(), and drop the now
       meaningless mode assertion from the test.</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * CVE-2026-29111: validate the GetUnitByControlGroup cgroup path
     - debian/patches/CVE-2026-29111.patch: an unprivileged D-Bus caller
       could hand PID 1 a cgroup path that is neither absolute nor
       normalized via the GetUnitByControlGroup method, which on v249 and
       older overwrites stack memory with attacker-controlled content.
       Validate with path_is_absolute() and path_is_normalized() before
       manager_get_unit_by_cgroup().
   * test: skip the meson suite on armel
     - debian/rules: the debian10-els armel worker runs under qemu-user
       (TCG) rather than native ARM hardware, so nine tests abort and two
       time out on interfaces qemu does not emulate (raw clone(),
       PR_SET_MM_ARG_*, SO_ATTACH_FILTER, netlink, netns, SIGBUS), and
       test-capability crashes the emulator itself.  None of it is
       reachable from the package source.  The full suite still runs on
       amd64 and arm64.
   * test: fix two test failures on the current build nodes
     - debian/patches/test-seccomp-accept-ENOSYS-from-sysctl-2-too.patch:
       _sysctl(2) was removed from the kernel and now fails with ENOSYS
       rather than EFAULT, so test_protect_sysctl() aborted (upstream
       commit 0af05e485a3a).
     - debian/patches/fs-util-do-not-chmod-symlinks-in-touch_file.patch:
       touch_file() chmod()ed symlinks through /proc/self/fd, which newer
       kernels reject, so test_touch_file() aborted. Skip the chmod() for
       symlinks as upstream does in fchmod_and_chown(), and drop the now
       meaningless mode assertion from the test.</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-24 08:04:07 UTC" />
    <updated date="2026-08-24 08:04:07 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1787401254.html" id="CLSA-2026:1787401254" title="CLSA-2026:1787401254" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-29111" id="CVE-2026-29111" title="CVE-2026-29111" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libnss-myhostname" version="241-7~deb10u10+tuxcare.els3">
          <filename>libnss-myhostname_241-7~deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">39a6ec2967c4260017fe2aa6193ff1cd4a44fcc0</sum>
        </package>
        <package arch="amd64" name="libnss-mymachines" version="241-7~deb10u10+tuxcare.els3">
          <filename>libnss-mymachines_241-7~deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">0566b4513fabe45a8510f52f6018fcd064a61d45</sum>
        </package>
        <package arch="amd64" name="libnss-resolve" version="241-7~deb10u10+tuxcare.els3">
          <filename>libnss-resolve_241-7~deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">3187f550a233a43f3d842136c7b78421e0f6d69a</sum>
        </package>
        <package arch="amd64" name="libnss-systemd" version="241-7~deb10u10+tuxcare.els3">
          <filename>libnss-systemd_241-7~deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">c1d8ef1f7d31db9ef066719c45ece91ce54e7851</sum>
        </package>
        <package arch="amd64" name="libpam-systemd" version="241-7~deb10u10+tuxcare.els3">
          <filename>libpam-systemd_241-7~deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">4554ba70eb88c6b51b76ad9499987236e091061e</sum>
        </package>
        <package arch="amd64" name="libsystemd-dev" version="241-7~deb10u10+tuxcare.els3">
          <filename>libsystemd-dev_241-7~deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">1e3310176212c6ac96c58b032c30b31ded20fe81</sum>
        </package>
        <package arch="amd64" name="libsystemd0" version="241-7~deb10u10+tuxcare.els3">
          <filename>libsystemd0_241-7~deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">8df9d7b8327621b74d3db3ce301a0af257e870d1</sum>
        </package>
        <package arch="amd64" name="libudev-dev" version="241-7~deb10u10+tuxcare.els3">
          <filename>libudev-dev_241-7~deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">175f692638f13ac0356afa8b0a745c52c2f567ed</sum>
        </package>
        <package arch="amd64" name="libudev1" version="241-7~deb10u10+tuxcare.els3">
          <filename>libudev1_241-7~deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">49b42e69a6b8068549d2ca043db2970f2e43071c</sum>
        </package>
        <package arch="amd64" name="systemd" version="241-7~deb10u10+tuxcare.els3">
          <filename>systemd_241-7~deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">39d5f1ab5e2f8d27ceb835a662e60d0d46092779</sum>
        </package>
        <package arch="amd64" name="systemd-container" version="241-7~deb10u10+tuxcare.els3">
          <filename>systemd-container_241-7~deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">29943d1a4386505e69737548d0e4b79dc0580c28</sum>
        </package>
        <package arch="amd64" name="systemd-coredump" version="241-7~deb10u10+tuxcare.els3">
          <filename>systemd-coredump_241-7~deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">df83ffb076c74bfd539d118edcc2c3d0de2fa837</sum>
        </package>
        <package arch="amd64" name="systemd-journal-remote" version="241-7~deb10u10+tuxcare.els3">
          <filename>systemd-journal-remote_241-7~deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">46acd609067e712c6f405325cc151a3480180a68</sum>
        </package>
        <package arch="amd64" name="systemd-sysv" version="241-7~deb10u10+tuxcare.els3">
          <filename>systemd-sysv_241-7~deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">26985878e22ddc7e29cd62ede1dbc671aa6632c4</sum>
        </package>
        <package arch="amd64" name="systemd-tests" version="241-7~deb10u10+tuxcare.els3">
          <filename>systemd-tests_241-7~deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">83964f910f59f2b7d33537738b693eb35b39cd15</sum>
        </package>
        <package arch="amd64" name="udev" version="241-7~deb10u10+tuxcare.els3">
          <filename>udev_241-7~deb10u10+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">013e4cf333740e629a53c3f6249728b48249678b</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1787660038</id>
    <title>Fix CVE(s): CVE-2026-0864</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: configuration injection in configparser via a carriage
     return in an attacker-controlled written value
     - debian/patches/CVE-2026-0864.patch: in Lib/configparser.py, normalize
       CR and CRLF to LF before indenting continuation lines in
       RawConfigParser._write_section(), so a bare carriage return inside a
       written value can no longer round-trip into an unindented line that
       the parser reads back as a separate "key = value" pair. Backport of
       upstream commit 5858e42c539d (gh-143927 / GH-143929) via the 3.10
       backport 12dcbd74d356; applies to 3.7.3 with line offsets only.
       Bundles the upstream regression test test_crlf_normalization
       (test_configparser.py).
     - CVE-2026-0864</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: configuration injection in configparser via a carriage
     return in an attacker-controlled written value
     - debian/patches/CVE-2026-0864.patch: in Lib/configparser.py, normalize
       CR and CRLF to LF before indenting continuation lines in
       RawConfigParser._write_section(), so a bare carriage return inside a
       written value can no longer round-trip into an unindented line that
       the parser reads back as a separate "key = value" pair. Backport of
       upstream commit 5858e42c539d (gh-143927 / GH-143929) via the 3.10
       backport 12dcbd74d356; applies to 3.7.3 with line offsets only.
       Bundles the upstream regression test test_crlf_normalization
       (test_configparser.py).
     - CVE-2026-0864</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-25 12:14:10 UTC" />
    <updated date="2026-08-25 12:14:10 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1787660038.html" id="CLSA-2026:1787660038" title="CLSA-2026:1787660038" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-0864" id="CVE-2026-0864" title="CVE-2026-0864" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="all" name="idle-python3.7" version="3.7.3-2+deb10u7+tuxcare.els7">
          <filename>idle-python3.7_3.7.3-2+deb10u7+tuxcare.els7_all.deb</filename>
          <sum type="sha">2692ee437fb5b243e16bb84419ef092eb2d3bfc2</sum>
        </package>
        <package arch="amd64" name="libpython3.7" version="3.7.3-2+deb10u7+tuxcare.els7">
          <filename>libpython3.7_3.7.3-2+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">43c5664ba223c7fc5668338930bdec56f973ff79</sum>
        </package>
        <package arch="amd64" name="libpython3.7-dev" version="3.7.3-2+deb10u7+tuxcare.els7">
          <filename>libpython3.7-dev_3.7.3-2+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">31d3e98fb2c378cfa30b8eac916febbbbe6f3638</sum>
        </package>
        <package arch="amd64" name="libpython3.7-minimal" version="3.7.3-2+deb10u7+tuxcare.els7">
          <filename>libpython3.7-minimal_3.7.3-2+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">10a534398f2f98afb6966934273f0da9ede02b11</sum>
        </package>
        <package arch="amd64" name="libpython3.7-stdlib" version="3.7.3-2+deb10u7+tuxcare.els7">
          <filename>libpython3.7-stdlib_3.7.3-2+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">40cb20bfedca567d787882a8b521865a5fd56bca</sum>
        </package>
        <package arch="all" name="libpython3.7-testsuite" version="3.7.3-2+deb10u7+tuxcare.els7">
          <filename>libpython3.7-testsuite_3.7.3-2+deb10u7+tuxcare.els7_all.deb</filename>
          <sum type="sha">15f1dcd248edef5e46a3acafc1172f7a3e49c342</sum>
        </package>
        <package arch="amd64" name="python3.7" version="3.7.3-2+deb10u7+tuxcare.els7">
          <filename>python3.7_3.7.3-2+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">9d64bf0e31b0ae4a8fef9ccdb63a212e0c25ea73</sum>
        </package>
        <package arch="amd64" name="python3.7-dev" version="3.7.3-2+deb10u7+tuxcare.els7">
          <filename>python3.7-dev_3.7.3-2+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">04207792098716849f76ede7c1bad00b3b5f6bec</sum>
        </package>
        <package arch="all" name="python3.7-doc" version="3.7.3-2+deb10u7+tuxcare.els7">
          <filename>python3.7-doc_3.7.3-2+deb10u7+tuxcare.els7_all.deb</filename>
          <sum type="sha">4a889daaa116dd6fb22a7d2c2ddaee9cecc0f547</sum>
        </package>
        <package arch="all" name="python3.7-examples" version="3.7.3-2+deb10u7+tuxcare.els7">
          <filename>python3.7-examples_3.7.3-2+deb10u7+tuxcare.els7_all.deb</filename>
          <sum type="sha">cbdc8cc7383e78789d1fe2b55f9e6359c56193c5</sum>
        </package>
        <package arch="amd64" name="python3.7-minimal" version="3.7.3-2+deb10u7+tuxcare.els7">
          <filename>python3.7-minimal_3.7.3-2+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">db34ca7e78a3304de92cad53c38cbc3c6c013c6d</sum>
        </package>
        <package arch="amd64" name="python3.7-venv" version="3.7.3-2+deb10u7+tuxcare.els7">
          <filename>python3.7-venv_3.7.3-2+deb10u7+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">47afe77168905468a082358ac089f290f200a774</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1787740667</id>
    <title>Fix CVE(s): CVE-2026-66032</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: double free in sftp_open() lets a malicious SSH server
     corrupt the heap of an authenticated client opening an SFTP session
     - debian/patches/CVE-2026-66032.patch: set data to NULL after freeing the
       SSH_FXP_STATUS response buffer on the FX_OK path, so the if(badness)
       arm cannot free the same pointer a second time when the follow-up
       sftp_packet_require() for SSH_FXP_HANDLE fails, in sftp_open() in
       src/sftp.c
     - CVE-2026-66032</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: double free in sftp_open() lets a malicious SSH server
     corrupt the heap of an authenticated client opening an SFTP session
     - debian/patches/CVE-2026-66032.patch: set data to NULL after freeing the
       SSH_FXP_STATUS response buffer on the FX_OK path, so the if(badness)
       arm cannot free the same pointer a second time when the follow-up
       sftp_packet_require() for SSH_FXP_HANDLE fails, in sftp_open() in
       src/sftp.c
     - CVE-2026-66032</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-26 10:38:04 UTC" />
    <updated date="2026-08-26 10:38:04 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1787740667.html" id="CLSA-2026:1787740667" title="CLSA-2026:1787740667" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-66032" id="CVE-2026-66032" title="CVE-2026-66032" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libssh2-1" version="1.8.0-2.1+deb10u1+tuxcare.els3">
          <filename>libssh2-1_1.8.0-2.1+deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">db2b9d030ab9a8fc2163855c61f90b51d3b9c5f9</sum>
        </package>
        <package arch="amd64" name="libssh2-1-dev" version="1.8.0-2.1+deb10u1+tuxcare.els3">
          <filename>libssh2-1-dev_1.8.0-2.1+deb10u1+tuxcare.els3_amd64.deb</filename>
          <sum type="sha">8061f7ee27a3cdc48ca69a21b1c0a97ddb92aef9</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1787756777</id>
    <title>Fix CVE(s): CVE-2026-73282, CVE-2026-73283</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: use-after-free in the ssh client when a remote
     forwarding is added over the multiplexing socket
     - debian/patches/CVE-2026-73282.patch: pass a heap-allocated index
       instead of a pointer into options.remote_forwards[] to
       ssh_confirm_remote_forward() in ssh.c, so a concurrent
       add_remote_forward() reallocation cannot leave the pending global
       request confirmation holding a dangling pointer.
     - CVE-2026-73282
   * SECURITY UPDATE: authorized_keys restrict keyword did not cover
     tunnel forwarding
     - debian/patches/CVE-2026-73283.patch: also reject tunnel device
       forwarding in server_request_tun() (serverloop.c) when the
       authenticating key carries the restrict option.
     - CVE-2026-73283</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: use-after-free in the ssh client when a remote
     forwarding is added over the multiplexing socket
     - debian/patches/CVE-2026-73282.patch: pass a heap-allocated index
       instead of a pointer into options.remote_forwards[] to
       ssh_confirm_remote_forward() in ssh.c, so a concurrent
       add_remote_forward() reallocation cannot leave the pending global
       request confirmation holding a dangling pointer.
     - CVE-2026-73282
   * SECURITY UPDATE: authorized_keys restrict keyword did not cover
     tunnel forwarding
     - debian/patches/CVE-2026-73283.patch: also reject tunnel device
       forwarding in server_request_tun() (serverloop.c) when the
       authenticating key carries the restrict option.
     - CVE-2026-73283</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-26 15:06:36 UTC" />
    <updated date="2026-08-26 15:06:36 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1787756777.html" id="CLSA-2026:1787756777" title="CLSA-2026:1787756777" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-73282" id="CVE-2026-73282" title="CVE-2026-73282" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-73283" id="CVE-2026-73283" title="CVE-2026-73283" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="openssh-client" version="1:7.9p1-10+deb10u4+tuxcare.els7">
          <filename>openssh-client_7.9p1-10+deb10u4+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">f6534ff5482f5a04fdda3164f29852cec9c56ae0</sum>
        </package>
        <package arch="amd64" name="openssh-server" version="1:7.9p1-10+deb10u4+tuxcare.els7">
          <filename>openssh-server_7.9p1-10+deb10u4+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">dc2c9ef80e98725a733d4c74ed1337fb0741b093</sum>
        </package>
        <package arch="amd64" name="openssh-sftp-server" version="1:7.9p1-10+deb10u4+tuxcare.els7">
          <filename>openssh-sftp-server_7.9p1-10+deb10u4+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">d717c72d52c4d76a4058b02c7c779243cdff04d9</sum>
        </package>
        <package arch="amd64" name="openssh-tests" version="1:7.9p1-10+deb10u4+tuxcare.els7">
          <filename>openssh-tests_7.9p1-10+deb10u4+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">8c11d2808626df41c4373de98206b2042501a77e</sum>
        </package>
        <package arch="all" name="ssh" version="1:7.9p1-10+deb10u4+tuxcare.els7">
          <filename>ssh_7.9p1-10+deb10u4+tuxcare.els7_all.deb</filename>
          <sum type="sha">ff56a495913908d57982e1c765299b6d03de9e75</sum>
        </package>
        <package arch="amd64" name="ssh-askpass-gnome" version="1:7.9p1-10+deb10u4+tuxcare.els7">
          <filename>ssh-askpass-gnome_7.9p1-10+deb10u4+tuxcare.els7_amd64.deb</filename>
          <sum type="sha">00b588990eb1d177b74ba1be563a156d3b4bde86</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1787656450</id>
    <title>Fix CVE(s): CVE-2023-6270, CVE-2026-31431, CVE-2026-53043</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * Bump kernel ABI to 28: ship the ELS kernel as linux-image-4.19.0-28-*,
     distinct from Debian stock 4.19.0-27.
   * Backport security fixes for CVE-2026-31431 (af_alg / AEAD):
     - crypto: authencesn - reject too-short AAD (assoclen&lt;8) to match ESP/ESN spec
     - crypto: scatterwalk - Backport memcpy_sglist()
     - crypto: authencesn - Do not place hiseq at end of dst for out-of-place
       decryption
     - crypto: authencesn - Fix src offset when decrypting in-place
     - crypto: algif_aead - use memcpy_sglist() instead of null skcipher
     - crypto: algif_aead - Revert to operating out-of-place
     - crypto: algif_aead - snapshot IV for async AEAD requests
     - crypto: authenc - use memcpy_sglist() instead of null skcipher
     - crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl
     - crypto: algif_aead - Fix minimum RX size check for decryption
   * Backport security fixes for CVE-2026-53043 (ocfs2/dlm out-of-bounds):
     - ocfs2/dlm: validate qr_numregions in dlm_match_regions()
     - ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison
   * New upstream stable update:
     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.317
     - wifi: mac80211: mesh: Fix leak of mesh_preq_queue objects
     - wifi: mac80211: Fix deadlock in ieee80211_sta_ps_deliver_wakeup()
     - wifi: iwlwifi: mvm: revert gen2 TX A-MPDU size to 64
     - wifi: iwlwifi: mvm: don't read past the mfuart notifcation
     - ipv6: sr: block BH in seg6_output_core() and seg6_input_core()
     - vxlan: Fix regression when dropping packets due to invalid src addresses
     - tcp: count CLOSE-WAIT sockets for TCP_MIB_CURRESTAB
     - ptp: Fix error message on failed pin verification
     - af_unix: Annotate data-race of sk-&gt;sk_state in unix_inq_len().
     - af_unix: Annotate data-races around sk-&gt;sk_state in unix_write_space() and poll().
     - af_unix: Annotate data-races around sk-&gt;sk_state in sendmsg() and recvmsg().
     - af_unix: Annotate data-races around sk-&gt;sk_state in UNIX_DIAG.
     - af_unix: Annotate data-race of net-&gt;unx.sysctl_max_dgram_qlen.
     - af_unix: Use unix_recvq_full_lockless() in unix_stream_connect().
     - af_unix: Use skb_queue_len_lockless() in sk_diag_show_rqlen().
     - af_unix: Annotate data-race of sk-&gt;sk_shutdown in sk_diag_fill().
     - usb: gadget: f_fs: Fix race between aio_cancel() and AIO request complete
     - drm/amd/display: Handle Y carry-over in VCP X.Y calculation
     - serial: sc16is7xx: replace hardcoded divisor value with BIT() macro
     - serial: sc16is7xx: fix bug in sc16is7xx_set_baud() when using prescaler
     - media: mc: mark the media devnode as registered from the, start
     - selftests/mm: compaction_test: fix incorrect write of zero to nr_hugepages
     - selftests/mm: conform test to TAP format output
     - selftests/mm: compaction_test: fix bogus test success on Aarch64
     - nilfs2: Remove check for PageError
     - nilfs2: return the mapped address from nilfs_get_page()
     - nilfs2: fix nilfs_empty_dir() misjudgment and long loop on I/O errors
     - USB: class: cdc-wdm: Fix CPU lockup caused by excessive log messages
     - mei: me: release irq in mei_me_pci_resume error path
     - jfs: xattr: fix buffer overflow for invalid xattr
     - xhci: Apply reset resume quirk to Etron EJ188 xHCI host
     - xhci: Apply broken streams quirk to Etron EJ188 xHCI host
     - Input: try trimming too long modalias strings
     - xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING
     - HID: core: remove unnecessary WARN_ON() in implement()
     - iommu/amd: Fix sysfs leak in iommu init
     - liquidio: Adjust a NULL pointer handling path in lio_vf_rep_copy_packet
     - drm/bridge/panel: Fix runtime warning on panel bridge release
     - tcp: fix race in tcp_v6_syn_recv_sock()
     - Bluetooth: L2CAP: Fix rejecting L2CAP_CONN_PARAM_UPDATE_REQ
     - ipv6/route: Add a missing check on proc_dointvec
     - net/ipv6: Fix the RT cache flush via sysctl using a previous delay
     - drivers: core: synchronize really_probe() and dev_uevent()
     - drm/exynos/vidi: fix memory leak in .get_modes()
     - vmci: prevent speculation leaks by sanitizing event in event_deliver()
     - fs/proc: fix softlockup in __read_vmcore
     - ocfs2: use coarse time for new created files
     - ocfs2: fix races between hole punching and AIO+DIO
     - PCI: rockchip-ep: Remove wrong mask on subsys_vendor_id
     - dmaengine: axi-dmac: fix possible race in remove()
     - intel_th: pci: Add Granite Rapids support
     - intel_th: pci: Add Granite Rapids SOC support
     - intel_th: pci: Add Sapphire Rapids SOC support
     - intel_th: pci: Add Meteor Lake-S support
     - intel_th: pci: Add Lunar Lake support
     - nilfs2: fix potential kernel bug due to lack of writeback flag waiting
     - hv_utils: drain the timesync packets on onchannelcallback
     - hugetlb_encode.h: fix undefined behaviour (34 &lt;&lt; 26)
     - usb-storage: alauda: Check whether the media is initialized
     - rcutorture: Fix rcu_torture_one_read() pipe_count overflow comment
     - batman-adv: bypass empty buckets in batadv_purge_orig_ref()
     - scsi: qedi: Fix crash while reading debugfs attribute
     - powerpc/pseries: Enforce hcall result buffer validity and size
     - powerpc/io: Avoid clang null pointer arithmetic warnings
     - usb: misc: uss720: check for incompatible versions of the Belkin F5U002
     - udf: udftime: prevent overflow in udf_disk_stamp_to_time()
     - PCI/PM: Avoid D3cold for HP Pavilion 17 PC/1972 PCIe Ports
     - MIPS: Octeon: Add PCIe link status check
     - MIPS: Routerboard 532: Fix vendor retry check code
     - cipso: fix total option length computation
     - netrom: Fix a memory leak in nr_heartbeat_expiry()
     - ipv6: prevent possible NULL dereference in rt6_probe()
     - xfrm6: check ip6_dst_idev() return value in xfrm6_get_saddr()
     - virtio_net: checksum offloading handling fix
     - net: usb: rtl8150 fix unintiatilzed variables in rtl8150_get_link_ksettings
     - regulator: core: Fix modpost error "regulator_get_regmap" undefined
     - dmaengine: ioatdma: Fix missing kmem_cache_destroy()
     - ACPICA: Revert "ACPICA: avoid Info: mapping multiple BARs. Your kernel is fine."
     - drm/radeon: fix UBSAN warning in kv_dpm.c
     - gcov: add support for GCC 14
     - ARM: dts: samsung: smdkv310: fix keypad no-autorepeat
     - ARM: dts: samsung: exynos4412-origen: fix keypad no-autorepeat
     - ARM: dts: samsung: smdk4412: fix keypad no-autorepeat
     - selftests/ftrace: Fix checkbashisms errors
     - tracing: Add MODULE_DESCRIPTION() to preemptirq_delay_test
     - perf/core: Fix missing wakeup when waiting for context reference
     - PCI: Add PCI_ERROR_RESPONSE and related definitions
     - x86/amd_nb: Check for invalid SMN reads
     - iio: dac: ad5592r-base: Replace indio_dev-&gt;mlock with own device lock
     - iio: dac: ad5592r: un-indent code-block for scale read
     - iio: dac: ad5592r: fix temperature channel scaling value
     - scsi: mpt3sas: Add ioc_&lt;level&gt; logging macros
     - scsi: mpt3sas: Gracefully handle online firmware update
     - scsi: mpt3sas: Avoid test/set_bit() operating in non-allocated memory
     - xhci: Use soft retry to recover faster from transaction errors
     - xhci: Set correct transferred length for cancelled bulk transfers
     - usb: xhci: do not perform Soft Retry for some xHCI hosts
     - pinctrl: fix deadlock in create_pinctrl() when handling -EPROBE_DEFER
     - pinctrl: rockchip: fix pinmux bits for RK3328 GPIO2-B pins
     - pinctrl: rockchip: fix pinmux bits for RK3328 GPIO3-B pins
     - pinctrl: rockchip: fix pinmux reset in rockchip_pmx_set
     - drm/amdgpu: fix UBSAN warning in kv_dpm.c
     - netfilter: nf_tables: validate family when identifying table via handle
     - ASoC: fsl-asoc-card: set priv-&gt;pdev before using it
     - netfilter: nf_tables: fully validate NFT_DATA_VALUE on store to data registers
     - drm/panel: ilitek-ili9881c: Fix warning with GPIO controllers that sleep
     - net/iucv: Avoid explicit cpumask var allocation on stack
     - ALSA: emux: improve patch ioctl data validation
     - media: dvbdev: Initialize sbuf
     - soc: ti: wkup_m3_ipc: Send NULL dummy message instead of pointer message
     - nvme: fixup comment for nvme RDMA Provider Type
     - gpio: davinci: Validate the obtained number of IRQs
     - i2c: ocores: stop transfer on timeout
     - i2c: ocores: set IACK bit after core is enabled
     - x86: stop playing stack games in profile_pc()
     - mmc: sdhci-pci: Convert PCIBIOS_* return codes to errnos
     - iio: adc: ad7266: Fix variable checking bug
     - iio: chemical: bme680: Fix pressure value output
     - iio: chemical: bme680: Fix calibration data variable
     - iio: chemical: bme680: Fix overflows in compensate() functions
     - iio: chemical: bme680: Fix sensor data read operation
     - net: usb: ax88179_178a: improve link status logs
     - usb: gadget: printer: SS+ support
     - usb: musb: da8xx: fix a resource leak in probe()
     - usb: atm: cxacru: fix endpoint checking in cxacru_bind()
     - tty: mcf: MCF54418 has 10 UARTS
     - hexagon: fix fadvise64_64 calling conventions
     - drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_ld_modes
     - drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_hd_modes
     - batman-adv: Don't accept TT entries for out-of-spec VIDs
     - ata: libata-core: Fix double free on error
     - ftruncate: pass a signed offset
     - pwm: stm32: Refuse too small period requests
     - ipv6: annotate some data-races around sk-&gt;sk_prot
     - ipv6: Fix data races around sk-&gt;sk_prot.
     - tcp: Fix data races around icsk-&gt;icsk_af_ops.
     - arm64: dts: rockchip: Add sound-dai-cells for RK3368
     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.318
     - asm-generic: Move common compat types to asm-generic/compat.h
     - media: dvb: as102-fe: Fix as10x_register_addr packing
     - media: dvb-usb: dib0700_devices: Add missing release_firmware()
     - IB/core: Implement a limit on UMAD receive List
     - drm/amd/display: Skip finding free audio for unknown engine_id
     - media: dw2102: Don't translate i2c read into write
     - sctp: prefer struct_size over open coded arithmetic
     - firmware: dmi: Stop decoding on broken entry
     - Input: ff-core - prefer struct_size over open coded arithmetic
     - net: dsa: mv88e6xxx: Correct check for empty list
     - media: dvb-frontends: tda18271c2dd: Remove casting during div
     - media: s2255: Use refcount_t instead of atomic_t for num_channels
     - media: dvb-frontends: tda10048: Fix integer overflow
     - i2c: i801: Annotate apanel_addr as __ro_after_init
     - powerpc/64: Set _IO_BASE to POISON_POINTER_DELTA not 0 for CONFIG_PCI=n
     - orangefs: fix out-of-bounds fsid access
     - powerpc/xmon: Check cpu id in commands "c#", "dp#" and "dx#"
     - jffs2: Fix potential illegal address access in jffs2_free_inode
     - s390/pkey: Wipe sensitive data on failure
     - tcp: take care of compressed acks in tcp_add_reno_sack()
     - tcp: tcp_mark_head_lost is only valid for sack-tcp
     - tcp: add ece_ack flag to reno sack functions
     - net: tcp better handling of reordering then loss cases
     - UPSTREAM: tcp: fix DSACK undo in fast recovery to call tcp_try_to_open()
     - tcp_metrics: validate source addr length
     - bonding: Fix out-of-bounds read in bond_option_arp_ip_targets_set()
     - selftests: fix OOM in msg_zerocopy selftest
     - selftests: make order checking verbose in msg_zerocopy selftest
     - inet_diag: Initialize pad field in struct inet_diag_req_v2
     - nilfs2: fix inode number range checks
     - nilfs2: add missing check for inode numbers on directory entries
     - mm: optimize the redundant loop of mm_update_owner_next()
     - Bluetooth: Fix incorrect pointer arithmatic in ext_adv_report_evt
     - can: kvaser_usb: Explicitly initialize family in leafimx driver_info struct
     - fsnotify: Do not generate events for O_PATH file descriptors
     - Revert "mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again"
     - drm/nouveau: fix null pointer dereference in nouveau_connector_get_modes
     - drm/amdgpu/atomfirmware: silence UBSAN warning
     - bnx2x: Fix multiple UBSAN array-index-out-of-bounds
     - media: dw2102: fix a potential buffer overflow
     - i2c: pnx: Fix potential deadlock warning from del_timer_sync() call in isr
     - nilfs2: fix incorrect inode allocation from reserved inodes
     - drm/i915: make find_fw_domain work on intel_uncore
     - tcp: fix incorrect undo caused by DSACK of TLP retransmit
     - net: lantiq_etop: add blank line after declaration
     - net: ethernet: lantiq_etop: fix double free in detach
     - ppp: reject claimed-as-LCP but actually malformed packets
     - ARM: davinci: Convert comma to semicolon
     - USB: serial: option: add Telit generic core-dump composition
     - USB: serial: option: add Telit FN912 rmnet compositions
     - USB: serial: option: add Fibocom FM350-GL
     - USB: serial: option: add support for Foxconn T99W651
     - USB: serial: option: add Netprisma LCUK54 series modules
     - USB: serial: option: add Rolling RW350-GL variants
     - USB: Add USB_QUIRK_NO_SET_INTF quirk for START BP-850k
     - usb: gadget: configfs: Prevent OOB read/write in usb_string_copy()
     - USB: core: Fix duplicate endpoint bug by clearing reserved bits in the descriptor
     - hpet: Support 32-bit userspace
     - libceph: fix race between delayed_work() and ceph_monc_stop()
     - tcp: refactor tcp_retransmit_timer()
     - net: tcp: fix unexcepted socket die when snd_wnd is 0
     - tcp: use signed arithmetic in tcp_rtx_probe0_timed_out()
     - tcp: avoid too many retransmit packets
     - SUNRPC: Fix RPC client cleaned up the freed pipefs dentries
     - nilfs2: fix kernel bug on rename operation of broken directory
     - i2c: rcar: bring hardware to known state when probing
     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.319
     - gcc-plugins: Rename last_stmt() for GCC 14+
     - scsi: qedf: Set qed_slowpath_params to zero before use
     - ACPI: EC: Abort address space access upon error
     - ACPI: EC: Avoid returning AE_OK on errors in address space handler
     - wifi: mac80211: mesh: init nonpeer_pm to active by default in mesh sdata
     - wifi: mac80211: fix UBSAN noise in ieee80211_prep_hw_scan()
     - Input: silead - Always support 10 fingers
     - ila: block BH in ila_output()
     - kconfig: gconf: give a proper initial state to the Save button
     - kconfig: remove wrong expr_trans_bool()
     - fs/file: fix the check in find_next_fd()
     - mei: demote client disconnect warning on suspend to debug
     - wifi: cfg80211: wext: add extra SIOCSIWSCAN data check
     - Input: elantech - fix touchpad state on resume for Lenovo N24
     - bytcr_rt5640 : inverse jack detect for Archos 101 cesium
     - can: kvaser_usb: fix return value for hif_usb_send_regout
     - s390/sclp: Fix sclp_init() cleanup on failure
     - ALSA: dmaengine_pcm: terminate dmaengine before synchronize
     - net: usb: qmi_wwan: add Telit FN912 compositions
     - net: mac802154: Fix racy device stats updates by DEV_STATS_INC() and DEV_STATS_ADD()
     - Bluetooth: hci_core: cancel all works upon hci_unregister_dev()
     - fs: better handle deep ancestor chains in is_subdir()
     - spi: imx: Don't expect DMA for i.MX{25,35,50,51,53} cspi devices
     - selftests/vDSO: fix clang build errors and warnings
     - hfsplus: fix uninit-value in copy_name
     - filelock: Remove locks reliably when fcntl/close race is detected
     - ARM: 9324/1: fix get_user() broken with veneer
     - ACPI: processor_idle: Fix invalid comparison with insertion sort for latency
     - net: relax socket state check at accept time.
     - ocfs2: add bounds checking to ocfs2_check_dir_entry()
     - jfs: don't walk off the end of ealist
     - filelock: Fix fcntl/close race recovery compat path
     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.320
     - platform/chrome: cros_ec_debugfs: fix wrong EC message version
     - hfsplus: fix to avoid false alarm of circular locking
     - x86/of: Return consistent error type from x86_of_pci_irq_enable()
     - x86/pci/intel_mid_pci: Fix PCIBIOS_* return code handling
     - x86/pci/xen: Fix PCIBIOS_* return code handling
     - x86/platform/iosf_mbi: Convert PCIBIOS_* return codes to errnos
     - hwmon: (adt7475) Fix default duty on fan is disabled
     - pwm: stm32: Always do lazy disabling
     - hwmon: (max6697) Fix underflow when writing limit attributes
     - hwmon: Introduce SENSOR_DEVICE_ATTR_{RO, RW, WO} and variants
     - hwmon: (max6697) Auto-convert to use SENSOR_DEVICE_ATTR_{RO, RW, WO}
     - hwmon: (max6697) Fix swapped temp{1,8} critical alarms
     - arm64: dts: rockchip: Increase VOP clk rate on RK3328
     - m68k: atari: Fix TT bootup freeze / unexpected (SCU) interrupt messages
     - x86/xen: Convert comma to semicolon
     - m68k: cmpxchg: Fix return value for default case in __arch_xchg()
     - wifi: brcmsmac: LCN PHY code is used for BCM4313 2G-only device
     - net/smc: Allow SMC-D 1MB DMB allocations
     - net/smc: set rmb's SG_MAX_SINGLE_ALLOC limitation only when CONFIG_ARCH_NO_SG_CHAIN is defined
     - selftests/bpf: Check length of recv in test_sockmap
     - wifi: cfg80211: fix typo in cfg80211_calculate_bitrate_he()
     - wifi: cfg80211: handle 2x996 RU allocation in cfg80211_calculate_bitrate_he()
     - net: fec: Refactor: #define magic constants
     - net: fec: Fix FEC_ECR_EN1588 being cleared on link-down
     - ipvs: Avoid unnecessary calls to skb_is_gso_sctp
     - perf: Fix perf_aux_size() for greater-than 32-bit size
     - perf: Prevent passing zero nr_pages to rb_alloc_aux()
     - bna: adjust 'name' buf size of bna_tcb and bna_ccb structures
     - selftests: forwarding: devlink_lib: Wait for udev events after reloading
     - media: imon: Fix race getting ictx-&gt;lock
     - saa7134: Unchecked i2c_transfer function result fixed
     - media: uvcvideo: Allow entity-defined get_info and get_cur
     - media: uvcvideo: Override default flags
     - media: renesas: vsp1: Fix _irqsave and _irq mix
     - media: renesas: vsp1: Store RPF partition configuration per RPF instance
     - leds: trigger: Unregister sysfs attributes before calling deactivate()
     - perf report: Fix condition in sort__sym_cmp()
     - drm/etnaviv: fix DMA direction handling for cached RW buffers
     - mfd: omap-usb-tll: Use struct_size to allocate tll
     - ext4: avoid writing unitialized memory to disk in EA inodes
     - sparc64: Fix incorrect function signature and add prototype for prom_cif_init
     - PCI: Equalize hotplug memory and io for occupied and empty slots
     - PCI: Fix resource double counting on remove &amp; rescan
     - RDMA/mlx4: Fix truncated output warning in mad.c
     - RDMA/mlx4: Fix truncated output warning in alias_GUID.c
     - RDMA/rxe: Don't set BTH_ACK_MASK for UC or UD QPs
     - mtd: make mtd_test.c a separate module
     - Input: elan_i2c - do not leave interrupt disabled on suspend failure
     - MIPS: Octeron: remove source file executable bit
     - powerpc/xmon: Fix disassembly CPU feature checks
     - macintosh/therm_windtunnel: fix module unload.
     - bnxt_re: Fix imm_data endianness
     - ice: Rework flex descriptor programming
     - netfilter: ctnetlink: use helper function to calculate expect ID
     - pinctrl: core: fix possible memory leak when pinctrl_enable() fails
     - pinctrl: single: fix possible memory leak when pinctrl_enable() fails
     - pinctrl: ti: ti-iodelay: Drop if block with always false condition
     - pinctrl: ti: ti-iodelay: fix possible memory leak when pinctrl_enable() fails
     - pinctrl: freescale: mxs: Fix refcount of child
     - fs/nilfs2: remove some unused macros to tame gcc
     - nilfs2: avoid undefined behavior in nilfs_cnt32_ge macro
     - tick/broadcast: Make takeover of broadcast hrtimer reliable
     - net: netconsole: Disable target before netpoll cleanup
     - af_packet: Handle outgoing VLAN packets without hardware offloading
     - ipv6: take care of scope when choosing the src addr
     - char: tpm: Fix possible memory leak in tpm_bios_measurements_open()
     - media: venus: fix use after free in vdec_close
     - hfs: fix to initialize fields of hfs_inode_info after hfs_alloc_inode()
     - drm/gma500: fix null pointer dereference in cdv_intel_lvds_get_modes
     - drm/gma500: fix null pointer dereference in psb_intel_lvds_get_modes
     - m68k: amiga: Turn off Warp1260 interrupts during boot
     - ext4: check dot and dotdot of dx_root before making dir indexed
     - ext4: make sure the first directory block is not a hole
     - wifi: mwifiex: Fix interface type change
     - leds: ss4200: Convert PCIBIOS_* return codes to errnos
     - tools/memory-model: Fix bug in lock.cat
     - hwrng: amd - Convert PCIBIOS_* return codes to errnos
     - PCI: hv: Return zero, not garbage, when reading PCI_INTERRUPT_PIN
     - binder: fix hang of unregistered readers
     - scsi: qla2xxx: Return ENOBUFS if sg_cnt is more than one for ELS cmds
     - f2fs: fix to don't dirty inode for readonly filesystem
     - clk: davinci: da8xx-cfgchip: Initialize clk_init_data before use
     - ubi: eba: properly rollback inside self_check_eba
     - decompress_bunzip2: fix rare decompression failure
     - kobject_uevent: Fix OOB access within zap_modalias_env()
     - rtc: cmos: Fix return value of nvmem callbacks
     - scsi: qla2xxx: During vport delete send async logout explicitly
     - scsi: qla2xxx: validate nvme_local_port correctly
     - perf/x86/intel/pt: Fix topa_entry base length
     - watchdog/perf: properly initialize the turbo mode timestamp and rearm counter
     - platform: mips: cpu_hwmon: Disable driver on unsupported hardware
     - RDMA/iwcm: Fix a use-after-free related to destroying CM IDs
     - selftests/sigaltstack: Fix ppc64 GCC build
     - nilfs2: handle inconsistent state in nilfs_btnode_create_block()
     - kdb: Fix bound check compiler warning
     - kdb: address -Wformat-security warnings
     - kdb: Use the passed prompt in kdb_position_cursor()
     - jfs: Fix array-index-out-of-bounds in diFree
     - dma: fix call order in dmam_free_coherent
     - MIPS: SMP-CPS: Fix address for GCR_ACCESS register for CM3 and later
     - net: ip_rt_get_source() - use new style struct initializer instead of memset
     - ipv4: Fix incorrect source address in Record Route option
     - net: bonding: correctly annotate RCU in bond_should_notify_peers()
     - tipc: Return non-zero value from tipc_udp_addr2str() on error
     - mISDN: Fix a use after free in hfcmulti_tx()
     - mm: avoid overflows in dirty throttling logic
     - PCI: rockchip: Make 'ep-gpios' DT property optional
     - PCI: rockchip: Use GPIOD_OUT_LOW flag while requesting ep_gpio
     - parport: parport_pc: Mark expected switch fall-through
     - parport: Convert printk(KERN_&lt;LEVEL&gt; to pr_&lt;level&gt;(
     - parport: Standardize use of printmode
     - dev/parport: fix the array out-of-bounds risk
     - driver core: Cast to (void *) with __force for __percpu pointer
     - devres: Fix memory leakage caused by driver API devm_free_percpu()
     - perf/x86/intel/pt: Export pt_cap_get()
     - perf/x86/intel/pt: Use helpers to obtain ToPA entry size
     - perf/x86/intel/pt: Use pointer arithmetics instead in ToPA entry calculation
     - perf/x86/intel/pt: Split ToPA metadata and page layout
     - perf/x86/intel/pt: Fix a topa_entry base address calculation
     - remoteproc: imx_rproc: ignore mapping vdev regions
     - remoteproc: imx_rproc: Fix ignoring mapping vdev regions
     - remoteproc: imx_rproc: Skip over memory region when node value is NULL
     - drm/vmwgfx: Fix overlay when using Screen Targets
     - net/iucv: fix use after free in iucv_sock_close()
     - ipv6: fix ndisc_is_useropt() handling for PIO
     - protect the fetch of -&gt;fd[fd] in do_dup2() from mispredictions
     - ALSA: usb-audio: Correct surround channels in UAC1 channel map
     - net: usb: sr9700: fix uninitialized variable use in sr_mdio_read
     - irqchip/mbigen: Fix mbigen node address layout
     - x86/mm: Fix pti_clone_pgtable() alignment assumption
     - net: usb: qmi_wwan: fix memory leak for not ip packets
     - net: linkwatch: use system_unbound_wq
     - Bluetooth: l2cap: always unlock channel in l2cap_conless_channel()
     - net: fec: Stop PPS on driver remove
     - md/raid5: avoid BUG_ON() while continue reshape after reassembling
     - clocksource/drivers/sh_cmt: Address race condition for clock events
     - PCI: Add Edimax Vendor ID to pci_ids.h
     - udf: prevent integer overflow in udf_bitmap_free_blocks()
     - wifi: nl80211: don't give key data to userspace
     - btrfs: fix bitmap leak when loading free space cache on duplicate entry
     - media: uvcvideo: Ignore empty TS packets
     - media: uvcvideo: Fix the bandwdith quirk on USB 3.x
     - jbd2: avoid memleak in jbd2_journal_write_metadata_buffer
     - s390/sclp: Prevent release of buffer in I/O
     - SUNRPC: Fix a race to wake a sync task
     - ext4: fix wrong unit use in ext4_mb_find_by_goal
     - arm64: Add support for SB barrier and patch in over DSB; ISB sequences
     - arm64: cpufeature: Force HWCAP to be based on the sysreg visible to user-space
     - arm64: Add Neoverse-V2 part
     - arm64: cputype: Add Cortex-X4 definitions
     - arm64: cputype: Add Neoverse-V3 definitions
     - arm64: errata: Add workaround for Arm errata 3194386 and 3312417
     - arm64: cputype: Add Cortex-X3 definitions
     - arm64: cputype: Add Cortex-A720 definitions
     - arm64: cputype: Add Cortex-X925 definitions
     - arm64: errata: Unify speculative SSBS errata logic
     - arm64: errata: Expand speculative SSBS workaround
     - arm64: cputype: Add Cortex-X1C definitions
     - arm64: cputype: Add Cortex-A725 definitions
     - arm64: errata: Expand speculative SSBS workaround (again)
     - i2c: smbus: Don't filter out duplicate alerts
     - i2c: smbus: Improve handling of stuck alerts
     - i2c: smbus: Send alert notifications to all devices if source not found
     - bpf: kprobe: remove unused declaring of bpf_kprobe_override
     - spi: lpspi: Replace all "master" with "controller"
     - spi: lpspi: Add slave mode support
     - spi: lpspi: Let watermark change with send data length
     - spi: lpspi: Add i.MX8 boards support for lpspi
     - spi: lpspi: add the error info of transfer speed setting
     - spi: fsl-lpspi: remove unneeded array
     - spi: spi-fsl-lpspi: Fix scldiv calculation
     - ALSA: line6: Fix racy access to midibuf
     - usb: vhci-hcd: Do not drop references before new references are gained
     - USB: serial: debug: do not echo input by default
     - usb: gadget: core: Check for unset descriptor
     - scsi: ufs: core: Fix hba-&gt;last_dme_cmd_tstamp timestamp updating logic
     - tick/broadcast: Move per CPU pointer access into the atomic section
     - ntp: Clamp maxerror and esterror to operating range
     - driver core: Fix uevent_show() vs driver detach race
     - ntp: Safeguard against time_constant overflow
     - serial: core: check uartclk for zero to avoid divide by zero
     - power: supply: axp288_charger: Fix constant_charge_voltage writes
     - power: supply: axp288_charger: Round constant_charge_voltage writes down
     - tracing: Fix overflow in get_free_elt()
     - x86/mtrr: Check if fixed MTRRs exist before saving them
     - drm/bridge: analogix_dp: properly handle zero sized AUX transactions
     - drm/mgag200: Set DDC timeout in milliseconds
     - kbuild: Fix '-S -c' in x86 stack protector scripts
     - netfilter: nf_tables: set element extended ACK reporting support
     - netfilter: nf_tables: use timestamp to check for set element timeout
     - netfilter: nf_tables: prefer nft_chain_validate
     - arm64: cpufeature: Fix the visibility of compat hwcaps
     - media: uvcvideo: Use entity get_cur in uvc_ctrl_set
     - drm/i915/gem: Fix Virtual Memory mapping boundaries calculation
     - exec: Fix ToCToU between perm check and set-uid/gid usage
     - nvme/pci: Add APST quirk for Lenovo N60z laptop
     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.321
     - fuse: Initialize beyond-EOF page contents before setting uptodate
     - ALSA: usb-audio: Support Yamaha P-125 quirk entry
     - xhci: Fix Panther point NULL pointer deref at full-speed re-enumeration
     - arm64: ACPI: NUMA: initialize all values of acpi_early_node_map to NUMA_NO_NODE
     - dm resume: don't return EINVAL when signalled
     - dm persistent data: fix memory allocation failure
     - bitmap: introduce generic optimized bitmap_size()
     - fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE
     - selinux: fix potential counting error in avc_add_xperms_decision()
     - drm/amdgpu: Actually check flags for all context ops.
     - memcg_write_event_control(): fix a user-triggerable oops
     - s390/cio: rename bitmap_size() -&gt; idset_bitmap_size()
     - overflow.h: Add flex_array_size() helper
     - overflow: Implement size_t saturating arithmetic helpers
     - btrfs: rename bitmap_set_bits() -&gt; btrfs_bitmap_set_bits()
     - net/mlx5e: Correctly report errors for ethtool rx flows
     - atm: idt77252: prevent use after free in dequeue_rx()
     - net: dsa: vsc73xx: pass value in phy_write operation
     - ssb: Fix division by zero issue in ssb_calc_clock_rate
     - wifi: cw1200: Avoid processing an invalid TIM IE
     - i2c: riic: avoid potential division by zero
     - staging: ks7010: disable bh on tx_dev_lock
     - binfmt_misc: cleanup on filesystem umount
     - scsi: spi: Fix sshdr use
     - gfs2: setattr_chown: Add missing initialization
     - wifi: iwlwifi: abort scan when rfkill on but device enabled
     - powerpc/xics: Check return value of kasprintf in icp_native_map_one_cpu
     - ext4: do not trim the group with corrupted block bitmap
     - quota: Remove BUG_ON from dqget()
     - media: pci: cx23885: check cx23885_vdev_init() return
     - fs: binfmt_elf_efpic: don't use missing interpreter's properties
     - scsi: lpfc: Initialize status local variable in lpfc_sli4_repost_sgl_list()
     - net/sun3_82586: Avoid reading past buffer in debug output
     - md: clean up invalid BUG_ON in md_ioctl
     - parisc: Use irq_enter_rcu() to fix warning at kernel/context_tracking.c:367
     - powerpc/boot: Handle allocation failure in simple_realloc()
     - powerpc/boot: Only free if realloc() succeeds
     - btrfs: change BUG_ON to assertion when checking for delayed_node root
     - btrfs: handle invalid root reference found in may_destroy_subvol()
     - btrfs: send: handle unexpected data in header buffer in begin_cmd()
     - btrfs: delete pointless BUG_ON check on quota root in btrfs_qgroup_account_extent()
     - f2fs: fix to do sanity check in update_sit_entry
     - usb: gadget: fsl: Increase size of name buffer for endpoints
     - Bluetooth: bnep: Fix out-of-bound access
     - NFS: avoid infinite loop in pnfs_update_layout.
     - openrisc: Call setup_memory() earlier in the init sequence
     - s390/iucv: fix receive buffer virtual vs physical address confusion
     - usb: dwc3: core: Skip setting event buffers for host only controllers
     - irqchip/gic-v3-its: Remove BUG_ON in its_vpe_irq_domain_alloc
     - ext4: set the type of max_zeroout to unsigned int to avoid overflow
     - nvmet-rdma: fix possible bad dereference when freeing rsps
     - hrtimer: Prevent queuing of hrtimer without a function callback
     - gtp: pull network headers in gtp_dev_xmit()
     - block: use "unsigned long" for blk_validate_block_size().
     - Bluetooth: Make use of __check_timeout on hci_sched_le
     - Bluetooth: hci_core: Fix not handling link timeouts propertly
     - Bluetooth: hci_core: Fix LE quote calculation
     - kcm: Serialise kcm_sendmsg() for the same socket.
     - netfilter: nft_counter: Synchronize nft_counter_reset() against reader.
     - ipv6: prevent UAF in ip6_send_skb()
     - net: xilinx: axienet: Always disable promiscuous mode
     - drm/msm: use drm_debug_enabled() to check for debug categories
     - drm/msm/dpu: don't play tricks with debug macros
     - mmc: mmc_test: Fix NULL dereference on allocation failure
     - Bluetooth: MGMT: Add error handling to pair_device()
     - HID: wacom: Defer calculation of resolution until resolution_code is known
     - cxgb4: add forgotten u64 ivlan cast before shift
     - mmc: dw_mmc: allow biu and ciu clocks to defer
     - ALSA: timer: Relax start tick time check for slave timer elements
     - Bluetooth: hci_ldisc: check HCI_UART_PROTO_READY flag in HCIUARTGETPROTO
     - Input: MT - limit max slots
     - tools: move alignment-related macros to new &lt;linux/align.h&gt;
     - drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc
     - pinctrl: single: fix potential NULL dereference in pcs_get_function()
     - wifi: mwifiex: duplicate static structs used in driver instances
     - dm suspend: return -ERESTARTSYS instead of -EINTR
     - scsi: mpt3sas: Avoid IOMMU page faults on REPORT ZONES
     - filelock: Correct the filelock owner in fcntl_setlk/fcntl_setlk64
     - media: uvcvideo: Fix integer overflow calculating timestamp
     - ata: libata-core: Fix null pointer dereference on error
     - cgroup/cpuset: Prevent UAF in proc_cpuset_show()
     - memcg: enable accounting of ipc resources
     - fbcon: Prevent that screen size is smaller than font size
     - fbmem: Check virtual screen sizes in fb_set_var()
     - net:rds: Fix possible deadlock in rds_message_put
     - ida: Fix crash in ida_free when the bitmap is empty
     - net: prevent mss overflow in skb_segment()
     - soundwire: stream: fix programming slave ports for non-continous port maps
     - gtp: fix a potential NULL pointer dereference
     - net: busy-poll: use ktime_get_ns() instead of local_clock()
     - cdc-acm: Add DISABLE_ECHO quirk for GE HealthCare UI Controller
     - USB: serial: option: add MeiG Smart SRM825L
     - usb: dwc3: omap: add missing depopulate in probe error path
     - usb: dwc3: core: Prevent USB core invalid event buffer address access
     - usb: dwc3: st: fix probed platform device ref count on probe error path
     - usb: core: sysfs: Unmerge @usb3_hardware_lpm_attr_group in remove_power_attributes()
     - scsi: aacraid: Fix double-free on probe failure
     - ipc: remove memcg accounting for sops objects in do_semtimedop()
     - drm/fb-helper: set x/yres_virtual in drm_fb_helper_check_var
     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.322
     - net: usb: qmi_wwan: add MeiG Smart SRM825L
     - usb: dwc3: st: Add of_node_put() before return in probe function
     - usb: dwc3: st: add missing depopulate in probe error path
     - drm/amdgpu: Fix uninitialized variable warning in amdgpu_afmt_acr
     - drm/amdgpu: fix overflowed array index read warning
     - drm/amdgpu: fix ucode out-of-bounds read warning
     - drm/amdgpu: fix mc_data out-of-bounds read warning
     - drm/amdkfd: Reconcile the definition and use of oem_id in struct kfd_topology_device
     - apparmor: fix possible NULL pointer dereference
     - usbip: Don't submit special requests twice
     - smack: tcp: ipv4, fix incorrect labeling
     - media: uvcvideo: Enforce alignment of frame and interval
     - block: initialize integrity buffer to zero before writing it to media
     - virtio_net: Fix napi_skb_cache_put warning
     - udf: Limit file size to 4TB
     - ALSA: usb-audio: Sanity checks for each pipe and EP types
     - ALSA: usb-audio: Fix gpf in snd_usb_pipe_sanity_check
     - sch/netem: fix use after free in netem_dequeue
     - ALSA: hda/conexant: Add pincfg quirk to enable top speakers on Sirius devices
     - ata: libata: Fix memory leak for error path in ata_host_alloc()
     - mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K
     - fuse: use unsigned type for getxattr/listxattr size truncation
     - clk: qcom: clk-alpha-pll: Fix the pll post div mask
     - nilfs2: fix missing cleanup on rollforward recovery error
     - nilfs2: fix state management in error path of log writing function
     - ALSA: hda: Add input value sanity checks to HDMI channel map controls
     - smack: unix sockets: fix accept()ed socket label
     - irqchip/armada-370-xp: Do not allow mapping IRQ 0 and 1
     - af_unix: Remove put_pid()/put_cred() in copy_peercred().
     - netfilter: nf_conncount: fix wrong variable type
     - udf: Avoid excessive partition lengths
     - wifi: brcmsmac: advertise MFP_CAPABLE to enable WPA3
     - media: qcom: camss: Add check for v4l2_fwnode_endpoint_parse
     - pcmcia: Use resource_size function on resource object
     - can: bcm: Remove proc entry when dev is unregistered.
     - igb: Fix not clearing TimeSync interrupts for 82580
     - platform/x86: dell-smbios: Fix error path in dell_smbios_init()
     - cx82310_eth: re-enable ethernet mode after router reboot
     - drivers/net/usb: Remove all strcpy() uses
     - net: usb: don't write directly to netdev-&gt;dev_addr
     - usbnet: modern method to get random MAC
     - rfkill: fix spelling mistake contidion to condition
     - net: bridge: add support for sticky fdb entries
     - bridge: switchdev: Allow clearing FDB entry offload indication
     - net: bridge: fdb: convert is_local to bitops
     - net: bridge: fdb: convert is_static to bitops
     - net: bridge: fdb: convert is_sticky to bitops
     - net: bridge: fdb: convert added_by_user to bitops
     - net: bridge: fdb: convert added_by_external_learn to use bitops
     - net: bridge: br_fdb_external_learn_add(): always set EXT_LEARN
     - net: dsa: vsc73xx: fix possible subblocks range of CAPT block
     - iommu/vt-d: Handle volatile descriptor status read
     - cgroup: Protect css-&gt;cgroup write under css_set_lock
     - um: line: always fill *error_out in setup_one_line()
     - devres: Initialize an uninitialized struct member
     - pci/hotplug/pnv_php: Fix hotplug driver crash on Powernv
     - hwmon: (adc128d818) Fix underflows seen when writing limit attributes
     - hwmon: (lm95234) Fix underflows seen when writing limit attributes
     - hwmon: (nct6775-core) Fix underflows seen when writing limit attributes
     - hwmon: (w83627ehf) Fix underflows seen when writing limit attributes
     - wifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id()
     - smp: Add missing destroy_work_on_stack() call in smp_call_on_cpu()
     - btrfs: replace BUG_ON with ASSERT in walk_down_proc()
     - btrfs: clean up our handling of refs == 0 in snapshot delete
     - PCI: Add missing bridge lock to pci_bus_lock()
     - btrfs: initialize location to fix -Wmaybe-uninitialized in btrfs_lookup_dentry()
     - HID: cougar: fix slab-out-of-bounds Read in cougar_report_fixup
     - Input: uinput - reject requests with unreasonable number of slots
     - usbnet: ipheth: race between ipheth_close and error handling
     - Squashfs: sanity check symbolic link size
     - of/irq: Prevent device address out-of-bounds read in interrupt map walk
     - ata: pata_macio: Use WARN instead of BUG
     - iio: buffer-dmaengine: fix releasing dma channel on error
     - iio: fix scale application in iio_convert_raw_to_processed_unlocked
     - nvmem: Fix return type of devm_nvmem_device_get() in kerneldoc
     - uio_hv_generic: Fix kernel NULL pointer dereference in hv_uio_rescind
     - Drivers: hv: vmbus: Fix rescind handling in uio_hv_generic
     - VMCI: Fix use-after-free when removing resource in vmci_resource_remove()
     - clocksource/drivers/imx-tpm: Fix return -ETIME when delta exceeds INT_MAX
     - clocksource/drivers/imx-tpm: Fix next event not taking effect sometime
     - uprobes: Use kzalloc to allocate xol area
     - ring-buffer: Rename ring_buffer_read() to read_buffer_iter_advance()
     - tracing: Avoid possible softlockup in tracing_iter_reset()
     - nilfs2: replace snprintf in show functions with sysfs_emit
     - nilfs2: protect references to superblock parameters exposed in sysfs
     - netns: add pre_exit method to struct pernet_operations
     - ila: call nf_unregister_net_hooks() sooner
     - ACPI: processor: Return an error if acpi_processor_get_info() fails in processor_add()
     - ACPI: processor: Fix memory leaks in error paths of processor_add()
     - drm/i915/fence: Mark debug_fence_init_onstack() with __maybe_unused
     - drm/i915/fence: Mark debug_fence_free() with __maybe_unused
     - rtmutex: Drop rt_mutex::wait_lock before scheduling
     - net, sunrpc: Remap EPERM in case of connection failure in xs_tcp_setup_socket
     - cx82310_eth: fix error return code in cx82310_bind()
     - netns: restore ops before calling ops_exit_list
     - Revert "parisc: Use irq_enter_rcu() to fix warning at kernel/context_tracking.c:367"
     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.323
     - staging: iio: frequency: ad9833: Get frequency value statically
     - staging: iio: frequency: ad9833: Load clock using clock framework
     - staging: iio: frequency: ad9834: Validate frequency parameter value
     - usbnet: ipheth: fix carrier detection in modes 1 and 4
     - net: ethernet: use ip_hdrlen() instead of bit shift
     - net: phy: vitesse: repair vsc73xx autonegotiation
     - scripts: kconfig: merge_config: config files: add a trailing newline
     - arm64: dts: rockchip: override BIOS_DISABLE signal via GPIO hog on RK3399 Puma
     - net/mlx5: Update the list of the PCI supported devices
     - net: ftgmac100: Enable TX interrupt to avoid TX timeout
     - net: dpaa: Pad packets to ETH_ZLEN
     - soundwire: stream: Revert "soundwire: stream: fix programming slave ports for non-continous port maps"
     - selftests/vm: remove call to ksft_set_plan()
     - selftests/kcmp: remove call to ksft_set_plan()
     - ASoC: allow module autoloading for table db1200_pids
     - pinctrl: at91: make it work with current gpiolib
     - microblaze: don't treat zero reserved memory regions as error
     - net: ftgmac100: Ensure tx descriptor updates are visible
     - wifi: iwlwifi: mvm: fix iwl_mvm_max_scan_ie_fw_cmd_room()
     - wifi: iwlwifi: mvm: don't wait for tx queues if firmware is dead
     - ASoC: tda7419: fix module autoloading
     - spi: bcm63xx: Enable module autoloading
     - x86/hyperv: Set X86_FEATURE_TSC_KNOWN_FREQ when Hyper-V provides frequency
     - ocfs2: add bounds checking to ocfs2_xattr_find_entry()
     - ocfs2: strict bound check before memcmp in ocfs2_xattr_find_entry()
     - gpio: prevent potential speculation leaks in gpio_device_get_desc()
     - USB: serial: pl2303: add device id for Macrosilicon MS3020
     - ACPI: PMIC: Remove unneeded check in tps68470_pmic_opregion_probe()
     - wifi: ath9k: fix parameter check in ath9k_init_debug()
     - wifi: ath9k: Remove error checks when creating debugfs entries
     - netfilter: nf_tables: elements with timeout below CONFIG_HZ never expire
     - wifi: cfg80211: fix UBSAN noise in cfg80211_wext_siwscan()
     - wifi: cfg80211: fix two more possible UBSAN-detected off-by-one errors
     - wifi: mac80211: use two-phase skb reclamation in ieee80211_do_stop()
     - can: bcm: Clear bo-&gt;bcm_proc_read after remove_proc_entry().
     - Bluetooth: btusb: Fix not handling ZPL/short-transfer
     - block, bfq: fix possible UAF for bfqq-&gt;bic with merge chain
     - block, bfq: choose the last bfqq from merge chain in bfq_setup_cooperator()
     - block, bfq: don't break merge chain in bfq_split_bfqq()
     - spi: ppc4xx: handle irq_of_parse_and_map() errors
     - spi: ppc4xx: Avoid returning 0 when failed to parse and map IRQ
     - ARM: versatile: fix OF node leak in CPUs prepare
     - reset: berlin: fix OF node leak in probe() error path
     - clocksource/drivers/qcom: Add missing iounmap() on errors in msm_dt_timer_init()
     - hwmon: (max16065) Fix overflows seen when writing limits
     - mtd: slram: insert break after errors in parsing the map
     - hwmon: (ntc_thermistor) fix module autoloading
     - power: supply: max17042_battery: Fix SOC threshold calc w/ no current sense
     - fbdev: hpfb: Fix an error handling path in hpfb_dio_probe()
     - drm/stm: Fix an error handling path in stm_drm_platform_probe()
     - drm/amd: fix typo
     - drm/amdgpu: Replace one-element array with flexible-array member
     - drm/amdgpu: properly handle vbios fake edid sizing
     - drm/radeon: Replace one-element array with flexible-array member
     - drm/radeon: properly handle vbios fake edid sizing
     - drm/rockchip: vop: Allow 4096px width scaling
     - drm/radeon/evergreen_cs: fix int overflow errors in cs track offsets
     - jfs: fix out-of-bounds in dbNextAG() and diAlloc()
     - drm/msm/a5xx: properly clear preemption records on resume
     - drm/msm/a5xx: fix races in preemption evaluation stage
     - ipmi: docs: don't advertise deprecated sysfs entries
     - drm/msm: fix %s null argument error
     - xen: use correct end address of kernel for conflict checking
     - xen/swiotlb: simplify range_straddles_page_boundary()
     - xen/swiotlb: add alignment check for dma buffers
     - selftests/bpf: Fix error compiling test_lru_map.c
     - xz: cleanup CRC32 edits from 2018
     - kthread: add kthread_work tracepoints
     - kthread: fix task state in kthread worker if being frozen
     - jbd2: introduce/export functions jbd2_journal_submit|finish_inode_data_buffers()
     - ext4: clear EXT4_GROUP_INFO_WAS_TRIMMED_BIT even mount with discard
     - smackfs: Use rcu_assign_pointer() to ensure safe assignment in smk_set_cipso
     - ext4: avoid negative min_clusters in find_group_orlov()
     - ext4: return error on ext4_find_inline_entry
     - ext4: avoid OOB when system.data xattr changes underneath the filesystem
     - nilfs2: fix potential null-ptr-deref in nilfs_btree_insert()
     - nilfs2: determine empty node blocks as corrupted
     - nilfs2: fix potential oob read in nilfs_btree_check_delete()
     - perf sched timehist: Fix missing free of session in perf_sched__timehist()
     - perf sched timehist: Fixed timestamp error when unable to confirm event sched_in time
     - perf time-utils: Fix 32-bit nsec parsing
     - clk: rockchip: Set parent rate for DCLK_VOP clock on RK3228
     - drivers: media: dvb-frontends/rtl2832: fix an out-of-bounds write error
     - drivers: media: dvb-frontends/rtl2830: fix an out-of-bounds write error
     - PCI: xilinx-nwl: Fix register misspelling
     - RDMA/iwcm: Fix WARNING:at_kernel/workqueue.c:#check_flush_dependency
     - pinctrl: single: fix missing error code in pcs_probe()
     - clk: ti: dra7-atl: Fix leak of of_nodes
     - pinctrl: mvebu: Fix devinit_dove_pinctrl_probe function
     - RDMA/cxgb4: Added NULL check for lookup_atid
     - ntb: intel: Fix the NULL vs IS_ERR() bug for debugfs_create_dir()
     - nfsd: call cache_put if xdr_reserve_space returns NULL
     - f2fs: enhance to update i_mode and acl atomically in f2fs_setattr()
     - f2fs: fix typo
     - f2fs: fix to update i_ctime in __f2fs_setxattr()
     - f2fs: remove unneeded check condition in __f2fs_setxattr()
     - f2fs: reduce expensive checkpoint trigger frequency
     - coresight: tmc: sg: Do not leak sg_table
     - netfilter: nf_reject_ipv6: fix nf_reject_ip6_tcphdr_put()
     - net: seeq: Fix use after free vulnerability in ether3 Driver Due to Race Condition
     - tcp: introduce tcp_skb_timestamp_us() helper
     - tcp: check skb is non-NULL in tcp_rto_delta_us()
     - net: qrtr: Update packets cloning when broadcasting
     - netfilter: ctnetlink: compile ctnetlink_label_size with CONFIG_NF_CONNTRACK_EVENTS
     - crypto: aead,cipher - zeroize key buffer after use
     - Remove *.orig pattern from .gitignore
     - soc: versatile: integrator: fix OF node leak in probe() error path
     - USB: appledisplay: close race between probe and completion handler
     - USB: misc: cypress_cy7c63: check for short transfer
     - firmware_loader: Block path traversal
     - tty: rp2: Fix reset with non forgiving PCIe host bridges
     - drbd: Fix atomicity violation in drbd_uuid_set_bm()
     - drbd: Add NULL check for net_conf to prevent dereference in state validation
     - ACPI: sysfs: validate return type of _STR method
     - f2fs: prevent possible int overflow in dir_block_index()
     - f2fs: avoid potential int overflow in sanity_check_area_boundary()
     - vfs: fix race between evice_inodes() and find_inode()&amp;iput()
     - fs: Fix file_set_fowner LSM hook inconsistencies
     - nfs: fix memory leak in error path of nfs4_do_reclaim
     - PCI: xilinx-nwl: Use irq_data_get_irq_chip_data()
     - PCI: xilinx-nwl: Fix off-by-one in INTx IRQ handler
     - soc: versatile: realview: fix memory leak during device remove
     - soc: versatile: realview: fix soc_dev leak during device remove
     - usb: yurex: Replace snprintf() with the safer scnprintf() variant
     - USB: misc: yurex: fix race between read and write
     - pps: remove usage of the deprecated ida_simple_xx() API
     - pps: add an error check in parport_attach
     - i2c: aspeed: Update the stop sw state when the bus recovery occurs
     - i2c: isch: Add missed 'else'
     - usb: yurex: Fix inconsistent locking bug in yurex_read()
     - mailbox: rockchip: fix a typo in module autoloading
     - mailbox: bcm2835: Fix timeout during suspend mode
     - ceph: remove the incorrect Fw reference check when dirtying pages
     - netfilter: uapi: NFTA_FLOWTABLE_HOOK is NLA_NESTED
     - netfilter: nf_tables: prevent nf_skb_duplicated corruption
     - r8152: Factor out OOB link list waits
     - net: ethernet: lantiq_etop: fix memory disclosure
     - net: avoid potential underflow in qdisc_pkt_len_init() with UFO
     - net: add more sanity checks to qdisc_pkt_len_init()
     - ipv4: ip_gre: Fix drops of small packets in ipgre_xmit
     - sctp: set sk_state back to CLOSED if autobind fails in sctp_listen_start
     - ALSA: hda/generic: Unconditionally prefer preferred_dacs pairs
     - ALSA: hda/conexant: Fix conflicting quirk for System76 Pangolin
     - f2fs: Require FMODE_WRITE for atomic write ioctls
     - wifi: ath9k: fix possible integer overflow in ath9k_get_et_stats()
     - wifi: ath9k_htc: Use __skb_set_length() for resetting urb before resubmit
     - net: hisilicon: hip04: fix OF node leak in probe()
     - net: hisilicon: hns_dsaf_mac: fix OF node leak in hns_mac_get_info()
     - net: hisilicon: hns_mdio: fix OF node leak in probe()
     - ACPICA: Fix memory leak if acpi_ps_get_next_namepath() fails
     - ACPICA: Fix memory leak if acpi_ps_get_next_field() fails
     - ACPI: EC: Do not release locks during operation region accesses
     - ACPICA: check null return of ACPI_ALLOCATE_ZEROED() in acpi_db_convert_to_package()
     - tipc: guard against string buffer overrun
     - net: mvpp2: Increase size of queue_name buffer
     - ipv4: Check !in_dev earlier for ioctl(SIOCSIFADDR).
     - ipv4: Mask upper DSCP bits and ECN bits in NETLINK_FIB_LOOKUP family
     - tcp: avoid reusing FIN_WAIT2 when trying to find port in connect() process
     - ACPICA: iasl: handle empty connection_node
     - wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_cmd_802_11_scan_ext()
     - signal: Replace BUG_ON()s
     - ALSA: asihpi: Fix potential OOB array access
     - ALSA: hdsp: Break infinite MIDI input flush loop
     - fbdev: pxafb: Fix possible use after free in pxafb_task()
     - power: reset: brcmstb: Do not go into infinite loop if reset fails
     - ata: sata_sil: Rename sil_blacklist to sil_quirks
     - jfs: UBSAN: shift-out-of-bounds in dbFindBits
     - jfs: Fix uaf in dbFreeBits
     - jfs: check if leafidx greater than num leaves per dmap tree
     - jfs: Fix uninit-value access of new_ea in ea_buffer
     - drm/amd/display: Check stream before comparing them
     - drm/amd/display: Fix index out of bounds in degamma hardware format translation
     - drm/printer: Allow NULL data in devcoredump printer
     - scsi: aacraid: Rearrange order of struct aac_srb_unit
     - drm/radeon/r100: Handle unknown family in r100_cp_init_microcode()
     - of/irq: Refer to actual buffer size in of_irq_parse_one()
     - ext4: ext4_search_dir should return a proper error
     - ext4: fix i_data_sem unlock order in ext4_ind_migrate()
     - spi: s3c64xx: fix timeout counters in flush_fifo
     - selftests: breakpoints: use remaining time to check if suspend succeed
     - selftests: vDSO: fix vDSO symbols lookup for powerpc64
     - i2c: xiic: Wait for TX empty to avoid missed TX NAKs
     - spi: bcm63xx: Fix module autoloading
     - perf/core: Fix small negative period being ignored
     - parisc: Fix itlb miss handler for 64-bit programs
     - ALSA: core: add isascii() check to card ID generator
     - ext4: no need to continue when the number of entries is 1
     - ext4: propagate errors from ext4_find_extent() in ext4_insert_range()
     - ext4: fix incorrect tid assumption in __jbd2_log_wait_for_space()
     - ext4: aovid use-after-free in ext4_ext_insert_extent()
     - ext4: fix double brelse() the buffer of the extents path
     - ext4: fix incorrect tid assumption in ext4_wait_for_tail_page_commit()
     - parisc: Fix 64-bit userspace syscall path
     - of/irq: Support #msi-cells=&lt;0&gt; in of_msi_get_domain
     - jbd2: stop waiting for space when jbd2_cleanup_journal_tail() returns error
     - ocfs2: fix the la space leak when unmounting an ocfs2 volume
     - ocfs2: fix uninit-value in ocfs2_get_block()
     - ocfs2: reserve space for inline xattr before attaching reflink tree
     - ocfs2: cancel dqi_sync_work before freeing oinfo
     - ocfs2: remove unreasonable unlock in ocfs2_read_blocks
     - ocfs2: fix null-ptr-deref when journal load failed.
     - ocfs2: fix possible null-ptr-deref in ocfs2_set_buffer_uptodate
     - riscv: define ILLEGAL_POINTER_VALUE for 64bit
     - aoe: fix the potential use-after-free problem in more places
     - clk: rockchip: fix error for unknown clocks
     - media: uapi/linux/cec.h: cec_msg_set_reply_to: zero flags
     - media: venus: fix use after free bug in venus_remove due to race condition
     - iio: magnetometer: ak8975: Fix reading for ak099xx sensors
     - tomoyo: fallback to realpath if symlink's pathname does not exist
     - Input: adp5589-keys - fix adp5589_gpio_get_value()
     - btrfs: wait for fixup workers before stopping cleaner kthread during umount
     - gpio: davinci: fix lazy disable
     - ext4: avoid ext4_error()'s caused by ENOMEM in the truncate path
     - ext4: fix slab-use-after-free in ext4_split_extent_at()
     - ext4: update orig_path in ext4_find_extent()
     - arm64: Add Cortex-715 CPU part definition
     - arm64: cputype: Add Neoverse-N3 definitions
     - arm64: errata: Expand speculative SSBS workaround once more
     - uprobes: fix kernel info leak via "[uprobes]" vma
     - nfsd: use ktime_get_seconds() for timestamps
     - nfsd: fix delegation_blocked() to block correctly for at least 30 seconds
     - rtc: at91sam9: drop platform_data support
     - rtc: at91sam9: fix OF node leak in probe() error path
     - ACPI: battery: Simplify battery hook locking
     - ACPI: battery: Fix possible crash when unregistering a battery hook
     - ext4: fix inode tree inconsistency caused by ENOMEM
     - net: ethernet: cortina: Drop TSO support
     - tracing: Remove precision vsnprintf() check from print event
     - drm: Move drm_mode_setcrtc() local re-init to failure path
     - drm/crtc: fix uninitialized variable use even harder
     - virtio_console: fix misc probe bugs
     - Input: synaptics-rmi4 - fix UAF of IRQ domain on driver removal
     - bpf: Check percpu map value size first
     - s390/facility: Disable compile time optimization for decompressor code
     - s390/mm: Add cond_resched() to cmm_alloc/free_pages()
     - ext4: nested locking for xattr inode
     - s390/cpum_sf: Remove WARN_ON_ONCE statements
     - ktest.pl: Avoid false positives with grub2 skip regex
     - clk: bcm: bcm53573: fix OF node leak in init
     - i2c: i801: Use a different adapter-name for IDF adapters
     - PCI: Mark Creative Labs EMU20k2 INTx masking as broken
     - media: videobuf2-core: clear memory related fields in __vb2_plane_dmabuf_put()
     - usb: chipidea: udc: enable suspend interrupt after usb reset
     - tools/iio: Add memory allocation failure check for trigger_name
     - driver core: bus: Return -EIO instead of 0 when show/store invalid bus attribute
     - fbdev: sisfb: Fix strbuf array overflow
     - NFS: Remove print_overflow_msg()
     - SUNRPC: Fix integer overflow in decode_rc_list()
     - tcp: fix tcp_enter_recovery() to zero retrans_stamp when it's safe
     - netfilter: br_netfilter: fix panic with metadata_dst skb
     - Bluetooth: RFCOMM: FIX possible deadlock in rfcomm_sk_state_change
     - gpio: aspeed: Add the flush write to ensure the write complete.
     - clk: Add (devm_)clk_get_optional() functions
     - clk: generalize devm_clk_get() a bit
     - clk: Provide new devm_clk helpers for prepared and enabled clocks
     - gpio: aspeed: Use devm_clk api to manage clock source
     - igb: Do not bring the device up after non-fatal error
     - net: ibm: emac: mal: fix wrong goto
     - ppp: fix ppp_async_encode() illegal access
     - net: ipv6: ensure we call ipv6_mc_down() at most once
     - CDC-NCM: avoid overflow in sanity checking
     - HID: plantronics: Workaround for an unexcepted opposite volume key
     - Revert "usb: yurex: Replace snprintf() with the safer scnprintf() variant"
     - usb: xhci: Fix problem with xhci resume from suspend
     - usb: storage: ignore bogus device raised by JieLi BR21 USB sound chip
     - net: Fix an unsafe loop on the list
     - posix-clock: Fix missing timespec64 check in pc_clock_settime()
     - arm64: probes: Remove broken LDR (literal) uprobe support
     - arm64: probes: Fix simulate_ldr*_literal()
     - PCI: Add function 0 DMA alias quirk for Glenfly Arise chip
     - fat: fix uninitialized variable
     - KVM: Fix a data race on last_boosted_vcpu in kvm_vcpu_on_spin()
     - net: dsa: mv88e6xxx: Fix out-of-bound access
     - s390/sclp_vt220: Convert newlines to CRLF instead of LFCR
     - KVM: s390: Change virtual to physical address access in diag 0x258 handler
     - x86/cpufeatures: Define X86_FEATURE_AMD_IBPB_RET
     - drm/vmwgfx: Handle surface check failure correctly
     - iio: dac: stm32-dac-core: add missing select REGMAP_MMIO in Kconfig
     - iio: adc: ti-ads8688: add missing select IIO_(TRIGGERED_)BUFFER in Kconfig
     - iio: hid-sensors: Fix an error handling path in _hid_sensor_set_report_latency()
     - iio: light: opt3001: add missing full-scale range value
     - Bluetooth: Remove debugfs directory on module init failure
     - Bluetooth: btusb: Fix regression with fake CSR controllers 0a12:0001
     - xhci: Fix incorrect stream context type macro
     - USB: serial: option: add support for Quectel EG916Q-GL
     - USB: serial: option: add Telit FN920C04 MBIM compositions
     - parport: Proper fix for array out-of-bounds access
     - x86/apic: Always explicitly disarm TSC-deadline timer
     - nilfs2: propagate directory read errors from nilfs_find_entry()
     - clk: Fix pointer casting to prevent oops in devm_clk_release()
     - clk: Fix slab-out-of-bounds error in devm_clk_release()
     - RDMA/bnxt_re: Fix incorrect AVID type in WQE structure
     - RDMA/cxgb4: Fix RDMA_CM_EVENT_UNREACHABLE error for iWARP
     - RDMA/bnxt_re: Return more meaningful error
     - drm/msm/dsi: fix 32-bit signed integer extension in pclk_rate calculation
     - macsec: don't increment counters for an unrelated SA
     - net: ethernet: aeroflex: fix potential memory leak in greth_start_xmit_gbit()
     - net: systemport: fix potential memory leak in bcm_sysport_xmit()
     - usb: typec: altmode should keep reference to parent
     - Bluetooth: bnep: fix wild-memory-access in proto_unregister
     - arm64:uprobe fix the uprobe SWBP_INSN in big-endian
     - arm64: probes: Fix uprobes for big-endian kernels
     - KVM: s390: gaccess: Refactor gpa and length calculation
     - KVM: s390: gaccess: Refactor access address range check
     - KVM: s390: gaccess: Cleanup access to guest pages
     - KVM: s390: gaccess: Check if guest address is in memslot
     - udf: fix uninit-value use in udf_get_fileshortad
     - jfs: Fix sanity check in dbMount
     - net/sun3_82586: fix potential memory leak in sun3_82586_send_packet()
     - be2net: fix potential memory leak in be_xmit()
     - net: usb: usbnet: fix name regression
     - posix-clock: posix-clock: Fix unbalanced locking in pc_clock_settime()
     - ALSA: hda/realtek: Update default depop procedure
     - drm/amd: Guard against bad data for ATIF ACPI method
     - ACPI: button: Add DMI quirk for Samsung Galaxy Book2 to fix initial lid detection issue
     - nilfs2: fix kernel bug due to missing clearing of buffer delay flag
     - hv_netvsc: Fix VF namespace also in synthetic NIC NETDEV_REGISTER event
     - selinux: improve error checking in sel_write_load()
     - arm64/uprobes: change the uprobe_opcode_t typedef to fix the sparse warning
     - xfrm: validate new SA's prefixlen using SA family when sel.family is unset
     - usb: dwc3: remove generic PHY calibrate() calls
     - usb: dwc3: Add splitdisable quirk for Hisilicon Kirin Soc
     - usb: dwc3: core: Stop processing of pending events if controller is halted
     - cgroup: Fix potential overflow issue when checking max_depth
     - wifi: mac80211: skip non-uploaded keys in ieee80211_iter_keys
     - gtp: simplify error handling code in 'gtp_encap_enable()'
     - gtp: allow -1 to be specified as file description from userspace
     - net/sched: stop qdisc_tree_reduce_backlog on TC_H_ROOT
     - bpf: Fix out-of-bounds write in trie_get_next_key()
     - net: support ip generic csum processing in skb_csum_hwoffload_help
     - net: skip offload for NETIF_F_IPV6_CSUM if ipv6 header contains extension
     - netfilter: nft_payload: sanitize offset and length before calling skb_checksum()
     - firmware: arm_sdei: Fix the input parameter of cpuhp_remove_state()
     - net: amd: mvme147: Fix probe banner message
     - misc: sgi-gru: Don't disable preemption in GRU driver
     - usbip: tools: Fix detach_port() invalid port error path
     - usb: phy: Fix API devm_usb_put_phy() can not release the phy
     - xhci: Fix Link TRB DMA in command ring stopped completion event
     - Revert "driver core: Fix uevent_show() vs driver detach race"
     - wifi: mac80211: do not pass a stopped vif to the driver in .get_txpower
     - wifi: ath10k: Fix memory leak in management tx
     - wifi: iwlegacy: Clear stale interrupts before resuming device
     - nilfs2: fix potential deadlock with newly created symlinks
     - ocfs2: pass u64 to ocfs2_truncate_inline maybe overflow
     - nilfs2: fix kernel bug due to missing clearing of checked flag
     - mm: shmem: fix data-race in shmem_getattr()
     - vt: prevent kernel-infoleak in con_font_get()
     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.324
     - arm64: dts: rockchip: Fix rt5651 compatible value on rk3399-sapphire-excavator
     - ARM: dts: rockchip: fix rk3036 acodec node
     - ARM: dts: rockchip: drop grf reference from rk3036 hdmi
     - ARM: dts: rockchip: Fix the realtek audio codec on rk3036-kylin
     - HID: core: zero-initialize the report buffer
     - security/keys: fix slab-out-of-bounds in key_task_permission
     - sctp: properly validate chunk size in sctp_sf_ootb()
     - can: c_can: fix {rx,tx}_errors statistics
     - net: hns3: fix kernel crash when uninstalling driver
     - media: stb0899_algo: initialize cfr before using it
     - media: dvbdev: prevent the risk of out of memory access
     - media: dvb_frontend: don't play tricks with underflow values
     - media: adv7604: prevent underflow condition when reporting colorspace
     - ALSA: firewire-lib: fix return value on fail in amdtp_tscm_init()
     - media: s5p-jpeg: prevent buffer overflows
     - media: cx24116: prevent overflows on SNR calculus
     - media: v4l2-tpg: prevent the risk of a division by zero
     - drm/amdgpu: add missing size check in amdgpu_debugfs_gprwave_read()
     - drm/amdgpu: prevent NULL pointer dereference if ATIF is not supported
     - dm cache: correct the number of origin blocks to match the target length
     - dm cache: fix out-of-bounds access to the dirty bitset when resizing
     - dm cache: optimize dirty bit checking with find_next_bit when resizing
     - dm cache: fix potential out-of-bounds access on the first resume
     - dm-unstriped: cast an operand to sector_t to prevent potential uint32_t overflow
     - nfs: Fix KMSAN warning in decode_getfattr_attrs()
     - btrfs: reinitialize delayed ref list after deleting it from the list
     - bonding (gcc13): synchronize bond_{a,t}lb_xmit() types
     - net: bridge: xmit: make sure we have at least eth header len bytes
     - media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format
     - fs/proc: fix compile warning about variable 'vmcore_mmap_ops'
     - usb: musb: sunxi: Fix accessing an released usb phy
     - USB: serial: io_edgeport: fix use after free in debug printk
     - USB: serial: qcserial: add support for Sierra Wireless EM86xx
     - USB: serial: option: add Fibocom FG132 0x0112 composition
     - USB: serial: option: add Quectel RG650V
     - irqchip/gic-v3: Force propagation of the active state with a read-back
     - ocfs2: remove entry once instead of null-ptr-dereference in ocfs2_xa_remove()
     - ALSA: pcm: Return 0 when size &lt; start_threshold in capture
     - ALSA: usb-audio: Add custom mixer status quirks for RME CC devices
     - ALSA: usb-audio: Support jack detection on Dell dock
     - ALSA: usb-audio: Add quirks for Dell WD19 dock
     - hv_sock: Initializing vsk-&gt;trans to NULL to prevent a dangling pointer
     - vsock/virtio: Initialization of the dangling pointer occurring in vsk-&gt;trans
     - ALSA: usb-audio: Add endianness annotations
     - 9p: Avoid creating multiple slab caches with the same name
     - HID: multitouch: Add quirk for HONOR MagicBook Art 14 touchpad
     - bpf: use kvzmalloc to allocate BPF verifier environment
     - sound: Make CONFIG_SND depend on INDIRECT_IOMEM instead of UML
     - powerpc/powernv: Free name on error in opal_event_init()
     - fs: Fix uninitialized value issue in from_kuid and from_kgid
     - net: usb: qmi_wwan: add Fibocom FG132 0x0112 composition
     - 9p: fix slab cache name creation for real
     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.325
     - netlink: terminate outstanding dump on socket close
     - ocfs2: uncache inode which has failed entering the group
     - nilfs2: fix null-ptr-deref in block_touch_buffer tracepoint
     - ocfs2: fix UBSAN warning in ocfs2_verify_volume()
     - nilfs2: fix null-ptr-deref in block_dirty_buffer tracepoint
     - Revert "mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K"
     - media: dvbdev: fix the logic when DVB_DYNAMIC_MINORS is not set
     - kbuild: Use uname for LINUX_COMPILE_HOST detection
     - mm: revert "mm: shmem: fix data-race in shmem_getattr()"
     - ASoC: Intel: bytcr_rt5640: Add DMI quirk for Vexia Edu Atla 10 tablet
     - mac80211: fix user-power when emulating chanctx
     - selftests/watchdog-test: Fix system accidentally reset after watchdog-test
     - x86/amd_nb: Fix compile-testing without CONFIG_AMD_NB
     - net: usb: qmi_wwan: add Quectel RG650V
     - proc/softirqs: replace seq_printf with seq_put_decimal_ull_width
     - nvme: fix metadata handling in nvme-passthrough
     - initramfs: avoid filename buffer overrun
     - m68k: mvme147: Fix SCSI controller IRQ numbers
     - m68k: mvme16x: Add and use "mvme16x.h"
     - m68k: mvme147: Reinstate early console
     - acpi/arm64: Adjust error handling procedure in gtdt_parse_timer_block()
     - s390/syscalls: Avoid creation of arch/arch/ directory
     - hfsplus: don't query the device logical block size multiple times
     - EDAC/fsl_ddr: Fix bad bit shift operations
     - crypto: pcrypt - Call crypto layer directly when padata_do_parallel() return -EBUSY
     - crypto: cavium - Fix the if condition to exit loop after timeout
     - crypto: bcm - add error check in the ahash_hmac_init function
     - crypto: cavium - Fix an error handling path in cpt_ucode_load_fw()
     - time: Fix references to _msecs_to_jiffies() handling of values
     - soc: qcom: geni-se: fix array underflow in geni_se_clk_tbl_get()
     - mmc: mmc_spi: drop buggy snprintf()
     - ARM: dts: cubieboard4: Fix DCDC5 regulator constraints
     - regmap: irq: Set lockdep class for hierarchical IRQ domains
     - firmware: arm_scpi: Check the DVFS OPP count returned by the firmware
     - drm/mm: Mark drm_mm_interval_tree*() functions with __maybe_unused
     - wifi: ath9k: add range check for conn_rsp_epid in htc_connect_service()
     - drm/omap: Fix locking in omap_gem_new_dmabuf()
     - bpf: Fix the xdp_adjust_tail sample prog issue
     - wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_config_scan()
     - drm/etnaviv: consolidate hardware fence handling in etnaviv_gpu
     - drm/etnaviv: dump: fix sparse warnings
     - drm/etnaviv: fix power register offset on GC300
     - drm/etnaviv: hold GPU lock across perfmon sampling
     - net: rfkill: gpio: Add check for clk_enable()
     - ALSA: us122l: Use snd_card_free_when_closed() at disconnection
     - ALSA: caiaq: Use snd_card_free_when_closed() at disconnection
     - ALSA: 6fire: Release resources at card release
     - netpoll: Use rcu_access_pointer() in netpoll_poll_lock
     - trace/trace_event_perf: remove duplicate samples on the first tracepoint event
     - powerpc/vdso: Flag VDSO64 entry points as functions
     - mfd: da9052-spi: Change read-mask to write-mask
     - cpufreq: loongson2: Unregister platform_driver on failure
     - mtd: rawnand: atmel: Fix possible memory leak
     - RDMA/bnxt_re: Check cqe flags to know imm_data vs inv_irkey
     - mfd: rt5033: Fix missing regmap_del_irq_chip()
     - scsi: bfa: Fix use-after-free in bfad_im_module_exit()
     - scsi: fusion: Remove unused variable 'rc'
     - scsi: qedi: Fix a possible memory leak in qedi_alloc_and_init_sb()
     - ocfs2: fix uninitialized value in ocfs2_file_read_iter()
     - powerpc/sstep: make emulate_vsx_load and emulate_vsx_store static
     - fbdev/sh7760fb: Alloc DMA memory from hardware device
     - fbdev: sh7760fb: Fix a possible memory leak in sh7760fb_alloc_mem()
     - dt-bindings: clock: adi,axi-clkgen: convert old binding to yaml format
     - dt-bindings: clock: axi-clkgen: include AXI clk
     - clk: axi-clkgen: use devm_platform_ioremap_resource() short-hand
     - clk: clk-axi-clkgen: make sure to enable the AXI bus clock
     - perf probe: Correct demangled symbols in C++ program
     - PCI: cpqphp: Use PCI_POSSIBLE_ERROR() to check config reads
     - PCI: cpqphp: Fix PCIBIOS_* return value confusion
     - m68k: mcfgpio: Fix incorrect register offset for CONFIG_M5441x
     - m68k: coldfire/device.c: only build FEC when HW macros are defined
     - rpmsg: glink: Add TX_DATA_CONT command while sending
     - rpmsg: glink: Send READ_NOTIFY command in FIFO full case
     - rpmsg: glink: Fix GLINK command prefix
     - rpmsg: glink: use only lower 16-bits of param2 for CMD_OPEN name length
     - NFSD: Prevent NULL dereference in nfsd4_process_cb_update()
     - NFSD: Cap the number of bytes copied by nfs4_reset_recoverydir()
     - vfio/pci: Properly hide first-in-list PCIe extended capability
     - power: supply: core: Remove might_sleep() from power_supply_put()
     - net: usb: lan78xx: Fix memory leak on device unplug by freeing PHY device
     - tg3: Set coherent DMA mask bits to 31 for BCM57766 chipsets
     - net: usb: lan78xx: Fix refcounting and autosuspend on invalid WoL configuration
     - marvell: pxa168_eth: fix call balance of pep-&gt;clk handling routines
     - net: stmmac: dwmac-socfpga: Set RX watchdog interrupt as broken
     - usb: using mutex lock and supporting O_NONBLOCK flag in iowarrior_read()
     - USB: chaoskey: fail open after removal
     - USB: chaoskey: Fix possible deadlock chaoskey_list_lock
     - misc: apds990x: Fix missing pm_runtime_disable()
     - apparmor: fix 'Do simple duplicate message elimination'
     - usb: ehci-spear: fix call balance of sehci clk handling routines
     - ext4: supress data-race warnings in ext4_free_inodes_{count,set}()
     - ext4: fix FS_IOC_GETFSMAP handling
     - jfs: xattr: check invalid xattr size more strictly
     - ASoC: codecs: Fix atomicity violation in snd_soc_component_get_drvdata()
     - PCI: Fix use-after-free of slot-&gt;bus on hot remove
     - tty: ldsic: fix tty_ldisc_autoload sysctl's proc_handler
     - Bluetooth: Fix type of len in rfcomm_sock_getsockopt{,_old}()
     - ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices
     - Revert "usb: gadget: composite: fix OS descriptors w_value logic"
     - serial: sh-sci: Clean sci_ports[0] after at earlycon exit
     - Revert "serial: sh-sci: Clean sci_ports[0] after at earlycon exit"
     - netfilter: ipset: add missing range check in bitmap_ip_uadt
     - spi: Fix acpi deferred irq probe
     - ubi: wl: Put source PEB into correct list if trying locking LEB failed
     - um: ubd: Do not use drvdata in release
     - um: net: Do not use drvdata in release
     - serial: 8250: omap: Move pm_runtime_get_sync
     - um: vector: Do not use drvdata in release
     - sh: cpuinfo: Fix a warning for CONFIG_CPUMASK_OFFSTACK
     - arm64: tls: Fix context-switching of tpidrro_el0 when kpti is enabled
     - block: fix ordering between checking BLK_MQ_S_STOPPED request adding
     - HID: wacom: Interpret tilt data from Intuos Pro BT as signed values
     - media: wl128x: Fix atomicity violation in fmc_send_cmd()
     - usb: dwc3: gadget: Fix checking for number of TRBs left
     - lib: string_helpers: silence snprintf() output truncation warning
     - NFSD: Prevent a potential integer overflow
     - rpmsg: glink: Propagate TX failures in intentless mode as well
     - um: Fix the return value of elf_core_copy_task_fpregs
     - NFSv4.0: Fix a use-after-free problem in the asynchronous open()
     - rtc: check if __rtc_read_time was successful in rtc_timer_do_work()
     - ubifs: Correct the total block count by deducting journal reservation
     - ubi: fastmap: Fix duplicate slab cache names while attaching
     - jffs2: fix use of uninitialized variable
     - block: return unsigned int from bdev_io_min
     - 9p/xen: fix init sequence
     - 9p/xen: fix release of IRQ
     - modpost: remove incorrect code in do_eisa_entry()
     - sh: intc: Fix use-after-free bug in register_intc_controller()</description>
    <severity>Critical</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * Bump kernel ABI to 28: ship the ELS kernel as linux-image-4.19.0-28-*,
     distinct from Debian stock 4.19.0-27.
   * Backport security fixes for CVE-2026-31431 (af_alg / AEAD):
     - crypto: authencesn - reject too-short AAD (assoclen&lt;8) to match ESP/ESN spec
     - crypto: scatterwalk - Backport memcpy_sglist()
     - crypto: authencesn - Do not place hiseq at end of dst for out-of-place
       decryption
     - crypto: authencesn - Fix src offset when decrypting in-place
     - crypto: algif_aead - use memcpy_sglist() instead of null skcipher
     - crypto: algif_aead - Revert to operating out-of-place
     - crypto: algif_aead - snapshot IV for async AEAD requests
     - crypto: authenc - use memcpy_sglist() instead of null skcipher
     - crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl
     - crypto: algif_aead - Fix minimum RX size check for decryption
   * Backport security fixes for CVE-2026-53043 (ocfs2/dlm out-of-bounds):
     - ocfs2/dlm: validate qr_numregions in dlm_match_regions()
     - ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison
   * New upstream stable update:
     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.317
     - wifi: mac80211: mesh: Fix leak of mesh_preq_queue objects
     - wifi: mac80211: Fix deadlock in ieee80211_sta_ps_deliver_wakeup()
     - wifi: iwlwifi: mvm: revert gen2 TX A-MPDU size to 64
     - wifi: iwlwifi: mvm: don't read past the mfuart notifcation
     - ipv6: sr: block BH in seg6_output_core() and seg6_input_core()
     - vxlan: Fix regression when dropping packets due to invalid src addresses
     - tcp: count CLOSE-WAIT sockets for TCP_MIB_CURRESTAB
     - ptp: Fix error message on failed pin verification
     - af_unix: Annotate data-race of sk-&gt;sk_state in unix_inq_len().
     - af_unix: Annotate data-races around sk-&gt;sk_state in unix_write_space() and poll().
     - af_unix: Annotate data-races around sk-&gt;sk_state in sendmsg() and recvmsg().
     - af_unix: Annotate data-races around sk-&gt;sk_state in UNIX_DIAG.
     - af_unix: Annotate data-race of net-&gt;unx.sysctl_max_dgram_qlen.
     - af_unix: Use unix_recvq_full_lockless() in unix_stream_connect().
     - af_unix: Use skb_queue_len_lockless() in sk_diag_show_rqlen().
     - af_unix: Annotate data-race of sk-&gt;sk_shutdown in sk_diag_fill().
     - usb: gadget: f_fs: Fix race between aio_cancel() and AIO request complete
     - drm/amd/display: Handle Y carry-over in VCP X.Y calculation
     - serial: sc16is7xx: replace hardcoded divisor value with BIT() macro
     - serial: sc16is7xx: fix bug in sc16is7xx_set_baud() when using prescaler
     - media: mc: mark the media devnode as registered from the, start
     - selftests/mm: compaction_test: fix incorrect write of zero to nr_hugepages
     - selftests/mm: conform test to TAP format output
     - selftests/mm: compaction_test: fix bogus test success on Aarch64
     - nilfs2: Remove check for PageError
     - nilfs2: return the mapped address from nilfs_get_page()
     - nilfs2: fix nilfs_empty_dir() misjudgment and long loop on I/O errors
     - USB: class: cdc-wdm: Fix CPU lockup caused by excessive log messages
     - mei: me: release irq in mei_me_pci_resume error path
     - jfs: xattr: fix buffer overflow for invalid xattr
     - xhci: Apply reset resume quirk to Etron EJ188 xHCI host
     - xhci: Apply broken streams quirk to Etron EJ188 xHCI host
     - Input: try trimming too long modalias strings
     - xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING
     - HID: core: remove unnecessary WARN_ON() in implement()
     - iommu/amd: Fix sysfs leak in iommu init
     - liquidio: Adjust a NULL pointer handling path in lio_vf_rep_copy_packet
     - drm/bridge/panel: Fix runtime warning on panel bridge release
     - tcp: fix race in tcp_v6_syn_recv_sock()
     - Bluetooth: L2CAP: Fix rejecting L2CAP_CONN_PARAM_UPDATE_REQ
     - ipv6/route: Add a missing check on proc_dointvec
     - net/ipv6: Fix the RT cache flush via sysctl using a previous delay
     - drivers: core: synchronize really_probe() and dev_uevent()
     - drm/exynos/vidi: fix memory leak in .get_modes()
     - vmci: prevent speculation leaks by sanitizing event in event_deliver()
     - fs/proc: fix softlockup in __read_vmcore
     - ocfs2: use coarse time for new created files
     - ocfs2: fix races between hole punching and AIO+DIO
     - PCI: rockchip-ep: Remove wrong mask on subsys_vendor_id
     - dmaengine: axi-dmac: fix possible race in remove()
     - intel_th: pci: Add Granite Rapids support
     - intel_th: pci: Add Granite Rapids SOC support
     - intel_th: pci: Add Sapphire Rapids SOC support
     - intel_th: pci: Add Meteor Lake-S support
     - intel_th: pci: Add Lunar Lake support
     - nilfs2: fix potential kernel bug due to lack of writeback flag waiting
     - hv_utils: drain the timesync packets on onchannelcallback
     - hugetlb_encode.h: fix undefined behaviour (34 &lt;&lt; 26)
     - usb-storage: alauda: Check whether the media is initialized
     - rcutorture: Fix rcu_torture_one_read() pipe_count overflow comment
     - batman-adv: bypass empty buckets in batadv_purge_orig_ref()
     - scsi: qedi: Fix crash while reading debugfs attribute
     - powerpc/pseries: Enforce hcall result buffer validity and size
     - powerpc/io: Avoid clang null pointer arithmetic warnings
     - usb: misc: uss720: check for incompatible versions of the Belkin F5U002
     - udf: udftime: prevent overflow in udf_disk_stamp_to_time()
     - PCI/PM: Avoid D3cold for HP Pavilion 17 PC/1972 PCIe Ports
     - MIPS: Octeon: Add PCIe link status check
     - MIPS: Routerboard 532: Fix vendor retry check code
     - cipso: fix total option length computation
     - netrom: Fix a memory leak in nr_heartbeat_expiry()
     - ipv6: prevent possible NULL dereference in rt6_probe()
     - xfrm6: check ip6_dst_idev() return value in xfrm6_get_saddr()
     - virtio_net: checksum offloading handling fix
     - net: usb: rtl8150 fix unintiatilzed variables in rtl8150_get_link_ksettings
     - regulator: core: Fix modpost error "regulator_get_regmap" undefined
     - dmaengine: ioatdma: Fix missing kmem_cache_destroy()
     - ACPICA: Revert "ACPICA: avoid Info: mapping multiple BARs. Your kernel is fine."
     - drm/radeon: fix UBSAN warning in kv_dpm.c
     - gcov: add support for GCC 14
     - ARM: dts: samsung: smdkv310: fix keypad no-autorepeat
     - ARM: dts: samsung: exynos4412-origen: fix keypad no-autorepeat
     - ARM: dts: samsung: smdk4412: fix keypad no-autorepeat
     - selftests/ftrace: Fix checkbashisms errors
     - tracing: Add MODULE_DESCRIPTION() to preemptirq_delay_test
     - perf/core: Fix missing wakeup when waiting for context reference
     - PCI: Add PCI_ERROR_RESPONSE and related definitions
     - x86/amd_nb: Check for invalid SMN reads
     - iio: dac: ad5592r-base: Replace indio_dev-&gt;mlock with own device lock
     - iio: dac: ad5592r: un-indent code-block for scale read
     - iio: dac: ad5592r: fix temperature channel scaling value
     - scsi: mpt3sas: Add ioc_&lt;level&gt; logging macros
     - scsi: mpt3sas: Gracefully handle online firmware update
     - scsi: mpt3sas: Avoid test/set_bit() operating in non-allocated memory
     - xhci: Use soft retry to recover faster from transaction errors
     - xhci: Set correct transferred length for cancelled bulk transfers
     - usb: xhci: do not perform Soft Retry for some xHCI hosts
     - pinctrl: fix deadlock in create_pinctrl() when handling -EPROBE_DEFER
     - pinctrl: rockchip: fix pinmux bits for RK3328 GPIO2-B pins
     - pinctrl: rockchip: fix pinmux bits for RK3328 GPIO3-B pins
     - pinctrl: rockchip: fix pinmux reset in rockchip_pmx_set
     - drm/amdgpu: fix UBSAN warning in kv_dpm.c
     - netfilter: nf_tables: validate family when identifying table via handle
     - ASoC: fsl-asoc-card: set priv-&gt;pdev before using it
     - netfilter: nf_tables: fully validate NFT_DATA_VALUE on store to data registers
     - drm/panel: ilitek-ili9881c: Fix warning with GPIO controllers that sleep
     - net/iucv: Avoid explicit cpumask var allocation on stack
     - ALSA: emux: improve patch ioctl data validation
     - media: dvbdev: Initialize sbuf
     - soc: ti: wkup_m3_ipc: Send NULL dummy message instead of pointer message
     - nvme: fixup comment for nvme RDMA Provider Type
     - gpio: davinci: Validate the obtained number of IRQs
     - i2c: ocores: stop transfer on timeout
     - i2c: ocores: set IACK bit after core is enabled
     - x86: stop playing stack games in profile_pc()
     - mmc: sdhci-pci: Convert PCIBIOS_* return codes to errnos
     - iio: adc: ad7266: Fix variable checking bug
     - iio: chemical: bme680: Fix pressure value output
     - iio: chemical: bme680: Fix calibration data variable
     - iio: chemical: bme680: Fix overflows in compensate() functions
     - iio: chemical: bme680: Fix sensor data read operation
     - net: usb: ax88179_178a: improve link status logs
     - usb: gadget: printer: SS+ support
     - usb: musb: da8xx: fix a resource leak in probe()
     - usb: atm: cxacru: fix endpoint checking in cxacru_bind()
     - tty: mcf: MCF54418 has 10 UARTS
     - hexagon: fix fadvise64_64 calling conventions
     - drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_ld_modes
     - drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_hd_modes
     - batman-adv: Don't accept TT entries for out-of-spec VIDs
     - ata: libata-core: Fix double free on error
     - ftruncate: pass a signed offset
     - pwm: stm32: Refuse too small period requests
     - ipv6: annotate some data-races around sk-&gt;sk_prot
     - ipv6: Fix data races around sk-&gt;sk_prot.
     - tcp: Fix data races around icsk-&gt;icsk_af_ops.
     - arm64: dts: rockchip: Add sound-dai-cells for RK3368
     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.318
     - asm-generic: Move common compat types to asm-generic/compat.h
     - media: dvb: as102-fe: Fix as10x_register_addr packing
     - media: dvb-usb: dib0700_devices: Add missing release_firmware()
     - IB/core: Implement a limit on UMAD receive List
     - drm/amd/display: Skip finding free audio for unknown engine_id
     - media: dw2102: Don't translate i2c read into write
     - sctp: prefer struct_size over open coded arithmetic
     - firmware: dmi: Stop decoding on broken entry
     - Input: ff-core - prefer struct_size over open coded arithmetic
     - net: dsa: mv88e6xxx: Correct check for empty list
     - media: dvb-frontends: tda18271c2dd: Remove casting during div
     - media: s2255: Use refcount_t instead of atomic_t for num_channels
     - media: dvb-frontends: tda10048: Fix integer overflow
     - i2c: i801: Annotate apanel_addr as __ro_after_init
     - powerpc/64: Set _IO_BASE to POISON_POINTER_DELTA not 0 for CONFIG_PCI=n
     - orangefs: fix out-of-bounds fsid access
     - powerpc/xmon: Check cpu id in commands "c#", "dp#" and "dx#"
     - jffs2: Fix potential illegal address access in jffs2_free_inode
     - s390/pkey: Wipe sensitive data on failure
     - tcp: take care of compressed acks in tcp_add_reno_sack()
     - tcp: tcp_mark_head_lost is only valid for sack-tcp
     - tcp: add ece_ack flag to reno sack functions
     - net: tcp better handling of reordering then loss cases
     - UPSTREAM: tcp: fix DSACK undo in fast recovery to call tcp_try_to_open()
     - tcp_metrics: validate source addr length
     - bonding: Fix out-of-bounds read in bond_option_arp_ip_targets_set()
     - selftests: fix OOM in msg_zerocopy selftest
     - selftests: make order checking verbose in msg_zerocopy selftest
     - inet_diag: Initialize pad field in struct inet_diag_req_v2
     - nilfs2: fix inode number range checks
     - nilfs2: add missing check for inode numbers on directory entries
     - mm: optimize the redundant loop of mm_update_owner_next()
     - Bluetooth: Fix incorrect pointer arithmatic in ext_adv_report_evt
     - can: kvaser_usb: Explicitly initialize family in leafimx driver_info struct
     - fsnotify: Do not generate events for O_PATH file descriptors
     - Revert "mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again"
     - drm/nouveau: fix null pointer dereference in nouveau_connector_get_modes
     - drm/amdgpu/atomfirmware: silence UBSAN warning
     - bnx2x: Fix multiple UBSAN array-index-out-of-bounds
     - media: dw2102: fix a potential buffer overflow
     - i2c: pnx: Fix potential deadlock warning from del_timer_sync() call in isr
     - nilfs2: fix incorrect inode allocation from reserved inodes
     - drm/i915: make find_fw_domain work on intel_uncore
     - tcp: fix incorrect undo caused by DSACK of TLP retransmit
     - net: lantiq_etop: add blank line after declaration
     - net: ethernet: lantiq_etop: fix double free in detach
     - ppp: reject claimed-as-LCP but actually malformed packets
     - ARM: davinci: Convert comma to semicolon
     - USB: serial: option: add Telit generic core-dump composition
     - USB: serial: option: add Telit FN912 rmnet compositions
     - USB: serial: option: add Fibocom FM350-GL
     - USB: serial: option: add support for Foxconn T99W651
     - USB: serial: option: add Netprisma LCUK54 series modules
     - USB: serial: option: add Rolling RW350-GL variants
     - USB: Add USB_QUIRK_NO_SET_INTF quirk for START BP-850k
     - usb: gadget: configfs: Prevent OOB read/write in usb_string_copy()
     - USB: core: Fix duplicate endpoint bug by clearing reserved bits in the descriptor
     - hpet: Support 32-bit userspace
     - libceph: fix race between delayed_work() and ceph_monc_stop()
     - tcp: refactor tcp_retransmit_timer()
     - net: tcp: fix unexcepted socket die when snd_wnd is 0
     - tcp: use signed arithmetic in tcp_rtx_probe0_timed_out()
     - tcp: avoid too many retransmit packets
     - SUNRPC: Fix RPC client cleaned up the freed pipefs dentries
     - nilfs2: fix kernel bug on rename operation of broken directory
     - i2c: rcar: bring hardware to known state when probing
     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.319
     - gcc-plugins: Rename last_stmt() for GCC 14+
     - scsi: qedf: Set qed_slowpath_params to zero before use
     - ACPI: EC: Abort address space access upon error
     - ACPI: EC: Avoid returning AE_OK on errors in address space handler
     - wifi: mac80211: mesh: init nonpeer_pm to active by default in mesh sdata
     - wifi: mac80211: fix UBSAN noise in ieee80211_prep_hw_scan()
     - Input: silead - Always support 10 fingers
     - ila: block BH in ila_output()
     - kconfig: gconf: give a proper initial state to the Save button
     - kconfig: remove wrong expr_trans_bool()
     - fs/file: fix the check in find_next_fd()
     - mei: demote client disconnect warning on suspend to debug
     - wifi: cfg80211: wext: add extra SIOCSIWSCAN data check
     - Input: elantech - fix touchpad state on resume for Lenovo N24
     - bytcr_rt5640 : inverse jack detect for Archos 101 cesium
     - can: kvaser_usb: fix return value for hif_usb_send_regout
     - s390/sclp: Fix sclp_init() cleanup on failure
     - ALSA: dmaengine_pcm: terminate dmaengine before synchronize
     - net: usb: qmi_wwan: add Telit FN912 compositions
     - net: mac802154: Fix racy device stats updates by DEV_STATS_INC() and DEV_STATS_ADD()
     - Bluetooth: hci_core: cancel all works upon hci_unregister_dev()
     - fs: better handle deep ancestor chains in is_subdir()
     - spi: imx: Don't expect DMA for i.MX{25,35,50,51,53} cspi devices
     - selftests/vDSO: fix clang build errors and warnings
     - hfsplus: fix uninit-value in copy_name
     - filelock: Remove locks reliably when fcntl/close race is detected
     - ARM: 9324/1: fix get_user() broken with veneer
     - ACPI: processor_idle: Fix invalid comparison with insertion sort for latency
     - net: relax socket state check at accept time.
     - ocfs2: add bounds checking to ocfs2_check_dir_entry()
     - jfs: don't walk off the end of ealist
     - filelock: Fix fcntl/close race recovery compat path
     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.320
     - platform/chrome: cros_ec_debugfs: fix wrong EC message version
     - hfsplus: fix to avoid false alarm of circular locking
     - x86/of: Return consistent error type from x86_of_pci_irq_enable()
     - x86/pci/intel_mid_pci: Fix PCIBIOS_* return code handling
     - x86/pci/xen: Fix PCIBIOS_* return code handling
     - x86/platform/iosf_mbi: Convert PCIBIOS_* return codes to errnos
     - hwmon: (adt7475) Fix default duty on fan is disabled
     - pwm: stm32: Always do lazy disabling
     - hwmon: (max6697) Fix underflow when writing limit attributes
     - hwmon: Introduce SENSOR_DEVICE_ATTR_{RO, RW, WO} and variants
     - hwmon: (max6697) Auto-convert to use SENSOR_DEVICE_ATTR_{RO, RW, WO}
     - hwmon: (max6697) Fix swapped temp{1,8} critical alarms
     - arm64: dts: rockchip: Increase VOP clk rate on RK3328
     - m68k: atari: Fix TT bootup freeze / unexpected (SCU) interrupt messages
     - x86/xen: Convert comma to semicolon
     - m68k: cmpxchg: Fix return value for default case in __arch_xchg()
     - wifi: brcmsmac: LCN PHY code is used for BCM4313 2G-only device
     - net/smc: Allow SMC-D 1MB DMB allocations
     - net/smc: set rmb's SG_MAX_SINGLE_ALLOC limitation only when CONFIG_ARCH_NO_SG_CHAIN is defined
     - selftests/bpf: Check length of recv in test_sockmap
     - wifi: cfg80211: fix typo in cfg80211_calculate_bitrate_he()
     - wifi: cfg80211: handle 2x996 RU allocation in cfg80211_calculate_bitrate_he()
     - net: fec: Refactor: #define magic constants
     - net: fec: Fix FEC_ECR_EN1588 being cleared on link-down
     - ipvs: Avoid unnecessary calls to skb_is_gso_sctp
     - perf: Fix perf_aux_size() for greater-than 32-bit size
     - perf: Prevent passing zero nr_pages to rb_alloc_aux()
     - bna: adjust 'name' buf size of bna_tcb and bna_ccb structures
     - selftests: forwarding: devlink_lib: Wait for udev events after reloading
     - media: imon: Fix race getting ictx-&gt;lock
     - saa7134: Unchecked i2c_transfer function result fixed
     - media: uvcvideo: Allow entity-defined get_info and get_cur
     - media: uvcvideo: Override default flags
     - media: renesas: vsp1: Fix _irqsave and _irq mix
     - media: renesas: vsp1: Store RPF partition configuration per RPF instance
     - leds: trigger: Unregister sysfs attributes before calling deactivate()
     - perf report: Fix condition in sort__sym_cmp()
     - drm/etnaviv: fix DMA direction handling for cached RW buffers
     - mfd: omap-usb-tll: Use struct_size to allocate tll
     - ext4: avoid writing unitialized memory to disk in EA inodes
     - sparc64: Fix incorrect function signature and add prototype for prom_cif_init
     - PCI: Equalize hotplug memory and io for occupied and empty slots
     - PCI: Fix resource double counting on remove &amp; rescan
     - RDMA/mlx4: Fix truncated output warning in mad.c
     - RDMA/mlx4: Fix truncated output warning in alias_GUID.c
     - RDMA/rxe: Don't set BTH_ACK_MASK for UC or UD QPs
     - mtd: make mtd_test.c a separate module
     - Input: elan_i2c - do not leave interrupt disabled on suspend failure
     - MIPS: Octeron: remove source file executable bit
     - powerpc/xmon: Fix disassembly CPU feature checks
     - macintosh/therm_windtunnel: fix module unload.
     - bnxt_re: Fix imm_data endianness
     - ice: Rework flex descriptor programming
     - netfilter: ctnetlink: use helper function to calculate expect ID
     - pinctrl: core: fix possible memory leak when pinctrl_enable() fails
     - pinctrl: single: fix possible memory leak when pinctrl_enable() fails
     - pinctrl: ti: ti-iodelay: Drop if block with always false condition
     - pinctrl: ti: ti-iodelay: fix possible memory leak when pinctrl_enable() fails
     - pinctrl: freescale: mxs: Fix refcount of child
     - fs/nilfs2: remove some unused macros to tame gcc
     - nilfs2: avoid undefined behavior in nilfs_cnt32_ge macro
     - tick/broadcast: Make takeover of broadcast hrtimer reliable
     - net: netconsole: Disable target before netpoll cleanup
     - af_packet: Handle outgoing VLAN packets without hardware offloading
     - ipv6: take care of scope when choosing the src addr
     - char: tpm: Fix possible memory leak in tpm_bios_measurements_open()
     - media: venus: fix use after free in vdec_close
     - hfs: fix to initialize fields of hfs_inode_info after hfs_alloc_inode()
     - drm/gma500: fix null pointer dereference in cdv_intel_lvds_get_modes
     - drm/gma500: fix null pointer dereference in psb_intel_lvds_get_modes
     - m68k: amiga: Turn off Warp1260 interrupts during boot
     - ext4: check dot and dotdot of dx_root before making dir indexed
     - ext4: make sure the first directory block is not a hole
     - wifi: mwifiex: Fix interface type change
     - leds: ss4200: Convert PCIBIOS_* return codes to errnos
     - tools/memory-model: Fix bug in lock.cat
     - hwrng: amd - Convert PCIBIOS_* return codes to errnos
     - PCI: hv: Return zero, not garbage, when reading PCI_INTERRUPT_PIN
     - binder: fix hang of unregistered readers
     - scsi: qla2xxx: Return ENOBUFS if sg_cnt is more than one for ELS cmds
     - f2fs: fix to don't dirty inode for readonly filesystem
     - clk: davinci: da8xx-cfgchip: Initialize clk_init_data before use
     - ubi: eba: properly rollback inside self_check_eba
     - decompress_bunzip2: fix rare decompression failure
     - kobject_uevent: Fix OOB access within zap_modalias_env()
     - rtc: cmos: Fix return value of nvmem callbacks
     - scsi: qla2xxx: During vport delete send async logout explicitly
     - scsi: qla2xxx: validate nvme_local_port correctly
     - perf/x86/intel/pt: Fix topa_entry base length
     - watchdog/perf: properly initialize the turbo mode timestamp and rearm counter
     - platform: mips: cpu_hwmon: Disable driver on unsupported hardware
     - RDMA/iwcm: Fix a use-after-free related to destroying CM IDs
     - selftests/sigaltstack: Fix ppc64 GCC build
     - nilfs2: handle inconsistent state in nilfs_btnode_create_block()
     - kdb: Fix bound check compiler warning
     - kdb: address -Wformat-security warnings
     - kdb: Use the passed prompt in kdb_position_cursor()
     - jfs: Fix array-index-out-of-bounds in diFree
     - dma: fix call order in dmam_free_coherent
     - MIPS: SMP-CPS: Fix address for GCR_ACCESS register for CM3 and later
     - net: ip_rt_get_source() - use new style struct initializer instead of memset
     - ipv4: Fix incorrect source address in Record Route option
     - net: bonding: correctly annotate RCU in bond_should_notify_peers()
     - tipc: Return non-zero value from tipc_udp_addr2str() on error
     - mISDN: Fix a use after free in hfcmulti_tx()
     - mm: avoid overflows in dirty throttling logic
     - PCI: rockchip: Make 'ep-gpios' DT property optional
     - PCI: rockchip: Use GPIOD_OUT_LOW flag while requesting ep_gpio
     - parport: parport_pc: Mark expected switch fall-through
     - parport: Convert printk(KERN_&lt;LEVEL&gt; to pr_&lt;level&gt;(
     - parport: Standardize use of printmode
     - dev/parport: fix the array out-of-bounds risk
     - driver core: Cast to (void *) with __force for __percpu pointer
     - devres: Fix memory leakage caused by driver API devm_free_percpu()
     - perf/x86/intel/pt: Export pt_cap_get()
     - perf/x86/intel/pt: Use helpers to obtain ToPA entry size
     - perf/x86/intel/pt: Use pointer arithmetics instead in ToPA entry calculation
     - perf/x86/intel/pt: Split ToPA metadata and page layout
     - perf/x86/intel/pt: Fix a topa_entry base address calculation
     - remoteproc: imx_rproc: ignore mapping vdev regions
     - remoteproc: imx_rproc: Fix ignoring mapping vdev regions
     - remoteproc: imx_rproc: Skip over memory region when node value is NULL
     - drm/vmwgfx: Fix overlay when using Screen Targets
     - net/iucv: fix use after free in iucv_sock_close()
     - ipv6: fix ndisc_is_useropt() handling for PIO
     - protect the fetch of -&gt;fd[fd] in do_dup2() from mispredictions
     - ALSA: usb-audio: Correct surround channels in UAC1 channel map
     - net: usb: sr9700: fix uninitialized variable use in sr_mdio_read
     - irqchip/mbigen: Fix mbigen node address layout
     - x86/mm: Fix pti_clone_pgtable() alignment assumption
     - net: usb: qmi_wwan: fix memory leak for not ip packets
     - net: linkwatch: use system_unbound_wq
     - Bluetooth: l2cap: always unlock channel in l2cap_conless_channel()
     - net: fec: Stop PPS on driver remove
     - md/raid5: avoid BUG_ON() while continue reshape after reassembling
     - clocksource/drivers/sh_cmt: Address race condition for clock events
     - PCI: Add Edimax Vendor ID to pci_ids.h
     - udf: prevent integer overflow in udf_bitmap_free_blocks()
     - wifi: nl80211: don't give key data to userspace
     - btrfs: fix bitmap leak when loading free space cache on duplicate entry
     - media: uvcvideo: Ignore empty TS packets
     - media: uvcvideo: Fix the bandwdith quirk on USB 3.x
     - jbd2: avoid memleak in jbd2_journal_write_metadata_buffer
     - s390/sclp: Prevent release of buffer in I/O
     - SUNRPC: Fix a race to wake a sync task
     - ext4: fix wrong unit use in ext4_mb_find_by_goal
     - arm64: Add support for SB barrier and patch in over DSB; ISB sequences
     - arm64: cpufeature: Force HWCAP to be based on the sysreg visible to user-space
     - arm64: Add Neoverse-V2 part
     - arm64: cputype: Add Cortex-X4 definitions
     - arm64: cputype: Add Neoverse-V3 definitions
     - arm64: errata: Add workaround for Arm errata 3194386 and 3312417
     - arm64: cputype: Add Cortex-X3 definitions
     - arm64: cputype: Add Cortex-A720 definitions
     - arm64: cputype: Add Cortex-X925 definitions
     - arm64: errata: Unify speculative SSBS errata logic
     - arm64: errata: Expand speculative SSBS workaround
     - arm64: cputype: Add Cortex-X1C definitions
     - arm64: cputype: Add Cortex-A725 definitions
     - arm64: errata: Expand speculative SSBS workaround (again)
     - i2c: smbus: Don't filter out duplicate alerts
     - i2c: smbus: Improve handling of stuck alerts
     - i2c: smbus: Send alert notifications to all devices if source not found
     - bpf: kprobe: remove unused declaring of bpf_kprobe_override
     - spi: lpspi: Replace all "master" with "controller"
     - spi: lpspi: Add slave mode support
     - spi: lpspi: Let watermark change with send data length
     - spi: lpspi: Add i.MX8 boards support for lpspi
     - spi: lpspi: add the error info of transfer speed setting
     - spi: fsl-lpspi: remove unneeded array
     - spi: spi-fsl-lpspi: Fix scldiv calculation
     - ALSA: line6: Fix racy access to midibuf
     - usb: vhci-hcd: Do not drop references before new references are gained
     - USB: serial: debug: do not echo input by default
     - usb: gadget: core: Check for unset descriptor
     - scsi: ufs: core: Fix hba-&gt;last_dme_cmd_tstamp timestamp updating logic
     - tick/broadcast: Move per CPU pointer access into the atomic section
     - ntp: Clamp maxerror and esterror to operating range
     - driver core: Fix uevent_show() vs driver detach race
     - ntp: Safeguard against time_constant overflow
     - serial: core: check uartclk for zero to avoid divide by zero
     - power: supply: axp288_charger: Fix constant_charge_voltage writes
     - power: supply: axp288_charger: Round constant_charge_voltage writes down
     - tracing: Fix overflow in get_free_elt()
     - x86/mtrr: Check if fixed MTRRs exist before saving them
     - drm/bridge: analogix_dp: properly handle zero sized AUX transactions
     - drm/mgag200: Set DDC timeout in milliseconds
     - kbuild: Fix '-S -c' in x86 stack protector scripts
     - netfilter: nf_tables: set element extended ACK reporting support
     - netfilter: nf_tables: use timestamp to check for set element timeout
     - netfilter: nf_tables: prefer nft_chain_validate
     - arm64: cpufeature: Fix the visibility of compat hwcaps
     - media: uvcvideo: Use entity get_cur in uvc_ctrl_set
     - drm/i915/gem: Fix Virtual Memory mapping boundaries calculation
     - exec: Fix ToCToU between perm check and set-uid/gid usage
     - nvme/pci: Add APST quirk for Lenovo N60z laptop
     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.321
     - fuse: Initialize beyond-EOF page contents before setting uptodate
     - ALSA: usb-audio: Support Yamaha P-125 quirk entry
     - xhci: Fix Panther point NULL pointer deref at full-speed re-enumeration
     - arm64: ACPI: NUMA: initialize all values of acpi_early_node_map to NUMA_NO_NODE
     - dm resume: don't return EINVAL when signalled
     - dm persistent data: fix memory allocation failure
     - bitmap: introduce generic optimized bitmap_size()
     - fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE
     - selinux: fix potential counting error in avc_add_xperms_decision()
     - drm/amdgpu: Actually check flags for all context ops.
     - memcg_write_event_control(): fix a user-triggerable oops
     - s390/cio: rename bitmap_size() -&gt; idset_bitmap_size()
     - overflow.h: Add flex_array_size() helper
     - overflow: Implement size_t saturating arithmetic helpers
     - btrfs: rename bitmap_set_bits() -&gt; btrfs_bitmap_set_bits()
     - net/mlx5e: Correctly report errors for ethtool rx flows
     - atm: idt77252: prevent use after free in dequeue_rx()
     - net: dsa: vsc73xx: pass value in phy_write operation
     - ssb: Fix division by zero issue in ssb_calc_clock_rate
     - wifi: cw1200: Avoid processing an invalid TIM IE
     - i2c: riic: avoid potential division by zero
     - staging: ks7010: disable bh on tx_dev_lock
     - binfmt_misc: cleanup on filesystem umount
     - scsi: spi: Fix sshdr use
     - gfs2: setattr_chown: Add missing initialization
     - wifi: iwlwifi: abort scan when rfkill on but device enabled
     - powerpc/xics: Check return value of kasprintf in icp_native_map_one_cpu
     - ext4: do not trim the group with corrupted block bitmap
     - quota: Remove BUG_ON from dqget()
     - media: pci: cx23885: check cx23885_vdev_init() return
     - fs: binfmt_elf_efpic: don't use missing interpreter's properties
     - scsi: lpfc: Initialize status local variable in lpfc_sli4_repost_sgl_list()
     - net/sun3_82586: Avoid reading past buffer in debug output
     - md: clean up invalid BUG_ON in md_ioctl
     - parisc: Use irq_enter_rcu() to fix warning at kernel/context_tracking.c:367
     - powerpc/boot: Handle allocation failure in simple_realloc()
     - powerpc/boot: Only free if realloc() succeeds
     - btrfs: change BUG_ON to assertion when checking for delayed_node root
     - btrfs: handle invalid root reference found in may_destroy_subvol()
     - btrfs: send: handle unexpected data in header buffer in begin_cmd()
     - btrfs: delete pointless BUG_ON check on quota root in btrfs_qgroup_account_extent()
     - f2fs: fix to do sanity check in update_sit_entry
     - usb: gadget: fsl: Increase size of name buffer for endpoints
     - Bluetooth: bnep: Fix out-of-bound access
     - NFS: avoid infinite loop in pnfs_update_layout.
     - openrisc: Call setup_memory() earlier in the init sequence
     - s390/iucv: fix receive buffer virtual vs physical address confusion
     - usb: dwc3: core: Skip setting event buffers for host only controllers
     - irqchip/gic-v3-its: Remove BUG_ON in its_vpe_irq_domain_alloc
     - ext4: set the type of max_zeroout to unsigned int to avoid overflow
     - nvmet-rdma: fix possible bad dereference when freeing rsps
     - hrtimer: Prevent queuing of hrtimer without a function callback
     - gtp: pull network headers in gtp_dev_xmit()
     - block: use "unsigned long" for blk_validate_block_size().
     - Bluetooth: Make use of __check_timeout on hci_sched_le
     - Bluetooth: hci_core: Fix not handling link timeouts propertly
     - Bluetooth: hci_core: Fix LE quote calculation
     - kcm: Serialise kcm_sendmsg() for the same socket.
     - netfilter: nft_counter: Synchronize nft_counter_reset() against reader.
     - ipv6: prevent UAF in ip6_send_skb()
     - net: xilinx: axienet: Always disable promiscuous mode
     - drm/msm: use drm_debug_enabled() to check for debug categories
     - drm/msm/dpu: don't play tricks with debug macros
     - mmc: mmc_test: Fix NULL dereference on allocation failure
     - Bluetooth: MGMT: Add error handling to pair_device()
     - HID: wacom: Defer calculation of resolution until resolution_code is known
     - cxgb4: add forgotten u64 ivlan cast before shift
     - mmc: dw_mmc: allow biu and ciu clocks to defer
     - ALSA: timer: Relax start tick time check for slave timer elements
     - Bluetooth: hci_ldisc: check HCI_UART_PROTO_READY flag in HCIUARTGETPROTO
     - Input: MT - limit max slots
     - tools: move alignment-related macros to new &lt;linux/align.h&gt;
     - drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc
     - pinctrl: single: fix potential NULL dereference in pcs_get_function()
     - wifi: mwifiex: duplicate static structs used in driver instances
     - dm suspend: return -ERESTARTSYS instead of -EINTR
     - scsi: mpt3sas: Avoid IOMMU page faults on REPORT ZONES
     - filelock: Correct the filelock owner in fcntl_setlk/fcntl_setlk64
     - media: uvcvideo: Fix integer overflow calculating timestamp
     - ata: libata-core: Fix null pointer dereference on error
     - cgroup/cpuset: Prevent UAF in proc_cpuset_show()
     - memcg: enable accounting of ipc resources
     - fbcon: Prevent that screen size is smaller than font size
     - fbmem: Check virtual screen sizes in fb_set_var()
     - net:rds: Fix possible deadlock in rds_message_put
     - ida: Fix crash in ida_free when the bitmap is empty
     - net: prevent mss overflow in skb_segment()
     - soundwire: stream: fix programming slave ports for non-continous port maps
     - gtp: fix a potential NULL pointer dereference
     - net: busy-poll: use ktime_get_ns() instead of local_clock()
     - cdc-acm: Add DISABLE_ECHO quirk for GE HealthCare UI Controller
     - USB: serial: option: add MeiG Smart SRM825L
     - usb: dwc3: omap: add missing depopulate in probe error path
     - usb: dwc3: core: Prevent USB core invalid event buffer address access
     - usb: dwc3: st: fix probed platform device ref count on probe error path
     - usb: core: sysfs: Unmerge @usb3_hardware_lpm_attr_group in remove_power_attributes()
     - scsi: aacraid: Fix double-free on probe failure
     - ipc: remove memcg accounting for sops objects in do_semtimedop()
     - drm/fb-helper: set x/yres_virtual in drm_fb_helper_check_var
     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.322
     - net: usb: qmi_wwan: add MeiG Smart SRM825L
     - usb: dwc3: st: Add of_node_put() before return in probe function
     - usb: dwc3: st: add missing depopulate in probe error path
     - drm/amdgpu: Fix uninitialized variable warning in amdgpu_afmt_acr
     - drm/amdgpu: fix overflowed array index read warning
     - drm/amdgpu: fix ucode out-of-bounds read warning
     - drm/amdgpu: fix mc_data out-of-bounds read warning
     - drm/amdkfd: Reconcile the definition and use of oem_id in struct kfd_topology_device
     - apparmor: fix possible NULL pointer dereference
     - usbip: Don't submit special requests twice
     - smack: tcp: ipv4, fix incorrect labeling
     - media: uvcvideo: Enforce alignment of frame and interval
     - block: initialize integrity buffer to zero before writing it to media
     - virtio_net: Fix napi_skb_cache_put warning
     - udf: Limit file size to 4TB
     - ALSA: usb-audio: Sanity checks for each pipe and EP types
     - ALSA: usb-audio: Fix gpf in snd_usb_pipe_sanity_check
     - sch/netem: fix use after free in netem_dequeue
     - ALSA: hda/conexant: Add pincfg quirk to enable top speakers on Sirius devices
     - ata: libata: Fix memory leak for error path in ata_host_alloc()
     - mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K
     - fuse: use unsigned type for getxattr/listxattr size truncation
     - clk: qcom: clk-alpha-pll: Fix the pll post div mask
     - nilfs2: fix missing cleanup on rollforward recovery error
     - nilfs2: fix state management in error path of log writing function
     - ALSA: hda: Add input value sanity checks to HDMI channel map controls
     - smack: unix sockets: fix accept()ed socket label
     - irqchip/armada-370-xp: Do not allow mapping IRQ 0 and 1
     - af_unix: Remove put_pid()/put_cred() in copy_peercred().
     - netfilter: nf_conncount: fix wrong variable type
     - udf: Avoid excessive partition lengths
     - wifi: brcmsmac: advertise MFP_CAPABLE to enable WPA3
     - media: qcom: camss: Add check for v4l2_fwnode_endpoint_parse
     - pcmcia: Use resource_size function on resource object
     - can: bcm: Remove proc entry when dev is unregistered.
     - igb: Fix not clearing TimeSync interrupts for 82580
     - platform/x86: dell-smbios: Fix error path in dell_smbios_init()
     - cx82310_eth: re-enable ethernet mode after router reboot
     - drivers/net/usb: Remove all strcpy() uses
     - net: usb: don't write directly to netdev-&gt;dev_addr
     - usbnet: modern method to get random MAC
     - rfkill: fix spelling mistake contidion to condition
     - net: bridge: add support for sticky fdb entries
     - bridge: switchdev: Allow clearing FDB entry offload indication
     - net: bridge: fdb: convert is_local to bitops
     - net: bridge: fdb: convert is_static to bitops
     - net: bridge: fdb: convert is_sticky to bitops
     - net: bridge: fdb: convert added_by_user to bitops
     - net: bridge: fdb: convert added_by_external_learn to use bitops
     - net: bridge: br_fdb_external_learn_add(): always set EXT_LEARN
     - net: dsa: vsc73xx: fix possible subblocks range of CAPT block
     - iommu/vt-d: Handle volatile descriptor status read
     - cgroup: Protect css-&gt;cgroup write under css_set_lock
     - um: line: always fill *error_out in setup_one_line()
     - devres: Initialize an uninitialized struct member
     - pci/hotplug/pnv_php: Fix hotplug driver crash on Powernv
     - hwmon: (adc128d818) Fix underflows seen when writing limit attributes
     - hwmon: (lm95234) Fix underflows seen when writing limit attributes
     - hwmon: (nct6775-core) Fix underflows seen when writing limit attributes
     - hwmon: (w83627ehf) Fix underflows seen when writing limit attributes
     - wifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id()
     - smp: Add missing destroy_work_on_stack() call in smp_call_on_cpu()
     - btrfs: replace BUG_ON with ASSERT in walk_down_proc()
     - btrfs: clean up our handling of refs == 0 in snapshot delete
     - PCI: Add missing bridge lock to pci_bus_lock()
     - btrfs: initialize location to fix -Wmaybe-uninitialized in btrfs_lookup_dentry()
     - HID: cougar: fix slab-out-of-bounds Read in cougar_report_fixup
     - Input: uinput - reject requests with unreasonable number of slots
     - usbnet: ipheth: race between ipheth_close and error handling
     - Squashfs: sanity check symbolic link size
     - of/irq: Prevent device address out-of-bounds read in interrupt map walk
     - ata: pata_macio: Use WARN instead of BUG
     - iio: buffer-dmaengine: fix releasing dma channel on error
     - iio: fix scale application in iio_convert_raw_to_processed_unlocked
     - nvmem: Fix return type of devm_nvmem_device_get() in kerneldoc
     - uio_hv_generic: Fix kernel NULL pointer dereference in hv_uio_rescind
     - Drivers: hv: vmbus: Fix rescind handling in uio_hv_generic
     - VMCI: Fix use-after-free when removing resource in vmci_resource_remove()
     - clocksource/drivers/imx-tpm: Fix return -ETIME when delta exceeds INT_MAX
     - clocksource/drivers/imx-tpm: Fix next event not taking effect sometime
     - uprobes: Use kzalloc to allocate xol area
     - ring-buffer: Rename ring_buffer_read() to read_buffer_iter_advance()
     - tracing: Avoid possible softlockup in tracing_iter_reset()
     - nilfs2: replace snprintf in show functions with sysfs_emit
     - nilfs2: protect references to superblock parameters exposed in sysfs
     - netns: add pre_exit method to struct pernet_operations
     - ila: call nf_unregister_net_hooks() sooner
     - ACPI: processor: Return an error if acpi_processor_get_info() fails in processor_add()
     - ACPI: processor: Fix memory leaks in error paths of processor_add()
     - drm/i915/fence: Mark debug_fence_init_onstack() with __maybe_unused
     - drm/i915/fence: Mark debug_fence_free() with __maybe_unused
     - rtmutex: Drop rt_mutex::wait_lock before scheduling
     - net, sunrpc: Remap EPERM in case of connection failure in xs_tcp_setup_socket
     - cx82310_eth: fix error return code in cx82310_bind()
     - netns: restore ops before calling ops_exit_list
     - Revert "parisc: Use irq_enter_rcu() to fix warning at kernel/context_tracking.c:367"
     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.323
     - staging: iio: frequency: ad9833: Get frequency value statically
     - staging: iio: frequency: ad9833: Load clock using clock framework
     - staging: iio: frequency: ad9834: Validate frequency parameter value
     - usbnet: ipheth: fix carrier detection in modes 1 and 4
     - net: ethernet: use ip_hdrlen() instead of bit shift
     - net: phy: vitesse: repair vsc73xx autonegotiation
     - scripts: kconfig: merge_config: config files: add a trailing newline
     - arm64: dts: rockchip: override BIOS_DISABLE signal via GPIO hog on RK3399 Puma
     - net/mlx5: Update the list of the PCI supported devices
     - net: ftgmac100: Enable TX interrupt to avoid TX timeout
     - net: dpaa: Pad packets to ETH_ZLEN
     - soundwire: stream: Revert "soundwire: stream: fix programming slave ports for non-continous port maps"
     - selftests/vm: remove call to ksft_set_plan()
     - selftests/kcmp: remove call to ksft_set_plan()
     - ASoC: allow module autoloading for table db1200_pids
     - pinctrl: at91: make it work with current gpiolib
     - microblaze: don't treat zero reserved memory regions as error
     - net: ftgmac100: Ensure tx descriptor updates are visible
     - wifi: iwlwifi: mvm: fix iwl_mvm_max_scan_ie_fw_cmd_room()
     - wifi: iwlwifi: mvm: don't wait for tx queues if firmware is dead
     - ASoC: tda7419: fix module autoloading
     - spi: bcm63xx: Enable module autoloading
     - x86/hyperv: Set X86_FEATURE_TSC_KNOWN_FREQ when Hyper-V provides frequency
     - ocfs2: add bounds checking to ocfs2_xattr_find_entry()
     - ocfs2: strict bound check before memcmp in ocfs2_xattr_find_entry()
     - gpio: prevent potential speculation leaks in gpio_device_get_desc()
     - USB: serial: pl2303: add device id for Macrosilicon MS3020
     - ACPI: PMIC: Remove unneeded check in tps68470_pmic_opregion_probe()
     - wifi: ath9k: fix parameter check in ath9k_init_debug()
     - wifi: ath9k: Remove error checks when creating debugfs entries
     - netfilter: nf_tables: elements with timeout below CONFIG_HZ never expire
     - wifi: cfg80211: fix UBSAN noise in cfg80211_wext_siwscan()
     - wifi: cfg80211: fix two more possible UBSAN-detected off-by-one errors
     - wifi: mac80211: use two-phase skb reclamation in ieee80211_do_stop()
     - can: bcm: Clear bo-&gt;bcm_proc_read after remove_proc_entry().
     - Bluetooth: btusb: Fix not handling ZPL/short-transfer
     - block, bfq: fix possible UAF for bfqq-&gt;bic with merge chain
     - block, bfq: choose the last bfqq from merge chain in bfq_setup_cooperator()
     - block, bfq: don't break merge chain in bfq_split_bfqq()
     - spi: ppc4xx: handle irq_of_parse_and_map() errors
     - spi: ppc4xx: Avoid returning 0 when failed to parse and map IRQ
     - ARM: versatile: fix OF node leak in CPUs prepare
     - reset: berlin: fix OF node leak in probe() error path
     - clocksource/drivers/qcom: Add missing iounmap() on errors in msm_dt_timer_init()
     - hwmon: (max16065) Fix overflows seen when writing limits
     - mtd: slram: insert break after errors in parsing the map
     - hwmon: (ntc_thermistor) fix module autoloading
     - power: supply: max17042_battery: Fix SOC threshold calc w/ no current sense
     - fbdev: hpfb: Fix an error handling path in hpfb_dio_probe()
     - drm/stm: Fix an error handling path in stm_drm_platform_probe()
     - drm/amd: fix typo
     - drm/amdgpu: Replace one-element array with flexible-array member
     - drm/amdgpu: properly handle vbios fake edid sizing
     - drm/radeon: Replace one-element array with flexible-array member
     - drm/radeon: properly handle vbios fake edid sizing
     - drm/rockchip: vop: Allow 4096px width scaling
     - drm/radeon/evergreen_cs: fix int overflow errors in cs track offsets
     - jfs: fix out-of-bounds in dbNextAG() and diAlloc()
     - drm/msm/a5xx: properly clear preemption records on resume
     - drm/msm/a5xx: fix races in preemption evaluation stage
     - ipmi: docs: don't advertise deprecated sysfs entries
     - drm/msm: fix %s null argument error
     - xen: use correct end address of kernel for conflict checking
     - xen/swiotlb: simplify range_straddles_page_boundary()
     - xen/swiotlb: add alignment check for dma buffers
     - selftests/bpf: Fix error compiling test_lru_map.c
     - xz: cleanup CRC32 edits from 2018
     - kthread: add kthread_work tracepoints
     - kthread: fix task state in kthread worker if being frozen
     - jbd2: introduce/export functions jbd2_journal_submit|finish_inode_data_buffers()
     - ext4: clear EXT4_GROUP_INFO_WAS_TRIMMED_BIT even mount with discard
     - smackfs: Use rcu_assign_pointer() to ensure safe assignment in smk_set_cipso
     - ext4: avoid negative min_clusters in find_group_orlov()
     - ext4: return error on ext4_find_inline_entry
     - ext4: avoid OOB when system.data xattr changes underneath the filesystem
     - nilfs2: fix potential null-ptr-deref in nilfs_btree_insert()
     - nilfs2: determine empty node blocks as corrupted
     - nilfs2: fix potential oob read in nilfs_btree_check_delete()
     - perf sched timehist: Fix missing free of session in perf_sched__timehist()
     - perf sched timehist: Fixed timestamp error when unable to confirm event sched_in time
     - perf time-utils: Fix 32-bit nsec parsing
     - clk: rockchip: Set parent rate for DCLK_VOP clock on RK3228
     - drivers: media: dvb-frontends/rtl2832: fix an out-of-bounds write error
     - drivers: media: dvb-frontends/rtl2830: fix an out-of-bounds write error
     - PCI: xilinx-nwl: Fix register misspelling
     - RDMA/iwcm: Fix WARNING:at_kernel/workqueue.c:#check_flush_dependency
     - pinctrl: single: fix missing error code in pcs_probe()
     - clk: ti: dra7-atl: Fix leak of of_nodes
     - pinctrl: mvebu: Fix devinit_dove_pinctrl_probe function
     - RDMA/cxgb4: Added NULL check for lookup_atid
     - ntb: intel: Fix the NULL vs IS_ERR() bug for debugfs_create_dir()
     - nfsd: call cache_put if xdr_reserve_space returns NULL
     - f2fs: enhance to update i_mode and acl atomically in f2fs_setattr()
     - f2fs: fix typo
     - f2fs: fix to update i_ctime in __f2fs_setxattr()
     - f2fs: remove unneeded check condition in __f2fs_setxattr()
     - f2fs: reduce expensive checkpoint trigger frequency
     - coresight: tmc: sg: Do not leak sg_table
     - netfilter: nf_reject_ipv6: fix nf_reject_ip6_tcphdr_put()
     - net: seeq: Fix use after free vulnerability in ether3 Driver Due to Race Condition
     - tcp: introduce tcp_skb_timestamp_us() helper
     - tcp: check skb is non-NULL in tcp_rto_delta_us()
     - net: qrtr: Update packets cloning when broadcasting
     - netfilter: ctnetlink: compile ctnetlink_label_size with CONFIG_NF_CONNTRACK_EVENTS
     - crypto: aead,cipher - zeroize key buffer after use
     - Remove *.orig pattern from .gitignore
     - soc: versatile: integrator: fix OF node leak in probe() error path
     - USB: appledisplay: close race between probe and completion handler
     - USB: misc: cypress_cy7c63: check for short transfer
     - firmware_loader: Block path traversal
     - tty: rp2: Fix reset with non forgiving PCIe host bridges
     - drbd: Fix atomicity violation in drbd_uuid_set_bm()
     - drbd: Add NULL check for net_conf to prevent dereference in state validation
     - ACPI: sysfs: validate return type of _STR method
     - f2fs: prevent possible int overflow in dir_block_index()
     - f2fs: avoid potential int overflow in sanity_check_area_boundary()
     - vfs: fix race between evice_inodes() and find_inode()&amp;iput()
     - fs: Fix file_set_fowner LSM hook inconsistencies
     - nfs: fix memory leak in error path of nfs4_do_reclaim
     - PCI: xilinx-nwl: Use irq_data_get_irq_chip_data()
     - PCI: xilinx-nwl: Fix off-by-one in INTx IRQ handler
     - soc: versatile: realview: fix memory leak during device remove
     - soc: versatile: realview: fix soc_dev leak during device remove
     - usb: yurex: Replace snprintf() with the safer scnprintf() variant
     - USB: misc: yurex: fix race between read and write
     - pps: remove usage of the deprecated ida_simple_xx() API
     - pps: add an error check in parport_attach
     - i2c: aspeed: Update the stop sw state when the bus recovery occurs
     - i2c: isch: Add missed 'else'
     - usb: yurex: Fix inconsistent locking bug in yurex_read()
     - mailbox: rockchip: fix a typo in module autoloading
     - mailbox: bcm2835: Fix timeout during suspend mode
     - ceph: remove the incorrect Fw reference check when dirtying pages
     - netfilter: uapi: NFTA_FLOWTABLE_HOOK is NLA_NESTED
     - netfilter: nf_tables: prevent nf_skb_duplicated corruption
     - r8152: Factor out OOB link list waits
     - net: ethernet: lantiq_etop: fix memory disclosure
     - net: avoid potential underflow in qdisc_pkt_len_init() with UFO
     - net: add more sanity checks to qdisc_pkt_len_init()
     - ipv4: ip_gre: Fix drops of small packets in ipgre_xmit
     - sctp: set sk_state back to CLOSED if autobind fails in sctp_listen_start
     - ALSA: hda/generic: Unconditionally prefer preferred_dacs pairs
     - ALSA: hda/conexant: Fix conflicting quirk for System76 Pangolin
     - f2fs: Require FMODE_WRITE for atomic write ioctls
     - wifi: ath9k: fix possible integer overflow in ath9k_get_et_stats()
     - wifi: ath9k_htc: Use __skb_set_length() for resetting urb before resubmit
     - net: hisilicon: hip04: fix OF node leak in probe()
     - net: hisilicon: hns_dsaf_mac: fix OF node leak in hns_mac_get_info()
     - net: hisilicon: hns_mdio: fix OF node leak in probe()
     - ACPICA: Fix memory leak if acpi_ps_get_next_namepath() fails
     - ACPICA: Fix memory leak if acpi_ps_get_next_field() fails
     - ACPI: EC: Do not release locks during operation region accesses
     - ACPICA: check null return of ACPI_ALLOCATE_ZEROED() in acpi_db_convert_to_package()
     - tipc: guard against string buffer overrun
     - net: mvpp2: Increase size of queue_name buffer
     - ipv4: Check !in_dev earlier for ioctl(SIOCSIFADDR).
     - ipv4: Mask upper DSCP bits and ECN bits in NETLINK_FIB_LOOKUP family
     - tcp: avoid reusing FIN_WAIT2 when trying to find port in connect() process
     - ACPICA: iasl: handle empty connection_node
     - wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_cmd_802_11_scan_ext()
     - signal: Replace BUG_ON()s
     - ALSA: asihpi: Fix potential OOB array access
     - ALSA: hdsp: Break infinite MIDI input flush loop
     - fbdev: pxafb: Fix possible use after free in pxafb_task()
     - power: reset: brcmstb: Do not go into infinite loop if reset fails
     - ata: sata_sil: Rename sil_blacklist to sil_quirks
     - jfs: UBSAN: shift-out-of-bounds in dbFindBits
     - jfs: Fix uaf in dbFreeBits
     - jfs: check if leafidx greater than num leaves per dmap tree
     - jfs: Fix uninit-value access of new_ea in ea_buffer
     - drm/amd/display: Check stream before comparing them
     - drm/amd/display: Fix index out of bounds in degamma hardware format translation
     - drm/printer: Allow NULL data in devcoredump printer
     - scsi: aacraid: Rearrange order of struct aac_srb_unit
     - drm/radeon/r100: Handle unknown family in r100_cp_init_microcode()
     - of/irq: Refer to actual buffer size in of_irq_parse_one()
     - ext4: ext4_search_dir should return a proper error
     - ext4: fix i_data_sem unlock order in ext4_ind_migrate()
     - spi: s3c64xx: fix timeout counters in flush_fifo
     - selftests: breakpoints: use remaining time to check if suspend succeed
     - selftests: vDSO: fix vDSO symbols lookup for powerpc64
     - i2c: xiic: Wait for TX empty to avoid missed TX NAKs
     - spi: bcm63xx: Fix module autoloading
     - perf/core: Fix small negative period being ignored
     - parisc: Fix itlb miss handler for 64-bit programs
     - ALSA: core: add isascii() check to card ID generator
     - ext4: no need to continue when the number of entries is 1
     - ext4: propagate errors from ext4_find_extent() in ext4_insert_range()
     - ext4: fix incorrect tid assumption in __jbd2_log_wait_for_space()
     - ext4: aovid use-after-free in ext4_ext_insert_extent()
     - ext4: fix double brelse() the buffer of the extents path
     - ext4: fix incorrect tid assumption in ext4_wait_for_tail_page_commit()
     - parisc: Fix 64-bit userspace syscall path
     - of/irq: Support #msi-cells=&lt;0&gt; in of_msi_get_domain
     - jbd2: stop waiting for space when jbd2_cleanup_journal_tail() returns error
     - ocfs2: fix the la space leak when unmounting an ocfs2 volume
     - ocfs2: fix uninit-value in ocfs2_get_block()
     - ocfs2: reserve space for inline xattr before attaching reflink tree
     - ocfs2: cancel dqi_sync_work before freeing oinfo
     - ocfs2: remove unreasonable unlock in ocfs2_read_blocks
     - ocfs2: fix null-ptr-deref when journal load failed.
     - ocfs2: fix possible null-ptr-deref in ocfs2_set_buffer_uptodate
     - riscv: define ILLEGAL_POINTER_VALUE for 64bit
     - aoe: fix the potential use-after-free problem in more places
     - clk: rockchip: fix error for unknown clocks
     - media: uapi/linux/cec.h: cec_msg_set_reply_to: zero flags
     - media: venus: fix use after free bug in venus_remove due to race condition
     - iio: magnetometer: ak8975: Fix reading for ak099xx sensors
     - tomoyo: fallback to realpath if symlink's pathname does not exist
     - Input: adp5589-keys - fix adp5589_gpio_get_value()
     - btrfs: wait for fixup workers before stopping cleaner kthread during umount
     - gpio: davinci: fix lazy disable
     - ext4: avoid ext4_error()'s caused by ENOMEM in the truncate path
     - ext4: fix slab-use-after-free in ext4_split_extent_at()
     - ext4: update orig_path in ext4_find_extent()
     - arm64: Add Cortex-715 CPU part definition
     - arm64: cputype: Add Neoverse-N3 definitions
     - arm64: errata: Expand speculative SSBS workaround once more
     - uprobes: fix kernel info leak via "[uprobes]" vma
     - nfsd: use ktime_get_seconds() for timestamps
     - nfsd: fix delegation_blocked() to block correctly for at least 30 seconds
     - rtc: at91sam9: drop platform_data support
     - rtc: at91sam9: fix OF node leak in probe() error path
     - ACPI: battery: Simplify battery hook locking
     - ACPI: battery: Fix possible crash when unregistering a battery hook
     - ext4: fix inode tree inconsistency caused by ENOMEM
     - net: ethernet: cortina: Drop TSO support
     - tracing: Remove precision vsnprintf() check from print event
     - drm: Move drm_mode_setcrtc() local re-init to failure path
     - drm/crtc: fix uninitialized variable use even harder
     - virtio_console: fix misc probe bugs
     - Input: synaptics-rmi4 - fix UAF of IRQ domain on driver removal
     - bpf: Check percpu map value size first
     - s390/facility: Disable compile time optimization for decompressor code
     - s390/mm: Add cond_resched() to cmm_alloc/free_pages()
     - ext4: nested locking for xattr inode
     - s390/cpum_sf: Remove WARN_ON_ONCE statements
     - ktest.pl: Avoid false positives with grub2 skip regex
     - clk: bcm: bcm53573: fix OF node leak in init
     - i2c: i801: Use a different adapter-name for IDF adapters
     - PCI: Mark Creative Labs EMU20k2 INTx masking as broken
     - media: videobuf2-core: clear memory related fields in __vb2_plane_dmabuf_put()
     - usb: chipidea: udc: enable suspend interrupt after usb reset
     - tools/iio: Add memory allocation failure check for trigger_name
     - driver core: bus: Return -EIO instead of 0 when show/store invalid bus attribute
     - fbdev: sisfb: Fix strbuf array overflow
     - NFS: Remove print_overflow_msg()
     - SUNRPC: Fix integer overflow in decode_rc_list()
     - tcp: fix tcp_enter_recovery() to zero retrans_stamp when it's safe
     - netfilter: br_netfilter: fix panic with metadata_dst skb
     - Bluetooth: RFCOMM: FIX possible deadlock in rfcomm_sk_state_change
     - gpio: aspeed: Add the flush write to ensure the write complete.
     - clk: Add (devm_)clk_get_optional() functions
     - clk: generalize devm_clk_get() a bit
     - clk: Provide new devm_clk helpers for prepared and enabled clocks
     - gpio: aspeed: Use devm_clk api to manage clock source
     - igb: Do not bring the device up after non-fatal error
     - net: ibm: emac: mal: fix wrong goto
     - ppp: fix ppp_async_encode() illegal access
     - net: ipv6: ensure we call ipv6_mc_down() at most once
     - CDC-NCM: avoid overflow in sanity checking
     - HID: plantronics: Workaround for an unexcepted opposite volume key
     - Revert "usb: yurex: Replace snprintf() with the safer scnprintf() variant"
     - usb: xhci: Fix problem with xhci resume from suspend
     - usb: storage: ignore bogus device raised by JieLi BR21 USB sound chip
     - net: Fix an unsafe loop on the list
     - posix-clock: Fix missing timespec64 check in pc_clock_settime()
     - arm64: probes: Remove broken LDR (literal) uprobe support
     - arm64: probes: Fix simulate_ldr*_literal()
     - PCI: Add function 0 DMA alias quirk for Glenfly Arise chip
     - fat: fix uninitialized variable
     - KVM: Fix a data race on last_boosted_vcpu in kvm_vcpu_on_spin()
     - net: dsa: mv88e6xxx: Fix out-of-bound access
     - s390/sclp_vt220: Convert newlines to CRLF instead of LFCR
     - KVM: s390: Change virtual to physical address access in diag 0x258 handler
     - x86/cpufeatures: Define X86_FEATURE_AMD_IBPB_RET
     - drm/vmwgfx: Handle surface check failure correctly
     - iio: dac: stm32-dac-core: add missing select REGMAP_MMIO in Kconfig
     - iio: adc: ti-ads8688: add missing select IIO_(TRIGGERED_)BUFFER in Kconfig
     - iio: hid-sensors: Fix an error handling path in _hid_sensor_set_report_latency()
     - iio: light: opt3001: add missing full-scale range value
     - Bluetooth: Remove debugfs directory on module init failure
     - Bluetooth: btusb: Fix regression with fake CSR controllers 0a12:0001
     - xhci: Fix incorrect stream context type macro
     - USB: serial: option: add support for Quectel EG916Q-GL
     - USB: serial: option: add Telit FN920C04 MBIM compositions
     - parport: Proper fix for array out-of-bounds access
     - x86/apic: Always explicitly disarm TSC-deadline timer
     - nilfs2: propagate directory read errors from nilfs_find_entry()
     - clk: Fix pointer casting to prevent oops in devm_clk_release()
     - clk: Fix slab-out-of-bounds error in devm_clk_release()
     - RDMA/bnxt_re: Fix incorrect AVID type in WQE structure
     - RDMA/cxgb4: Fix RDMA_CM_EVENT_UNREACHABLE error for iWARP
     - RDMA/bnxt_re: Return more meaningful error
     - drm/msm/dsi: fix 32-bit signed integer extension in pclk_rate calculation
     - macsec: don't increment counters for an unrelated SA
     - net: ethernet: aeroflex: fix potential memory leak in greth_start_xmit_gbit()
     - net: systemport: fix potential memory leak in bcm_sysport_xmit()
     - usb: typec: altmode should keep reference to parent
     - Bluetooth: bnep: fix wild-memory-access in proto_unregister
     - arm64:uprobe fix the uprobe SWBP_INSN in big-endian
     - arm64: probes: Fix uprobes for big-endian kernels
     - KVM: s390: gaccess: Refactor gpa and length calculation
     - KVM: s390: gaccess: Refactor access address range check
     - KVM: s390: gaccess: Cleanup access to guest pages
     - KVM: s390: gaccess: Check if guest address is in memslot
     - udf: fix uninit-value use in udf_get_fileshortad
     - jfs: Fix sanity check in dbMount
     - net/sun3_82586: fix potential memory leak in sun3_82586_send_packet()
     - be2net: fix potential memory leak in be_xmit()
     - net: usb: usbnet: fix name regression
     - posix-clock: posix-clock: Fix unbalanced locking in pc_clock_settime()
     - ALSA: hda/realtek: Update default depop procedure
     - drm/amd: Guard against bad data for ATIF ACPI method
     - ACPI: button: Add DMI quirk for Samsung Galaxy Book2 to fix initial lid detection issue
     - nilfs2: fix kernel bug due to missing clearing of buffer delay flag
     - hv_netvsc: Fix VF namespace also in synthetic NIC NETDEV_REGISTER event
     - selinux: improve error checking in sel_write_load()
     - arm64/uprobes: change the uprobe_opcode_t typedef to fix the sparse warning
     - xfrm: validate new SA's prefixlen using SA family when sel.family is unset
     - usb: dwc3: remove generic PHY calibrate() calls
     - usb: dwc3: Add splitdisable quirk for Hisilicon Kirin Soc
     - usb: dwc3: core: Stop processing of pending events if controller is halted
     - cgroup: Fix potential overflow issue when checking max_depth
     - wifi: mac80211: skip non-uploaded keys in ieee80211_iter_keys
     - gtp: simplify error handling code in 'gtp_encap_enable()'
     - gtp: allow -1 to be specified as file description from userspace
     - net/sched: stop qdisc_tree_reduce_backlog on TC_H_ROOT
     - bpf: Fix out-of-bounds write in trie_get_next_key()
     - net: support ip generic csum processing in skb_csum_hwoffload_help
     - net: skip offload for NETIF_F_IPV6_CSUM if ipv6 header contains extension
     - netfilter: nft_payload: sanitize offset and length before calling skb_checksum()
     - firmware: arm_sdei: Fix the input parameter of cpuhp_remove_state()
     - net: amd: mvme147: Fix probe banner message
     - misc: sgi-gru: Don't disable preemption in GRU driver
     - usbip: tools: Fix detach_port() invalid port error path
     - usb: phy: Fix API devm_usb_put_phy() can not release the phy
     - xhci: Fix Link TRB DMA in command ring stopped completion event
     - Revert "driver core: Fix uevent_show() vs driver detach race"
     - wifi: mac80211: do not pass a stopped vif to the driver in .get_txpower
     - wifi: ath10k: Fix memory leak in management tx
     - wifi: iwlegacy: Clear stale interrupts before resuming device
     - nilfs2: fix potential deadlock with newly created symlinks
     - ocfs2: pass u64 to ocfs2_truncate_inline maybe overflow
     - nilfs2: fix kernel bug due to missing clearing of checked flag
     - mm: shmem: fix data-race in shmem_getattr()
     - vt: prevent kernel-infoleak in con_font_get()
     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.324
     - arm64: dts: rockchip: Fix rt5651 compatible value on rk3399-sapphire-excavator
     - ARM: dts: rockchip: fix rk3036 acodec node
     - ARM: dts: rockchip: drop grf reference from rk3036 hdmi
     - ARM: dts: rockchip: Fix the realtek audio codec on rk3036-kylin
     - HID: core: zero-initialize the report buffer
     - security/keys: fix slab-out-of-bounds in key_task_permission
     - sctp: properly validate chunk size in sctp_sf_ootb()
     - can: c_can: fix {rx,tx}_errors statistics
     - net: hns3: fix kernel crash when uninstalling driver
     - media: stb0899_algo: initialize cfr before using it
     - media: dvbdev: prevent the risk of out of memory access
     - media: dvb_frontend: don't play tricks with underflow values
     - media: adv7604: prevent underflow condition when reporting colorspace
     - ALSA: firewire-lib: fix return value on fail in amdtp_tscm_init()
     - media: s5p-jpeg: prevent buffer overflows
     - media: cx24116: prevent overflows on SNR calculus
     - media: v4l2-tpg: prevent the risk of a division by zero
     - drm/amdgpu: add missing size check in amdgpu_debugfs_gprwave_read()
     - drm/amdgpu: prevent NULL pointer dereference if ATIF is not supported
     - dm cache: correct the number of origin blocks to match the target length
     - dm cache: fix out-of-bounds access to the dirty bitset when resizing
     - dm cache: optimize dirty bit checking with find_next_bit when resizing
     - dm cache: fix potential out-of-bounds access on the first resume
     - dm-unstriped: cast an operand to sector_t to prevent potential uint32_t overflow
     - nfs: Fix KMSAN warning in decode_getfattr_attrs()
     - btrfs: reinitialize delayed ref list after deleting it from the list
     - bonding (gcc13): synchronize bond_{a,t}lb_xmit() types
     - net: bridge: xmit: make sure we have at least eth header len bytes
     - media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format
     - fs/proc: fix compile warning about variable 'vmcore_mmap_ops'
     - usb: musb: sunxi: Fix accessing an released usb phy
     - USB: serial: io_edgeport: fix use after free in debug printk
     - USB: serial: qcserial: add support for Sierra Wireless EM86xx
     - USB: serial: option: add Fibocom FG132 0x0112 composition
     - USB: serial: option: add Quectel RG650V
     - irqchip/gic-v3: Force propagation of the active state with a read-back
     - ocfs2: remove entry once instead of null-ptr-dereference in ocfs2_xa_remove()
     - ALSA: pcm: Return 0 when size &lt; start_threshold in capture
     - ALSA: usb-audio: Add custom mixer status quirks for RME CC devices
     - ALSA: usb-audio: Support jack detection on Dell dock
     - ALSA: usb-audio: Add quirks for Dell WD19 dock
     - hv_sock: Initializing vsk-&gt;trans to NULL to prevent a dangling pointer
     - vsock/virtio: Initialization of the dangling pointer occurring in vsk-&gt;trans
     - ALSA: usb-audio: Add endianness annotations
     - 9p: Avoid creating multiple slab caches with the same name
     - HID: multitouch: Add quirk for HONOR MagicBook Art 14 touchpad
     - bpf: use kvzmalloc to allocate BPF verifier environment
     - sound: Make CONFIG_SND depend on INDIRECT_IOMEM instead of UML
     - powerpc/powernv: Free name on error in opal_event_init()
     - fs: Fix uninitialized value issue in from_kuid and from_kgid
     - net: usb: qmi_wwan: add Fibocom FG132 0x0112 composition
     - 9p: fix slab cache name creation for real
     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.325
     - netlink: terminate outstanding dump on socket close
     - ocfs2: uncache inode which has failed entering the group
     - nilfs2: fix null-ptr-deref in block_touch_buffer tracepoint
     - ocfs2: fix UBSAN warning in ocfs2_verify_volume()
     - nilfs2: fix null-ptr-deref in block_dirty_buffer tracepoint
     - Revert "mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K"
     - media: dvbdev: fix the logic when DVB_DYNAMIC_MINORS is not set
     - kbuild: Use uname for LINUX_COMPILE_HOST detection
     - mm: revert "mm: shmem: fix data-race in shmem_getattr()"
     - ASoC: Intel: bytcr_rt5640: Add DMI quirk for Vexia Edu Atla 10 tablet
     - mac80211: fix user-power when emulating chanctx
     - selftests/watchdog-test: Fix system accidentally reset after watchdog-test
     - x86/amd_nb: Fix compile-testing without CONFIG_AMD_NB
     - net: usb: qmi_wwan: add Quectel RG650V
     - proc/softirqs: replace seq_printf with seq_put_decimal_ull_width
     - nvme: fix metadata handling in nvme-passthrough
     - initramfs: avoid filename buffer overrun
     - m68k: mvme147: Fix SCSI controller IRQ numbers
     - m68k: mvme16x: Add and use "mvme16x.h"
     - m68k: mvme147: Reinstate early console
     - acpi/arm64: Adjust error handling procedure in gtdt_parse_timer_block()
     - s390/syscalls: Avoid creation of arch/arch/ directory
     - hfsplus: don't query the device logical block size multiple times
     - EDAC/fsl_ddr: Fix bad bit shift operations
     - crypto: pcrypt - Call crypto layer directly when padata_do_parallel() return -EBUSY
     - crypto: cavium - Fix the if condition to exit loop after timeout
     - crypto: bcm - add error check in the ahash_hmac_init function
     - crypto: cavium - Fix an error handling path in cpt_ucode_load_fw()
     - time: Fix references to _msecs_to_jiffies() handling of values
     - soc: qcom: geni-se: fix array underflow in geni_se_clk_tbl_get()
     - mmc: mmc_spi: drop buggy snprintf()
     - ARM: dts: cubieboard4: Fix DCDC5 regulator constraints
     - regmap: irq: Set lockdep class for hierarchical IRQ domains
     - firmware: arm_scpi: Check the DVFS OPP count returned by the firmware
     - drm/mm: Mark drm_mm_interval_tree*() functions with __maybe_unused
     - wifi: ath9k: add range check for conn_rsp_epid in htc_connect_service()
     - drm/omap: Fix locking in omap_gem_new_dmabuf()
     - bpf: Fix the xdp_adjust_tail sample prog issue
     - wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_config_scan()
     - drm/etnaviv: consolidate hardware fence handling in etnaviv_gpu
     - drm/etnaviv: dump: fix sparse warnings
     - drm/etnaviv: fix power register offset on GC300
     - drm/etnaviv: hold GPU lock across perfmon sampling
     - net: rfkill: gpio: Add check for clk_enable()
     - ALSA: us122l: Use snd_card_free_when_closed() at disconnection
     - ALSA: caiaq: Use snd_card_free_when_closed() at disconnection
     - ALSA: 6fire: Release resources at card release
     - netpoll: Use rcu_access_pointer() in netpoll_poll_lock
     - trace/trace_event_perf: remove duplicate samples on the first tracepoint event
     - powerpc/vdso: Flag VDSO64 entry points as functions
     - mfd: da9052-spi: Change read-mask to write-mask
     - cpufreq: loongson2: Unregister platform_driver on failure
     - mtd: rawnand: atmel: Fix possible memory leak
     - RDMA/bnxt_re: Check cqe flags to know imm_data vs inv_irkey
     - mfd: rt5033: Fix missing regmap_del_irq_chip()
     - scsi: bfa: Fix use-after-free in bfad_im_module_exit()
     - scsi: fusion: Remove unused variable 'rc'
     - scsi: qedi: Fix a possible memory leak in qedi_alloc_and_init_sb()
     - ocfs2: fix uninitialized value in ocfs2_file_read_iter()
     - powerpc/sstep: make emulate_vsx_load and emulate_vsx_store static
     - fbdev/sh7760fb: Alloc DMA memory from hardware device
     - fbdev: sh7760fb: Fix a possible memory leak in sh7760fb_alloc_mem()
     - dt-bindings: clock: adi,axi-clkgen: convert old binding to yaml format
     - dt-bindings: clock: axi-clkgen: include AXI clk
     - clk: axi-clkgen: use devm_platform_ioremap_resource() short-hand
     - clk: clk-axi-clkgen: make sure to enable the AXI bus clock
     - perf probe: Correct demangled symbols in C++ program
     - PCI: cpqphp: Use PCI_POSSIBLE_ERROR() to check config reads
     - PCI: cpqphp: Fix PCIBIOS_* return value confusion
     - m68k: mcfgpio: Fix incorrect register offset for CONFIG_M5441x
     - m68k: coldfire/device.c: only build FEC when HW macros are defined
     - rpmsg: glink: Add TX_DATA_CONT command while sending
     - rpmsg: glink: Send READ_NOTIFY command in FIFO full case
     - rpmsg: glink: Fix GLINK command prefix
     - rpmsg: glink: use only lower 16-bits of param2 for CMD_OPEN name length
     - NFSD: Prevent NULL dereference in nfsd4_process_cb_update()
     - NFSD: Cap the number of bytes copied by nfs4_reset_recoverydir()
     - vfio/pci: Properly hide first-in-list PCIe extended capability
     - power: supply: core: Remove might_sleep() from power_supply_put()
     - net: usb: lan78xx: Fix memory leak on device unplug by freeing PHY device
     - tg3: Set coherent DMA mask bits to 31 for BCM57766 chipsets
     - net: usb: lan78xx: Fix refcounting and autosuspend on invalid WoL configuration
     - marvell: pxa168_eth: fix call balance of pep-&gt;clk handling routines
     - net: stmmac: dwmac-socfpga: Set RX watchdog interrupt as broken
     - usb: using mutex lock and supporting O_NONBLOCK flag in iowarrior_read()
     - USB: chaoskey: fail open after removal
     - USB: chaoskey: Fix possible deadlock chaoskey_list_lock
     - misc: apds990x: Fix missing pm_runtime_disable()
     - apparmor: fix 'Do simple duplicate message elimination'
     - usb: ehci-spear: fix call balance of sehci clk handling routines
     - ext4: supress data-race warnings in ext4_free_inodes_{count,set}()
     - ext4: fix FS_IOC_GETFSMAP handling
     - jfs: xattr: check invalid xattr size more strictly
     - ASoC: codecs: Fix atomicity violation in snd_soc_component_get_drvdata()
     - PCI: Fix use-after-free of slot-&gt;bus on hot remove
     - tty: ldsic: fix tty_ldisc_autoload sysctl's proc_handler
     - Bluetooth: Fix type of len in rfcomm_sock_getsockopt{,_old}()
     - ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices
     - Revert "usb: gadget: composite: fix OS descriptors w_value logic"
     - serial: sh-sci: Clean sci_ports[0] after at earlycon exit
     - Revert "serial: sh-sci: Clean sci_ports[0] after at earlycon exit"
     - netfilter: ipset: add missing range check in bitmap_ip_uadt
     - spi: Fix acpi deferred irq probe
     - ubi: wl: Put source PEB into correct list if trying locking LEB failed
     - um: ubd: Do not use drvdata in release
     - um: net: Do not use drvdata in release
     - serial: 8250: omap: Move pm_runtime_get_sync
     - um: vector: Do not use drvdata in release
     - sh: cpuinfo: Fix a warning for CONFIG_CPUMASK_OFFSTACK
     - arm64: tls: Fix context-switching of tpidrro_el0 when kpti is enabled
     - block: fix ordering between checking BLK_MQ_S_STOPPED request adding
     - HID: wacom: Interpret tilt data from Intuos Pro BT as signed values
     - media: wl128x: Fix atomicity violation in fmc_send_cmd()
     - usb: dwc3: gadget: Fix checking for number of TRBs left
     - lib: string_helpers: silence snprintf() output truncation warning
     - NFSD: Prevent a potential integer overflow
     - rpmsg: glink: Propagate TX failures in intentless mode as well
     - um: Fix the return value of elf_core_copy_task_fpregs
     - NFSv4.0: Fix a use-after-free problem in the asynchronous open()
     - rtc: check if __rtc_read_time was successful in rtc_timer_do_work()
     - ubifs: Correct the total block count by deducting journal reservation
     - ubi: fastmap: Fix duplicate slab cache names while attaching
     - jffs2: fix use of uninitialized variable
     - block: return unsigned int from bdev_io_min
     - 9p/xen: fix init sequence
     - 9p/xen: fix release of IRQ
     - modpost: remove incorrect code in do_eisa_entry()
     - sh: intc: Fix use-after-free bug in register_intc_controller()</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-27 15:49:18 UTC" />
    <updated date="2026-08-27 15:49:18 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1787656450.html" id="CLSA-2026:1787656450" title="CLSA-2026:1787656450" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2023-6270" id="CVE-2023-6270" title="CVE-2023-6270" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-31431" id="CVE-2026-31431" title="CVE-2026-31431" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-53043" id="CVE-2026-53043" title="CVE-2026-53043" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="hyperv-daemons" version="4.19.325-1+tuxcare.els1">
          <filename>hyperv-daemons_4.19.325-1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">fb982c10cc1a618bff008f4126a3b8e8049bcd38</sum>
        </package>
        <package arch="amd64" name="libbpf-dev" version="4.19.325-1+tuxcare.els1">
          <filename>libbpf-dev_4.19.325-1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">5aba74e980b0e262f24068fa86065af8c4a91347</sum>
        </package>
        <package arch="amd64" name="libbpf4.19" version="4.19.325-1+tuxcare.els1">
          <filename>libbpf4.19_4.19.325-1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">ec42764744dc88dfb22b0e51fc3f4d7828c89195</sum>
        </package>
        <package arch="amd64" name="libcpupower-dev" version="4.19.325-1+tuxcare.els1">
          <filename>libcpupower-dev_4.19.325-1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">2a644686b79881daca320663a371cf31d74ec80d</sum>
        </package>
        <package arch="amd64" name="libcpupower1" version="4.19.325-1+tuxcare.els1">
          <filename>libcpupower1_4.19.325-1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">8257cd5aaa58fb3bb634553c2c41b911f7220c8e</sum>
        </package>
        <package arch="amd64" name="linux-compiler-gcc-8-x86" version="4.19.325-1+tuxcare.els1">
          <filename>linux-compiler-gcc-8-x86_4.19.325-1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">865fe9ed2efaa724e56078551646c40bac31c0c6</sum>
        </package>
        <package arch="amd64" name="linux-config-4.19" version="4.19.325-1+tuxcare.els1">
          <filename>linux-config-4.19_4.19.325-1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">dc75d2711cd0d15aee294f4e830c825a0680b416</sum>
        </package>
        <package arch="amd64" name="linux-cpupower" version="4.19.325-1+tuxcare.els1">
          <filename>linux-cpupower_4.19.325-1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">5978a0e0dcfda9ad369e2956add0bb47a41ab9d5</sum>
        </package>
        <package arch="all" name="linux-doc-4.19" version="4.19.325-1+tuxcare.els1">
          <filename>linux-doc-4.19_4.19.325-1+tuxcare.els1_all.deb</filename>
          <sum type="sha">37ebbeea4df23fcca0025dc9cceb7b8b23a8a6ca</sum>
        </package>
        <package arch="amd64" name="linux-headers-4.19.0-28-all" version="4.19.325-1+tuxcare.els1">
          <filename>linux-headers-4.19.0-28-all_4.19.325-1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">27200fa0aea3c58ced88cbfa2844446aca8be391</sum>
        </package>
        <package arch="amd64" name="linux-headers-4.19.0-28-all-amd64" version="4.19.325-1+tuxcare.els1">
          <filename>linux-headers-4.19.0-28-all-amd64_4.19.325-1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">d211de3024993f0bf03c1d49606296d3a7c752c3</sum>
        </package>
        <package arch="amd64" name="linux-headers-4.19.0-28-amd64" version="4.19.325-1+tuxcare.els1">
          <filename>linux-headers-4.19.0-28-amd64_4.19.325-1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">550c56567e1c0529b7a4109878dc80bdfcc5708d</sum>
        </package>
        <package arch="all" name="linux-headers-4.19.0-28-common" version="4.19.325-1+tuxcare.els1">
          <filename>linux-headers-4.19.0-28-common_4.19.325-1+tuxcare.els1_all.deb</filename>
          <sum type="sha">59069286a9b1d0f04986bd86c757ff612656b2ac</sum>
        </package>
        <package arch="amd64" name="linux-image-4.19.0-28-amd64-unsigned" version="4.19.325-1+tuxcare.els1">
          <filename>linux-image-4.19.0-28-amd64-unsigned_4.19.325-1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">fb2f5d5699f9f8fd7f51be9b00db3863edd5a2f6</sum>
        </package>
        <package arch="amd64" name="linux-image-amd64-signed-template" version="4.19.325-1+tuxcare.els1">
          <filename>linux-image-amd64-signed-template_4.19.325-1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">ece3c2b4cdb63bbf270309e02673d36b718f51db</sum>
        </package>
        <package arch="amd64" name="linux-kbuild-4.19" version="4.19.325-1+tuxcare.els1">
          <filename>linux-kbuild-4.19_4.19.325-1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">78d6e5b2543d136e1176fff4b3e3438a6bfff539</sum>
        </package>
        <package arch="amd64" name="linux-libc-dev" version="4.19.325-1+tuxcare.els1">
          <filename>linux-libc-dev_4.19.325-1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">7f74fac131738f30148274adc1049afc64c890bb</sum>
        </package>
        <package arch="amd64" name="linux-perf-4.19" version="4.19.325-1+tuxcare.els1">
          <filename>linux-perf-4.19_4.19.325-1+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">fe6bd2c58eb10bb8da1af7a976ce5553ddccfbcf</sum>
        </package>
        <package arch="all" name="linux-source-4.19" version="4.19.325-1+tuxcare.els1">
          <filename>linux-source-4.19_4.19.325-1+tuxcare.els1_all.deb</filename>
          <sum type="sha">7349f277e132552565981ee47c4a1a0c14ee6c48</sum>
        </package>
        <package arch="all" name="linux-support-4.19.0-28" version="4.19.325-1+tuxcare.els1">
          <filename>linux-support-4.19.0-28_4.19.325-1+tuxcare.els1_all.deb</filename>
          <sum type="sha">78ab6392f66cbaff3b254312dcac641084ef990d</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1788041847</id>
    <title>Fix CVE(s): CVE-2025-48384</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: arbitrary code execution via CR in config values
     - debian/patches/CVE-2025-48384.patch: quote config values containing
       a carriage return so that it is not stripped when read back
     - CVE-2025-48384</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: arbitrary code execution via CR in config values
     - debian/patches/CVE-2025-48384.patch: quote config values containing
       a carriage return so that it is not stripped when read back
     - CVE-2025-48384</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-29 22:17:38 UTC" />
    <updated date="2026-08-29 22:17:38 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1788041847.html" id="CLSA-2026:1788041847" title="CLSA-2026:1788041847" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-48384" id="CVE-2025-48384" title="CVE-2025-48384" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="git" version="1:2.20.1-2+deb10u9+tuxcare.els4">
          <filename>git_2.20.1-2+deb10u9+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">1e39b108b5f6e5775a4dd8a89465ce85767597f7</sum>
        </package>
        <package arch="all" name="git-all" version="1:2.20.1-2+deb10u9+tuxcare.els4">
          <filename>git-all_2.20.1-2+deb10u9+tuxcare.els4_all.deb</filename>
          <sum type="sha">89bc71ecea2b994eedde32ac8c684fb3ec39b437</sum>
        </package>
        <package arch="all" name="git-cvs" version="1:2.20.1-2+deb10u9+tuxcare.els4">
          <filename>git-cvs_2.20.1-2+deb10u9+tuxcare.els4_all.deb</filename>
          <sum type="sha">27d16d9ed9456afe5f365c01a86829300c9c3305</sum>
        </package>
        <package arch="all" name="git-daemon-run" version="1:2.20.1-2+deb10u9+tuxcare.els4">
          <filename>git-daemon-run_2.20.1-2+deb10u9+tuxcare.els4_all.deb</filename>
          <sum type="sha">d4391ddc36d19c9a29d80e97bc3610280bee3553</sum>
        </package>
        <package arch="all" name="git-daemon-sysvinit" version="1:2.20.1-2+deb10u9+tuxcare.els4">
          <filename>git-daemon-sysvinit_2.20.1-2+deb10u9+tuxcare.els4_all.deb</filename>
          <sum type="sha">442e2f8bbd3c3299084ca46cdac6d6d33cb541f8</sum>
        </package>
        <package arch="all" name="git-doc" version="1:2.20.1-2+deb10u9+tuxcare.els4">
          <filename>git-doc_2.20.1-2+deb10u9+tuxcare.els4_all.deb</filename>
          <sum type="sha">e675bee424b87e3a0d0231910e44fa204fb792a6</sum>
        </package>
        <package arch="all" name="git-el" version="1:2.20.1-2+deb10u9+tuxcare.els4">
          <filename>git-el_2.20.1-2+deb10u9+tuxcare.els4_all.deb</filename>
          <sum type="sha">af597b67eaa1ea4d9bb93cddd07dbbfd5e3a0853</sum>
        </package>
        <package arch="all" name="git-email" version="1:2.20.1-2+deb10u9+tuxcare.els4">
          <filename>git-email_2.20.1-2+deb10u9+tuxcare.els4_all.deb</filename>
          <sum type="sha">2c5f0f0d56c175240902e47c242c72f1fa64f680</sum>
        </package>
        <package arch="all" name="git-gui" version="1:2.20.1-2+deb10u9+tuxcare.els4">
          <filename>git-gui_2.20.1-2+deb10u9+tuxcare.els4_all.deb</filename>
          <sum type="sha">91cd4ba52085f68759ad3a0047e0f04bf0630b65</sum>
        </package>
        <package arch="all" name="git-man" version="1:2.20.1-2+deb10u9+tuxcare.els4">
          <filename>git-man_2.20.1-2+deb10u9+tuxcare.els4_all.deb</filename>
          <sum type="sha">a98898663814d1ff3aaa0da8f68b199bf7e48bfa</sum>
        </package>
        <package arch="all" name="git-mediawiki" version="1:2.20.1-2+deb10u9+tuxcare.els4">
          <filename>git-mediawiki_2.20.1-2+deb10u9+tuxcare.els4_all.deb</filename>
          <sum type="sha">52467a3f734b887ea8ac44f6f03a1faf21125853</sum>
        </package>
        <package arch="all" name="git-svn" version="1:2.20.1-2+deb10u9+tuxcare.els4">
          <filename>git-svn_2.20.1-2+deb10u9+tuxcare.els4_all.deb</filename>
          <sum type="sha">86e94a35e9cfbc4b6f0c39b1fbbd393806c813bb</sum>
        </package>
        <package arch="all" name="gitk" version="1:2.20.1-2+deb10u9+tuxcare.els4">
          <filename>gitk_2.20.1-2+deb10u9+tuxcare.els4_all.deb</filename>
          <sum type="sha">04a7de4fdbffffefc133715fd8383ce4fe2962e0</sum>
        </package>
        <package arch="all" name="gitweb" version="1:2.20.1-2+deb10u9+tuxcare.els4">
          <filename>gitweb_2.20.1-2+deb10u9+tuxcare.els4_all.deb</filename>
          <sum type="sha">d46f0a0bb5e2bacc65d9221d6c45e27b46a72c22</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1788163557</id>
    <title>Fix CVE(s): CVE-2026-14669</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Heap buffer overflow in to_char(timestamptz):
     DCH_to_char() copies the timezone abbreviation into a
     DCH_MAX_ITEM_SIZ-budgeted workspace with an unchecked strcpy(), and
     any client can select a longer POSIX abbreviation via SET TIME ZONE
     (CVSS 8.8, arbitrary code execution as the database OS user)
     - debian/patches/CVE-2026-14669.patch: Reject POSIX timezone
       abbreviations that would overflow the TZ/tz item budget in
       DCH_to_char() with an error instead of strcpy()ing them past the
       palloc'd buffer (upstream commit 12a620686, shipped in 14.24 via
       the REL_14_STABLE carrier 5fb3c63; applies verbatim)
     - CVE-2026-14669</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Heap buffer overflow in to_char(timestamptz):
     DCH_to_char() copies the timezone abbreviation into a
     DCH_MAX_ITEM_SIZ-budgeted workspace with an unchecked strcpy(), and
     any client can select a longer POSIX abbreviation via SET TIME ZONE
     (CVSS 8.8, arbitrary code execution as the database OS user)
     - debian/patches/CVE-2026-14669.patch: Reject POSIX timezone
       abbreviations that would overflow the TZ/tz item budget in
       DCH_to_char() with an error instead of strcpy()ing them past the
       palloc'd buffer (upstream commit 12a620686, shipped in 14.24 via
       the REL_14_STABLE carrier 5fb3c63; applies verbatim)
     - CVE-2026-14669</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-31 08:06:08 UTC" />
    <updated date="2026-08-31 08:06:08 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1788163557.html" id="CLSA-2026:1788163557" title="CLSA-2026:1788163557" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-14669" id="CVE-2026-14669" title="CVE-2026-14669" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libecpg-compat3-9.6" version="9.6.24-0+deb10u1+tuxcare.els4">
          <filename>libecpg-compat3-9.6_9.6.24-0+deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">365f29c0ed453fcbb36ac1d9a40bbbc7f462cb10</sum>
        </package>
        <package arch="amd64" name="libecpg-dev-9.6" version="9.6.24-0+deb10u1+tuxcare.els4">
          <filename>libecpg-dev-9.6_9.6.24-0+deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">75597011cb17e9f024adf24761716a2d11b0e94a</sum>
        </package>
        <package arch="amd64" name="libecpg6-9.6" version="9.6.24-0+deb10u1+tuxcare.els4">
          <filename>libecpg6-9.6_9.6.24-0+deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">c04ac32b35cac08ca1f12fdfdfc6f918465d60a7</sum>
        </package>
        <package arch="amd64" name="libpgtypes3-9.6" version="9.6.24-0+deb10u1+tuxcare.els4">
          <filename>libpgtypes3-9.6_9.6.24-0+deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">ba6b7cac507be144450b7c10ee350f259b534a4d</sum>
        </package>
        <package arch="amd64" name="libpq-dev-9.6" version="9.6.24-0+deb10u1+tuxcare.els4">
          <filename>libpq-dev-9.6_9.6.24-0+deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">11209ecdae47fa03ae2dae59dfd6129d8c44e755</sum>
        </package>
        <package arch="amd64" name="libpq5-9.6" version="9.6.24-0+deb10u1+tuxcare.els4">
          <filename>libpq5-9.6_9.6.24-0+deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">e28c6181a70d955cc9fb4926e19d71bbced73fc3</sum>
        </package>
        <package arch="amd64" name="postgresql-9.6" version="9.6.24-0+deb10u1+tuxcare.els4">
          <filename>postgresql-9.6_9.6.24-0+deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">f28abffb903efcc11f749e5cef8f861b488de13b</sum>
        </package>
        <package arch="amd64" name="postgresql-client-9.6" version="9.6.24-0+deb10u1+tuxcare.els4">
          <filename>postgresql-client-9.6_9.6.24-0+deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">c7ed464a01cc40ef0896d037aa64bc8cff1df584</sum>
        </package>
        <package arch="amd64" name="postgresql-contrib-9.6" version="9.6.24-0+deb10u1+tuxcare.els4">
          <filename>postgresql-contrib-9.6_9.6.24-0+deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">21bb5c7fc34ef42d05885dd3a413514ef2ee50d2</sum>
        </package>
        <package arch="all" name="postgresql-doc-9.6" version="9.6.24-0+deb10u1+tuxcare.els4">
          <filename>postgresql-doc-9.6_9.6.24-0+deb10u1+tuxcare.els4_all.deb</filename>
          <sum type="sha">ea210ef8f0f938f71a0d8738aaf251be10a04b7f</sum>
        </package>
        <package arch="amd64" name="postgresql-plperl-9.6" version="9.6.24-0+deb10u1+tuxcare.els4">
          <filename>postgresql-plperl-9.6_9.6.24-0+deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">714a5edd3f8f07d758b19f558bd7b3989d425772</sum>
        </package>
        <package arch="amd64" name="postgresql-plpython-9.6" version="9.6.24-0+deb10u1+tuxcare.els4">
          <filename>postgresql-plpython-9.6_9.6.24-0+deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">f27479829fe01bce7cafa9fd10526203aa20ef07</sum>
        </package>
        <package arch="amd64" name="postgresql-plpython3-9.6" version="9.6.24-0+deb10u1+tuxcare.els4">
          <filename>postgresql-plpython3-9.6_9.6.24-0+deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">7b3fb7a874a5b2fe1f4ff7279f86ac75f6ec8e19</sum>
        </package>
        <package arch="amd64" name="postgresql-pltcl-9.6" version="9.6.24-0+deb10u1+tuxcare.els4">
          <filename>postgresql-pltcl-9.6_9.6.24-0+deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">24f85f815aba0e4c81ddc1306016383659824db0</sum>
        </package>
        <package arch="amd64" name="postgresql-server-dev-9.6" version="9.6.24-0+deb10u1+tuxcare.els4">
          <filename>postgresql-server-dev-9.6_9.6.24-0+deb10u1+tuxcare.els4_amd64.deb</filename>
          <sum type="sha">0eeb55224af1b447ef659e669d9d6c334e3fa2f6</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1788171117</id>
    <title>Fix CVE(s): CVE-2026-73072, CVE-2026-73076, CVE-2026-73078</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Heap buffer overflow in set_sofo() in src/spellfile.c: a crafted spell file with an SN_SAL section before an SN_SOFO section leaves sl_sal_first[] entries at -1, so the counting loop under-counts multi-byte mapping lists and later writes run past the end of an undersized heap allocation
     - debian/patches/CVE-2026-73072.patch: reset sl_sal_first[] with vim_memset() at the top of the SN_SOFO counting loop in set_sofo(), as done upstream in patch 9.2.0846, so entries left at -1 by a preceding set_sal_first() can no longer skew the item counts
     - CVE-2026-73072
   * SECURITY UPDATE: Code execution via a crafted vimball archive: a member named .VimballRecord overwrites the un-vimball bookkeeping file with attacker-chosen Ex commands that are later :executed verbatim by vimball#RmVimball(), allowing arbitrary OS command execution through :!
     - debian/patches/CVE-2026-73076.patch: forbid extracting a vimball member named .VimballRecord, record file deletions with string() quoting, and make vimball#RmVimball() execute only whitelisted call delete('...') entries instead of the whole record line (upstream patch 9.2.0847 adapted to vimball v37)
     - CVE-2026-73076
   * SECURITY UPDATE: Code injection in netrw bookmark, history and target menus: paths are interpolated into :execute'd :menu commands escaped with g:netrw_menu_escape, which lacks the Ex separator '|', so a crafted directory path breaks out of the :menu command and runs arbitrary Ex/shell commands
     - debian/patches/CVE-2026-73078.patch: add '|' to g:netrw_menu_escape, escape the :e menu targets with escape(fnameescape(...),'|') in s:NetrwBookmarkMenu(), and quote the netrw#MakeTgt() arguments with string() in s:NetrwTgtMenu() (upstream patch 9.2.0840 adapted to netrw v156)
     - CVE-2026-73078</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Heap buffer overflow in set_sofo() in src/spellfile.c: a crafted spell file with an SN_SAL section before an SN_SOFO section leaves sl_sal_first[] entries at -1, so the counting loop under-counts multi-byte mapping lists and later writes run past the end of an undersized heap allocation
     - debian/patches/CVE-2026-73072.patch: reset sl_sal_first[] with vim_memset() at the top of the SN_SOFO counting loop in set_sofo(), as done upstream in patch 9.2.0846, so entries left at -1 by a preceding set_sal_first() can no longer skew the item counts
     - CVE-2026-73072
   * SECURITY UPDATE: Code execution via a crafted vimball archive: a member named .VimballRecord overwrites the un-vimball bookkeeping file with attacker-chosen Ex commands that are later :executed verbatim by vimball#RmVimball(), allowing arbitrary OS command execution through :!
     - debian/patches/CVE-2026-73076.patch: forbid extracting a vimball member named .VimballRecord, record file deletions with string() quoting, and make vimball#RmVimball() execute only whitelisted call delete('...') entries instead of the whole record line (upstream patch 9.2.0847 adapted to vimball v37)
     - CVE-2026-73076
   * SECURITY UPDATE: Code injection in netrw bookmark, history and target menus: paths are interpolated into :execute'd :menu commands escaped with g:netrw_menu_escape, which lacks the Ex separator '|', so a crafted directory path breaks out of the :menu command and runs arbitrary Ex/shell commands
     - debian/patches/CVE-2026-73078.patch: add '|' to g:netrw_menu_escape, escape the :e menu targets with escape(fnameescape(...),'|') in s:NetrwBookmarkMenu(), and quote the netrw#MakeTgt() arguments with string() in s:NetrwTgtMenu() (upstream patch 9.2.0840 adapted to netrw v156)
     - CVE-2026-73078</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-31 10:12:09 UTC" />
    <updated date="2026-08-31 10:12:09 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1788171117.html" id="CLSA-2026:1788171117" title="CLSA-2026:1788171117" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-73072" id="CVE-2026-73072" title="CVE-2026-73072" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-73076" id="CVE-2026-73076" title="CVE-2026-73076" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-73078" id="CVE-2026-73078" title="CVE-2026-73078" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="vim" version="2:8.1.0875-5+deb10u6+tuxcare.els27">
          <filename>vim_8.1.0875-5+deb10u6+tuxcare.els27_amd64.deb</filename>
          <sum type="sha">267597af0e98d7ada0a35dc86560a9bc0039dc94</sum>
        </package>
        <package arch="amd64" name="vim-athena" version="2:8.1.0875-5+deb10u6+tuxcare.els27">
          <filename>vim-athena_8.1.0875-5+deb10u6+tuxcare.els27_amd64.deb</filename>
          <sum type="sha">474a45eb0ba71b0a266dc305a7356f05dd3fab89</sum>
        </package>
        <package arch="all" name="vim-common" version="2:8.1.0875-5+deb10u6+tuxcare.els27">
          <filename>vim-common_8.1.0875-5+deb10u6+tuxcare.els27_all.deb</filename>
          <sum type="sha">f0db7b011fcbc6d174fc611347a4838151ba9306</sum>
        </package>
        <package arch="all" name="vim-doc" version="2:8.1.0875-5+deb10u6+tuxcare.els27">
          <filename>vim-doc_8.1.0875-5+deb10u6+tuxcare.els27_all.deb</filename>
          <sum type="sha">ef73266a8df6f37e792c0c0bb2fa616074d2ad7d</sum>
        </package>
        <package arch="amd64" name="vim-gtk" version="2:8.1.0875-5+deb10u6+tuxcare.els27">
          <filename>vim-gtk_8.1.0875-5+deb10u6+tuxcare.els27_amd64.deb</filename>
          <sum type="sha">accba39a329fc51d473b3a7f188f543227a23a2b</sum>
        </package>
        <package arch="amd64" name="vim-gtk3" version="2:8.1.0875-5+deb10u6+tuxcare.els27">
          <filename>vim-gtk3_8.1.0875-5+deb10u6+tuxcare.els27_amd64.deb</filename>
          <sum type="sha">a3cfbe035f71db7e50dce5aa6ca6043f5e152923</sum>
        </package>
        <package arch="all" name="vim-gui-common" version="2:8.1.0875-5+deb10u6+tuxcare.els27">
          <filename>vim-gui-common_8.1.0875-5+deb10u6+tuxcare.els27_all.deb</filename>
          <sum type="sha">fea76a0714bfe0af6c216cccafed5d85d4d9d343</sum>
        </package>
        <package arch="amd64" name="vim-nox" version="2:8.1.0875-5+deb10u6+tuxcare.els27">
          <filename>vim-nox_8.1.0875-5+deb10u6+tuxcare.els27_amd64.deb</filename>
          <sum type="sha">2ff52abd32e928321277833858f97e0f89d2db14</sum>
        </package>
        <package arch="all" name="vim-runtime" version="2:8.1.0875-5+deb10u6+tuxcare.els27">
          <filename>vim-runtime_8.1.0875-5+deb10u6+tuxcare.els27_all.deb</filename>
          <sum type="sha">48bdfd5838a020bf9f6daa91ea7e74abfb75d5e2</sum>
        </package>
        <package arch="amd64" name="vim-tiny" version="2:8.1.0875-5+deb10u6+tuxcare.els27">
          <filename>vim-tiny_8.1.0875-5+deb10u6+tuxcare.els27_amd64.deb</filename>
          <sum type="sha">d00000b9fe3fe8a6c2e1a5c7b59bc85912a607d6</sum>
        </package>
        <package arch="amd64" name="xxd" version="2:8.1.0875-5+deb10u6+tuxcare.els27">
          <filename>xxd_8.1.0875-5+deb10u6+tuxcare.els27_amd64.deb</filename>
          <sum type="sha">b2eda3e23c8dd103473a7cfda8a8be8257f9e87a</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1788193166</id>
    <title>Fix CVE(s): CVE-2026-6475</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: Path traversal in pg_rewind: file, directory and
     symlink paths received from the source server over libpq were acted on
     without validation, so a rogue origin could make pg_rewind write,
     truncate or unlink files outside the target data directory
     - debian/patches/CVE-2026-6475.patch: Add path_is_safe_for_extraction()
       in src/port/path.c, which canonicalises a path and requires it to stay
       relative and below the current directory, and gate every pg_rewind
       target file/dir/symlink operation on it with pg_fatal() (upstream
       commit 498829dca4; the pg_basebackup astreamer half of that commit is
       v15+ and absent from 9.6)
     - CVE-2026-6475: path traversal in pg_rewind target file operations via
       unvalidated paths supplied by the source server</description>
    <severity>Moderate</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: Path traversal in pg_rewind: file, directory and
     symlink paths received from the source server over libpq were acted on
     without validation, so a rogue origin could make pg_rewind write,
     truncate or unlink files outside the target data directory
     - debian/patches/CVE-2026-6475.patch: Add path_is_safe_for_extraction()
       in src/port/path.c, which canonicalises a path and requires it to stay
       relative and below the current directory, and gate every pg_rewind
       target file/dir/symlink operation on it with pg_fatal() (upstream
       commit 498829dca4; the pg_basebackup astreamer half of that commit is
       v15+ and absent from 9.6)
     - CVE-2026-6475: path traversal in pg_rewind target file operations via
       unvalidated paths supplied by the source server</summary>
    <pushcount>0</pushcount>
    <issued date="2026-08-31 16:19:38 UTC" />
    <updated date="2026-08-31 16:19:38 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1788193166.html" id="CLSA-2026:1788193166" title="CLSA-2026:1788193166" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-6475" id="CVE-2026-6475" title="CVE-2026-6475" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libecpg-compat3-9.6" version="9.6.24-0+deb10u1+tuxcare.els5">
          <filename>libecpg-compat3-9.6_9.6.24-0+deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">185ae2310787c4a3092e6205faa814b2b039bc87</sum>
        </package>
        <package arch="amd64" name="libecpg-dev-9.6" version="9.6.24-0+deb10u1+tuxcare.els5">
          <filename>libecpg-dev-9.6_9.6.24-0+deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">c0f5151cdfd947f901bb6aac952a126ef6d2b472</sum>
        </package>
        <package arch="amd64" name="libecpg6-9.6" version="9.6.24-0+deb10u1+tuxcare.els5">
          <filename>libecpg6-9.6_9.6.24-0+deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">c99a744766c65e729f544cf68702a22ad0c25185</sum>
        </package>
        <package arch="amd64" name="libpgtypes3-9.6" version="9.6.24-0+deb10u1+tuxcare.els5">
          <filename>libpgtypes3-9.6_9.6.24-0+deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">29bb667effc75810f49a85eda826996eedc33e23</sum>
        </package>
        <package arch="amd64" name="libpq-dev-9.6" version="9.6.24-0+deb10u1+tuxcare.els5">
          <filename>libpq-dev-9.6_9.6.24-0+deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">fdc4de2e278f6d6b68e229f2a7fff6bd68edaedd</sum>
        </package>
        <package arch="amd64" name="libpq5-9.6" version="9.6.24-0+deb10u1+tuxcare.els5">
          <filename>libpq5-9.6_9.6.24-0+deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">73508bf72dec7e3a25433f5b0814a9509666b2b8</sum>
        </package>
        <package arch="amd64" name="postgresql-9.6" version="9.6.24-0+deb10u1+tuxcare.els5">
          <filename>postgresql-9.6_9.6.24-0+deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">98472f5f67a8c88f56a4287eb04f1e2c44ccf5d7</sum>
        </package>
        <package arch="amd64" name="postgresql-client-9.6" version="9.6.24-0+deb10u1+tuxcare.els5">
          <filename>postgresql-client-9.6_9.6.24-0+deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">8e5cec09409d2881ea2eea656ab680fedc0f7ffb</sum>
        </package>
        <package arch="amd64" name="postgresql-contrib-9.6" version="9.6.24-0+deb10u1+tuxcare.els5">
          <filename>postgresql-contrib-9.6_9.6.24-0+deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">c6492e8c1839893839fe7848fd5eec7185105c55</sum>
        </package>
        <package arch="all" name="postgresql-doc-9.6" version="9.6.24-0+deb10u1+tuxcare.els5">
          <filename>postgresql-doc-9.6_9.6.24-0+deb10u1+tuxcare.els5_all.deb</filename>
          <sum type="sha">225fbbe1bfedf09ef74aaf7c02bd965015a939ce</sum>
        </package>
        <package arch="amd64" name="postgresql-plperl-9.6" version="9.6.24-0+deb10u1+tuxcare.els5">
          <filename>postgresql-plperl-9.6_9.6.24-0+deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">c108e57ce362bed6857de88c5860283728bbdcff</sum>
        </package>
        <package arch="amd64" name="postgresql-plpython-9.6" version="9.6.24-0+deb10u1+tuxcare.els5">
          <filename>postgresql-plpython-9.6_9.6.24-0+deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">f92dd6df4245c4d70b4d6e67ef27cea951bb0f21</sum>
        </package>
        <package arch="amd64" name="postgresql-plpython3-9.6" version="9.6.24-0+deb10u1+tuxcare.els5">
          <filename>postgresql-plpython3-9.6_9.6.24-0+deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">a6e71d605c365b57d5f0c0b1328e5ac5bd367e12</sum>
        </package>
        <package arch="amd64" name="postgresql-pltcl-9.6" version="9.6.24-0+deb10u1+tuxcare.els5">
          <filename>postgresql-pltcl-9.6_9.6.24-0+deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">8d3f9c6ec96c4d33b9bdc4f37ce19a6c7b23a306</sum>
        </package>
        <package arch="amd64" name="postgresql-server-dev-9.6" version="9.6.24-0+deb10u1+tuxcare.els5">
          <filename>postgresql-server-dev-9.6_9.6.24-0+deb10u1+tuxcare.els5_amd64.deb</filename>
          <sum type="sha">d4ffe51b94c0bbc782151a313ae2e8d7065f7676</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1788262732</id>
    <title>Fix CVE(s): CVE-2026-19654</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: denial of service in the optional imptcp module: a regex match at offset zero after oversize-frame recovery submits a negative message length and crashes rsyslogd
     - debian/patches/CVE-2026-19654.patch: denial of service in the optional imptcp module: a regex match at offset zero after oversize-frame recovery submits a negative message length and crashes rsyslogd
     - CVE-2026-19654
   * debian/patches/Skip-tests-that-cannot-run-in-the-build-environment.patch:
     skip omfile-read-only, omfile-read-only-errmsg, privdropuser and
     privdropuserid. All four fail in the pdebuild chroot for reasons
     unrelated to rsyslog (root bypasses the 0400 mode the first two rely
     on; the chroot has no unprivileged test user for the last two), and
     they fail identically on the unpatched vendor sources.</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: denial of service in the optional imptcp module: a regex match at offset zero after oversize-frame recovery submits a negative message length and crashes rsyslogd
     - debian/patches/CVE-2026-19654.patch: denial of service in the optional imptcp module: a regex match at offset zero after oversize-frame recovery submits a negative message length and crashes rsyslogd
     - CVE-2026-19654
   * debian/patches/Skip-tests-that-cannot-run-in-the-build-environment.patch:
     skip omfile-read-only, omfile-read-only-errmsg, privdropuser and
     privdropuserid. All four fail in the pdebuild chroot for reasons
     unrelated to rsyslog (root bypasses the 0400 mode the first two rely
     on; the chroot has no unprivileged test user for the last two), and
     they fail identically on the unpatched vendor sources.</summary>
    <pushcount>0</pushcount>
    <issued date="2026-09-01 11:39:02 UTC" />
    <updated date="2026-09-01 11:39:02 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1788262732.html" id="CLSA-2026:1788262732" title="CLSA-2026:1788262732" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-19654" id="CVE-2026-19654" title="CVE-2026-19654" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="rsyslog" version="8.1901.0-1+deb10u2+tuxcare.els1">
          <filename>rsyslog_8.1901.0-1+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">71173699bdc01937849908dd719dd2865a3c4832</sum>
        </package>
        <package arch="amd64" name="rsyslog-czmq" version="8.1901.0-1+deb10u2+tuxcare.els1">
          <filename>rsyslog-czmq_8.1901.0-1+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">1b2c578ab43af702c51bdaa40949025763c0a29c</sum>
        </package>
        <package arch="amd64" name="rsyslog-elasticsearch" version="8.1901.0-1+deb10u2+tuxcare.els1">
          <filename>rsyslog-elasticsearch_8.1901.0-1+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">cf85135ab9cf92e3795c8a5b25da2ee0c89ac8c5</sum>
        </package>
        <package arch="amd64" name="rsyslog-gnutls" version="8.1901.0-1+deb10u2+tuxcare.els1">
          <filename>rsyslog-gnutls_8.1901.0-1+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">52368389dac12b497b79d6bee3c22c53819f30ce</sum>
        </package>
        <package arch="amd64" name="rsyslog-gssapi" version="8.1901.0-1+deb10u2+tuxcare.els1">
          <filename>rsyslog-gssapi_8.1901.0-1+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">ced28ef5f2e01bc45c216d3edc50a52f952c533d</sum>
        </package>
        <package arch="amd64" name="rsyslog-hiredis" version="8.1901.0-1+deb10u2+tuxcare.els1">
          <filename>rsyslog-hiredis_8.1901.0-1+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">408b996ffe4b70e6056127f80d31adb6c9703a99</sum>
        </package>
        <package arch="amd64" name="rsyslog-kafka" version="8.1901.0-1+deb10u2+tuxcare.els1">
          <filename>rsyslog-kafka_8.1901.0-1+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">092361690a609f95a06970354c4b437f7e9295e8</sum>
        </package>
        <package arch="amd64" name="rsyslog-mongodb" version="8.1901.0-1+deb10u2+tuxcare.els1">
          <filename>rsyslog-mongodb_8.1901.0-1+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">288a184b72f2030a0a6adcd9408b6d8453498943</sum>
        </package>
        <package arch="amd64" name="rsyslog-mysql" version="8.1901.0-1+deb10u2+tuxcare.els1">
          <filename>rsyslog-mysql_8.1901.0-1+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">8d279ed2c46d9e491dfbf1f4149af5ca2403394b</sum>
        </package>
        <package arch="amd64" name="rsyslog-pgsql" version="8.1901.0-1+deb10u2+tuxcare.els1">
          <filename>rsyslog-pgsql_8.1901.0-1+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">ba01d9cdaa9d9d7fdde3648bcf399dd98139db52</sum>
        </package>
        <package arch="amd64" name="rsyslog-relp" version="8.1901.0-1+deb10u2+tuxcare.els1">
          <filename>rsyslog-relp_8.1901.0-1+deb10u2+tuxcare.els1_amd64.deb</filename>
          <sum type="sha">7df1dd22e45526eb317dd76dbbd1aa02f01a9a7e</sum>
        </package>
      </collection>
    </pkglist>
  </update>
<update from="packager@tuxcare.com" status="final" type="security" version="1">
    <id>CLSA-2026:1788264910</id>
    <title>Fix CVE(s): CVE-2026-54874, CVE-2026-63072</title>
    <rights>TuxCare License Agreement</rights>
    <release>0</release>
    <description>   * SECURITY UPDATE: avoid buffering the whole DTLS read buffer for a record arriving early for the next epoch (ssl/record/rec_layer_d1.c)
     - debian/patches/CVE-2026-54874.patch: avoid buffering the whole DTLS read buffer for a record arriving early for the next epoch (ssl/record/rec_layer_d1.c)
     - CVE-2026-54874
   * SECURITY UPDATE: fix 8-byte out-of-bounds heap write in CMS AES-WRAP-PAD key unwrapping (crypto/cms/cms_kari.c)
     - debian/patches/CVE-2026-63072.patch: fix 8-byte out-of-bounds heap write in CMS AES-WRAP-PAD key unwrapping (crypto/cms/cms_kari.c)
     - debian/patches/CVE-2026-63072-test.patch: add the upstream regression test for the AES-WRAP-PAD unwrap overflow (test/cmsapitest.c)
     - CVE-2026-63072</description>
    <severity>Important</severity>
    <solution>Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the CLN.</solution>
    <summary>   * SECURITY UPDATE: avoid buffering the whole DTLS read buffer for a record arriving early for the next epoch (ssl/record/rec_layer_d1.c)
     - debian/patches/CVE-2026-54874.patch: avoid buffering the whole DTLS read buffer for a record arriving early for the next epoch (ssl/record/rec_layer_d1.c)
     - CVE-2026-54874
   * SECURITY UPDATE: fix 8-byte out-of-bounds heap write in CMS AES-WRAP-PAD key unwrapping (crypto/cms/cms_kari.c)
     - debian/patches/CVE-2026-63072.patch: fix 8-byte out-of-bounds heap write in CMS AES-WRAP-PAD key unwrapping (crypto/cms/cms_kari.c)
     - debian/patches/CVE-2026-63072-test.patch: add the upstream regression test for the AES-WRAP-PAD unwrap overflow (test/cmsapitest.c)
     - CVE-2026-63072</summary>
    <pushcount>0</pushcount>
    <issued date="2026-09-01 12:15:22 UTC" />
    <updated date="2026-09-01 12:15:22 UTC" />
    <references>
      <reference href="https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1788264910.html" id="CLSA-2026:1788264910" title="CLSA-2026:1788264910" type="self" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-54874" id="CVE-2026-54874" title="CVE-2026-54874" type="cve" />
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-63072" id="CVE-2026-63072" title="CVE-2026-63072" type="cve" />
    </references>
    <pkglist>
      <collection>
        <name>tuxcare-debian10-els</name>
        <package arch="amd64" name="libssl-dev" version="1.1.1n-0+deb10u6+tuxcare.els6">
          <filename>libssl-dev_1.1.1n-0+deb10u6+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">70911e54bc17e486a9d902993ef5826a0f7c6518</sum>
        </package>
        <package arch="all" name="libssl-doc" version="1.1.1n-0+deb10u6+tuxcare.els6">
          <filename>libssl-doc_1.1.1n-0+deb10u6+tuxcare.els6_all.deb</filename>
          <sum type="sha">ed5a1cbf386e0e87090b704cda69544df155443e</sum>
        </package>
        <package arch="amd64" name="libssl1.1" version="1.1.1n-0+deb10u6+tuxcare.els6">
          <filename>libssl1.1_1.1.1n-0+deb10u6+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">99f1ed5379032805d5b652bf991cc4aaf9b59c7e</sum>
        </package>
        <package arch="amd64" name="openssl" version="1.1.1n-0+deb10u6+tuxcare.els6">
          <filename>openssl_1.1.1n-0+deb10u6+tuxcare.els6_amd64.deb</filename>
          <sum type="sha">69ac0240f7ca2a0b8a2ef409cc6b09b36a7dfeb6</sum>
        </package>
      </collection>
    </pkglist>
  </update>
</updates>