[From nobody Sun Aug 16 13:03:08 2026
Received: (at 1144498-done) by bugs.debian.org; 16 Aug 2026 12:00:08 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-110.5 required=4.0 tests=ALL_TRUSTED,BAYES_00,
 DKIMWL_WL_HIGH,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,
 FROMDEVELOPER,HAS_BUG_NUMBER,SPF_HELO_NONE,SPF_PASS,
 USER_IN_DKIM_WELCOMELIST autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 17; hammy, 112; neutral, 34; spammy,
 1. spammytokens:0.921-+--offer
 hammytokens:0.000-+--Hx-spam-relays-external:sk:stravin,
 0.000-+--H*RT:sk:stravin, 0.000-+--Hx-spam-relays-external:311,
 0.000-+--H*RT:311, 0.000-+--H*RT:108
Return-path: &lt;zeha@debian.org&gt;
Received: from stravinsky.debian.org ([2001:41b8:202:deb::311:108]:59150)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;zeha@debian.org&gt;) id 1wvZX6-009lBn-2p
 for 1144498-done@bugs.debian.org; Sun, 16 Aug 2026 12:00:08 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; 
 s=smtpauto.stravinsky;
 h=X-Debian-User:In-Reply-To:Content-Type:MIME-Version:
 References:Message-ID:Subject:To:From:Date:Reply-To:Cc:
 Content-Transfer-Encoding:Content-ID:Content-Description;
 bh=o68kvaPxHJFzOld0a8/AKSBCPHa8kpY7ipnilF6cUK8=; b=pBHGqObOiWO/RTC+7Ox28uVdCD
 pTPuCz89xqa1uSRIsHUtKlCfs3bClDUEqfjcj/bhVRl1uCYEcfzdGsjcjYPqe28auhT+NcGp1hFlZ
 Iaf9fvQ4E9WlfOwZaKsBTlGReK/Wssv5h//+IWLvXI/lZNns4r6zMQ+ge25jte+xsU17h4T0qHap/
 P+x55AqTSwqxKhP6PbOzckFWcDcyiqMVK4OtblEiO+cezxvfiF+IrgLlrAGZ4BixjMJRKyzVzAQiQ
 wn9Qw4FUqQ+162e8RIEZrA5MzrZP3mFBup/bpVNSWY476yojE9aBCzBdJ+s+A2hXJYstwZ1ls86iT
 vIPLRlmw==;
Received: from authenticated-user by stravinsky.debian.org with esmtpsa
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;zeha@debian.org&gt;) id 1wvZX4-007R4o-2g;
 Sun, 16 Aug 2026 12:00:06 +0000
Date: Sun, 16 Aug 2026 14:00:05 +0200
From: Chris Hofstaedtler &lt;zeha@debian.org&gt;
To: &quot;Mohammad, Ejas Ali&quot; &lt;ejas.ali.mohammad@accenture.com&gt;,
 1144498-done@bugs.debian.org
Subject: Re: Bug#1144498: perl: 8 unpatched security CVEs - request fix for
 trixie
Message-ID: &lt;aoGmRTfRcF-6FSR5@per.namespace.at&gt;
References: &lt;PH8P114MB220533421DDA5CAD5C6B0716BED82@PH8P114MB2205.NAMP114.PROD.OUTLOOK.COM&gt;
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
In-Reply-To: &lt;PH8P114MB220533421DDA5CAD5C6B0716BED82@PH8P114MB2205.NAMP114.PROD.OUTLOOK.COM&gt;
X-Debian-User: zeha

On Sun, Aug 16, 2026 at 07:33:45AM +0000, Mohammad, Ejas Ali wrote:
&gt; Package: perl
&gt; Version: 5.40.1-6
&gt; Severity: Critical &amp; High
&gt; 
&gt; Hi Debian Security Team,
&gt; 
&gt; The following CVEs are reported against the perl source package in Trixie and have no fix available at time of filing.

There are already bugs filed for these CVEs, and as you say they are 
tracked in the security tracker.

There is no need for an additional bug to keep track of the work. Closing this one.

I assume this was not an offer of a tested package that is ready for 
trixie-security?

Best,
Chris]