[Pkg-roundcube-maintainers] Bug#1146838: planned updates for bookworm and trixie?

Guilhem Moulin guilhem at debian.org
Tue Sep 29 15:06:42 BST 2026


On Tue, 29 Sep 2026 at 13:24:48 +0000, Björn Wiggert (wiggert.it) wrote:
> Does this mean that all Roundcube installations using the currently
> available Debian 12 and Debian 13 packages are currently vulnerable to
> at least some of the issues fixed in Roundcube 1.6.19?

Yes.

> And is my understanding correct that the updates for bookworm and
> trixie have effectively been held back while waiting for CVE IDs to be
> assigned?

Yes.

> I am asking because this would mean that known security issues remain
> unfixed in the supported Debian packages for the time being, even
> though upstream fixes are already available.
>
> Is waiting for CVE assignment before publishing such updates normal
> Debian security practice in this situation, or is this an exceptional
> case?

Ideally each upstream project would have an embargoed process with its
downstreams and request CVE IDs themselves (in coordinations with the
reporters).  This is not the case here.
https://github.com/roundcube/roundcubemail/issues/10123

-- 
Guilhem.



More information about the Pkg-roundcube-maintainers mailing list