I've worked during August 2026 on the below listed packages, for Freexian LTS/ELTS Many thanks to Freexian and sponsors for providing this opportunity! LTS: === * libarchive: Prepared update for bullseye, bookworm (and stable in pipeline) fixing CVE-2026-14164 CVE-2026-15028 CVE-2026-16517. Released [DLA 4762-1]. Spotted a regression by previous upload (3.4.3-2+deb11u4) only after upload. Soon that will be fixed. * librabbitmq: Prepared update for bullseye and bookworm fixing CVE-2026-59986 CVE-2026-61547. Released [DLA 4763-1] * libvncserver: Prepared update for bullseye fixing CVE-2026-32853 CVE-2026-32854 CVE-2026-44988 CVE-2026-50538. Released [DLA 4755-1] * ruby-grape: Fixed a regression caused by an earlier upload of a ruby-rack and released [DLA 4706-2] Continuing from previous month(s); * calibre: Fixed a regression cause by an earlier upload in bookworm. Maintainer provided patches and PoC. Also piggybacked a CVE fix. Released [DLA 4744-1]. * xrdp: Send an update for stable security to Sec team which uploaded and released [DSA 6469-1]. For bullseye and bookworm, all the patches backported in previous months except the CVE-2026-33145 and CVE-2026-32107. CVE-2026-32107 backported but CVE-2026-33145 marked as ignored due to backporting difficulties. More info in commit [ac1208da] Released [DLA 4759-1] for bullseye and bookworm * ruby-rack: Prepared update for trixie and send to sec team for review. ELTS: ==== This month I couldn't work on any packages for ELTS. -- [ac1208da]-https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac1208daac40b7aafda565d13360dc87316945ac