# July 2026 During this month, I have worked on the following tasks for Debian LTS and ELTS. Thanks to Freexian and sponsors for making this possible [0]. ## dnsmasq - Investigate CVE-2026-2291, CVE-2026-4890, CVE-2026-4891, CVE-2026-4892, CVE-2026-4893 and CVE-2026-5172 for ELTS * CVE-2026-5172 not-affected on buster & stretch, marked as such extract_addresses() lacks the vulnerable generic-RR/rrblock path * CVE-2026-4890 and CVE-2026-4891 not-affected on stretch, marked as such DNSSEC support was disabled in 2.76-5+deb9u5 - Cherry-pick and backport patches for the other 3-5 CVEs (from DLA-4625-1) * Fix autopkgtests and adopt tests/environment to buster and stretch * Getting the buster/stretch ELTS branches reviewed & fixed (thanks arnaudr!) * Final testing/validation/installability/migration of the ELTS packages * Published the corresponding ELA-1772-1 for buster/stretch: https://www.freexian.com/lts/extended/updates/ela-1772-1-dnsmasq/ ## Misc - Participated in the monthly LTS/ELTS team meeting. - Debian LTS team BoF at DebConf 2026 Cheers, Lukas [0] https://www.freexian.com/lts/debian/#sponsors