- dpkg (1.20.13+rpi1) bullseye-staging; urgency=medium
++dpkg (1.20.14+rpi1) bullseye-staging; urgency=medium
+
+ [changes brought forward from 1.20.5+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Sun, 02 Aug 2020 12:08:02 +0000]
+ * Hack up Vendor.pm so it doesn't fail
+ (see https://lists.debian.org/debian-dpkg/2020/08/msg00004.html )
+ * disable testsuite.
+
- -- Raspbian forward porter <root@raspbian.org> Mon, 18 May 2026 20:50:49 +0000
++ -- Raspbian forward porter <root@raspbian.org> Thu, 09 Jul 2026 20:50:27 +0000
++
+ dpkg (1.20.14) bullseye-security; urgency=medium
+
+ [ Guillem Jover ]
+ * libdpkg: Handle tar long GNU names and links not being NUL terminated.
+ Closes: #1061404
+ * libdpkg: Do not segfault when adding triggers in no-act mode.
+ Closes: #1108192
+ * dpkg-deb: Fix cleanup for control member with restricted directories.
+ Reported by zhutyra on HackerOne. Fixes CVE-2025-6297.
+ * Perl modules:
+ - Dpkg::BuildDriver::DebianRules: Fix uninitialized Perl variables.
+ Closes: #1107971
+ - Dpkg::BuildDriver::DebianRules: Fix R³ dpkg/target/<target> values
+ handling.
+ * Localization:
+ - Fix typos in Swedish man pages translations. Closes: #1065575
+
+ -- Guillem Jover <guillem@debian.org> Mon, 06 Jul 2026 03:44:17 +0200
dpkg (1.20.13) bullseye; urgency=medium