Merge version 4:25.2.3-2+rpi1+deb13u3 and 4:25.2.3-2+deb13u5 to produce 4:25.2.3... archive/raspbian/4%25.2.3-2+rpi1+deb13u5 raspbian/4%25.2.3-2+rpi1+deb13u5
authorRaspbian automatic forward porter <root@raspbian.org>
Fri, 19 Jun 2026 08:49:26 +0000 (09:49 +0100)
committerRaspbian automatic forward porter <root@raspbian.org>
Fri, 19 Jun 2026 08:49:26 +0000 (09:49 +0100)
1  2 
debian/changelog

index e4f63fc7870a11005e289f887a9a226540c97de7,3368e55f63c1dcac67c9a4b14a5df266a84bc972..93ef13510ff324ef1359309f4ed1e33b0ec53287
@@@ -1,19 -1,24 +1,41 @@@
- libreoffice (4:25.2.3-2+rpi1+deb13u3) trixie-staging; urgency=medium
++libreoffice (4:25.2.3-2+rpi1+deb13u5) trixie-staging; urgency=medium
 +
 +  [changes brought forward from 1:6.0.2-1+rpi2 by Peter Michael Green <plugwash@raspbian.org> at Fri, 27 Apr 2018 02:14:18 +0000]
 +  * Disable testsuite.
 +
 +  [changes introduced in 1:5.4.0-1+rpi1 by Peter Michael Green]
 +  * Disable pdfium, it fails to build for armv6
 +
 +  [changes introduced in 1:7.2.4-3+rpi1 by Peter Michael Green]
 +  * Use clang 11, newer versions cause armv7 contamination issues.
 +
 +  [changes introduced in 4:24.2.5-1+rpi1 by Peter Michael Green]
 +  * Build with gcc rather than clang.
 +  * Disable skia.
 +
-  -- Raspbian forward porter <root@raspbian.org>  Mon, 12 Jan 2026 01:11:21 +0000
++ -- Raspbian forward porter <root@raspbian.org>  Fri, 19 Jun 2026 08:49:23 +0000
++
+ libreoffice (4:25.2.3-2+deb13u5) trixie-security; urgency=medium
+   * debian/patches/CVE-2026-*.diff: fix
+     - CVE-2026-6039 DXF heap-buffer-overflow in DrawLWPolyLineEntity
+     - CVE-2026-6040 ODT use-after-free in lcl_InsertBlankWidthChars
+     - CVE-2026-6045 EMF+ Heap-buffer-overflow in EMFPBrush::Read
+     - CVE-2026-8356 ANT-2026-01882: Stack Buffer Overflow in
+       `SdrEscherImport::RecolorGraphic()`
+     - CVE-2026-8357 ANT-2026-03093: Off-by-one heap-buffer-overflow in
+       LibreOffice Calc formula compiler
+     - CVE-2026-8358 ANT-2026-03238: Heap-buffer-overflow in LibreOffice
+       Calc FODS tracked-changes importer via duplicate action ID
+  -- Rene Engelhard <rene@debian.org>  Mon, 25 May 2026 13:04:39 +0200
+ libreoffice (4:25.2.3-2+deb13u4) trixie-security; urgency=medium
+   * debian/patches/Conform-AlignEngine-parsing-to-spec.diff: as name says;
+     from libreoffice-26-2 branch; fixes CVE-2026-4430
+  -- Rene Engelhard <rene@debian.org>  Thu, 19 Mar 2026 21:20:19 +0100
  
  libreoffice (4:25.2.3-2+deb13u3) trixie; urgency=medium