Update changelog
authorSimon McVittie <smcv@debian.org>
Mon, 10 Aug 2026 10:19:29 +0000 (11:19 +0100)
committerSimon McVittie <smcv@debian.org>
Mon, 10 Aug 2026 10:19:29 +0000 (11:19 +0100)
debian/changelog

index 13cc1b8e4bb94ab155a178c3e4b64f9e5308ea92..bfe92558552afa8fab6ca8f3edc282bae374bf6e 100644 (file)
@@ -1,10 +1,12 @@
 ostree (2026.3-1) UNRELEASED; urgency=medium
 
   * New upstream release
-    - Prevent heap buffer overflow on 32-bit systems
-      (RHEL-189207, no known CVE)
-    - Set memory limits for LZMA decoding to prevent resource exhaustion
-      (RHEL-189208, no known CVE)
+    - Prevent heap buffer overflow on 32-bit systems if downloading from an
+      attacker-controlled OSTree repository
+      (GHSA-xppc-j946-vcj7, RHEL-189207, no known CVE)
+    - Set memory limits for LZMA decoding to prevent resource exhaustion if
+      downloading from an attacker-controlled OSTree repository
+      (GHSA-7cgc-gp99-6jmm, RHEL-189208, no known CVE)
 
  -- Simon McVittie <smcv@debian.org>  Mon, 10 Aug 2026 11:09:00 +0100