u-boot (2021.01+dfsg-5+deb11u3) bullseye-security; urgency=high
* Non-maintainer upload by the LTS Team.
* CVE-2024-42040: buffer overread vulnerability in the DHCP implementation.
(Closes: #
1081557)
* CVE-2026-46728: mishandles use of unit addresses in a FIT.
(Closes: #
1136954)
* Remove avr32 arch support removed in dpkg 1.22.0 (Closes: #
1056750)
- now also leads to DAK rejecting the upload even for older suites.
[dgit import unpatched u-boot 2021.01+dfsg-5+deb11u3]