New Debian libcap2 1:2.66-4+deb12u1 fixes: This update addresses the following issue: 1:2.66-4+deb12u1 (Sat, 15 Mar 2025 13:43:35 +0100) * Cherry-pick patch fixing CVE-2025-1390. In /etc/security/capability.conf, configurations not starting with "@" were incorrectly recognized as group names.
--- mirror/ftp/pool/main/libc/libcap2/libcap2_2.66-4.dsc +++ apt/ucs_5.2-0-errata5.2-1/source/libcap2_2.66-4+deb12u1.dsc @@ -1,3 +1,9 @@ +1:2.66-4+deb12u1 [Sat, 15 Mar 2025 13:43:35 +0100] Christian Kastner <ckk@debian.org>: + + * Cherry-pick patch fixing CVE-2025-1390. + In /etc/security/capability.conf, configurations not starting with "@" + were incorrectly recognized as group names. (Closes: #1098318) + 1:2.66-4 [Mon, 15 May 2023 20:34:57 +0200] Christian Kastner <ckk@debian.org>: * Apply upstream patches for CVE-2023-2602, CVE-2023-2603 <http://piuparts.knut.univention.de/5.2-1/#1214838067443536657>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.2-1] 785de8368a Bug #58296: libcap2 1:2.66-4+deb12u1 doc/errata/staging/libcap2.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.2x95>