Skip to content

Prepare stable update for libsub-handlesvia-perl

This package has one open CVE that is not-affected in bullseye, but unfixed in more recent releases.

In this case, the remaining open CVEs have been triaged as <no-dsa> by the security team, so they have no immediate plans to deal with them.

Please coordinate with the maintainer and SRM to have an updated package included in the next point release (for CVEs affecting bookworm). https://www.debian.org/doc/manuals/developers-reference/pkgs.html#special-case-uploads-to-the-stable-and-oldstable-distributions

Additionally, please keep the security team informed concerning this matter by mailing team@security.debian.org with a brief summary once a course of action has been agreed upon between yourself, the maintainer, and SRM (as applicable).

Package: libsub-handlesvia-perl
CVE(s): CVE-2025-30673
Fixed in: bullseye \<not-affected>
Still present in: bookworm

(cc @santiago for reviewing the new template)