https://www.freexian.com/./index.xml
· source : Home | Freexian
Recent content in Home on Freexian
🗒️ Articles (40 affichés sur 100 retenus)
📄 100
30/10/2020 09:07
How can I access the package repositories? The package repositories are private. Only customers of the service have access to them. See the documentation for details on how you can access them. On how many servers can I use the package repositories? This depends on the offer that you picked. Up to 3…
Lire l'article →
05/12/2025 06:41
After subscription to the Extended LTS (ELTS) service, Freexian hands over credentials — under the form of a username and a password — to the technical contact listed on the service order form. You will need those to access the APT repositories, they are referred to as ${username} and ${password} in…
Lire l'article →
28/10/2020 10:46
The package repositories hosting the various PHP releases are private. That means that only customers of this service can get access to them. This document explains the various options available and the required steps to configure those repositories. Installing the freexian archive GPG key All the p…
Lire l'article →
16/09/2026 18:58
Freexian Security Policy Freexian relies on the Common Vulnerabilities and Exposures (CVE) system and the coordination with vendors across the ecosystem to track and triage all the different security issues that have been identified in the packages shipped in our supported Debian releases. Freexian …
Lire l'article →
10/07/2018 09:58
The kernel versions originally shipped with each Debian release are no longer maintained during the Extended LTS phase of each release’s lifecycle. Instead, we provide backports of Linux from more recent Debian releases. Currently, this means that for Debian 9 “stretch”, Debian 10 “buster” and Debia…
Lire l'article →
30/05/2018 10:46
Follow with an RSS feed The Extended LTS Advisories (ELA) are published in the Updates section of this website. They can be monitored through this RSS feed. Follow by email If you want to be notified by email, you can subscribe to our dedicated mailing list. Click here, fill the fields, submit the f…
Lire l'article →
20/04/2022 10:46
One package list per Debian release We need a list of packages to support for each Debian release that you are using. The best way to build this list is to gather the list of installed packages on all the Debian systems that you are running. The dpkg-query command can be used for this: $ dpkg-query …
Lire l'article →
20/04/2022 09:58
Explanations about the ELTS cost estimation We have been doing security support of Debian packages since 2014 so we have a long history of data that lets us estimate the workload (and thus cost) required to keep each package secure. We also have historical data of our customers so we know which pack…
Lire l'article →
02/09/2026 13:58
Freexian CSAF and VEX data Providing our users with accurate information about vulnerabilities and security advisories for the various Debian releases, throughout the whole 10-year lifecycle, is one of the main goals of the Freexian LTS/ELTS services. Moreover, managing and delivering vulnerability …
Lire l'article →
06/11/2025 10:00
Extended LTS for Debian 13 Trixie Support period 2025-08-09: Publication of Debian 13 Trixie 2028-08-10: Security support handed over to the Debian LTS team. 2030-06-30: End of support in Debian. Security support now handled by Freexian’s Extended LTS service. 2035-06-30: End of support. Architectur…
Lire l'article →
27/11/2023 10:00
Extended LTS for Debian 12 Bookworm Support period 2023-06-10: Publication of Debian 12 Bookworm 2026-06-11: Security support handed over to the Debian LTS team. 2028-06-30: End of support in Debian. Security support now handled by Freexian’s Extended LTS service. 2033-06-30: End of support. Archite…
Lire l'article →
27/11/2023 09:58
Extended LTS for Debian 11 Bullseye Support period 2021-08-14: Publication of Debian 11 Bullseye 2024-08-15: Security support handed over to the Debian LTS team. 2026-08-31: End of support in Debian. Security support now handled by Freexian’s Extended LTS service. 2031-06-30: End of support. Archite…
Lire l'article →
12/09/2023 09:58
Extended LTS for Debian 10 Buster Support period 2019-07-06: Publication of Debian 10 Buster 2022-06-30: Security support handed over to the Debian LTS team. 2024-06-30: End of support in Debian. Security support now handled by Freexian’s Extended LTS service. 2029-06-30: End of support. Architectur…
Lire l'article →
20/04/2022 09:58
Extended LTS for Debian 9 Stretch Support period 2017-06-17: Publication of Debian 9 Stretch 2020-06-30: Security support handed over to the Debian LTS team. 2022-06-30: End of support in Debian. Security support now handled by Freexian’s Extended LTS service. 2027-06-30: End of support. Architectur…
Lire l'article →
20/04/2022 09:58
Extended LTS for Debian 8 Jessie Support period 2015-04-26: Publication of Debian 8 Jessie 2018-06-17: Security support handed over to the Debian LTS team. 2020-06-30: End of support in Debian. Security support now handled by Freexian’s Extended LTS service. 2025-06-30: End of support. Architectures…
Lire l'article →
28/10/2020 10:13
Why setup a private mirror? Only customers of the “enterprise” offer have the required access to setup a private mirror with rsync (which is what’s described on this page). They typically have very large setup with several thousands of servers needing access to the PHP LTS repositories and it makes …
Lire l'article →
04/07/2024 14:10
This document provides a base to backport security patches provided by Freexian Debian ELTS into Raspberry PI OS packages. We describe a git-based workflow, particularly using git-buildpackage, focusing also on source debian packages in "3.0 (quilt)" format, so the (security) patches to be backporte…
Lire l'article →
27/09/2026 01:53
Package : nginx Version : 1.14.2-2+deb10u9 (buster) Related CVEs : CVE-2026-42533 CVE-2026-56434 Multiple vulnerabilities were discovered in nginx, a high-performance web and reverse proxy server, which may result in denial of service or potentially the execution of arbitrary code. CVE-2026-42533 A …
Lire l'article →
27/09/2026 01:48
Package : nginx Version : 1.18.0-6.1+deb11u9 (bullseye) Related CVEs : CVE-2026-42533 CVE-2026-56434 CVE-2026-60005 Multiple vulnerabilities were discovered in nginx, a high-performance web and reverse proxy server, which may result in denial of service, memory disclosure or potentially the executio…
Lire l'article →
24/09/2026 20:28
Package : redis Version : 5:6.0.16-1+deb11u10 (bullseye) Related CVEs : CVE-2026-81934 A use-after-free vulnerability was discovered in the Redis key/value database in the handling of pending TLS data. A remote, unauthenticated attacker may be been able to execute arbitrary commands with the privile…
Lire l'article →
24/09/2026 12:06
Package : libdatetime-timezone-perl Version : 1:2.09-1+2026c (stretch), 1:2.23-1+2026c (buster), 1:2.47-1+2026c (bullseye) This update includes the changes in tzdata 2026c for the Perl bindings.
Lire l'article →
23/09/2026 21:52
We are always looking for talented individuals who embrace our mission statement and our values. Have a look at the job descriptions below and feel free to apply if there’s a match! Open positions None currently, but if you think that you would be a good match for Freexian, feel free to reach out to…
Lire l'article →
23/09/2026 17:45
Package : tzdata Version : 2026c-0+deb9u1 (stretch), 2026c-0+deb10u1 (buster), 2026c-0+deb11u1 (bullseye) This update includes the changes in tzdata 2026c. Notable changes are: Alberta moved to permanent -06 on 2026-06-18, so it will not fall back from -06 to -07 on 2026-11-01. Morocco moved to perm…
Lire l'article →
20/09/2026 15:39
Package : libde265 Version : 1.0.11-0+deb9u8 (stretch), 1.0.11-0+deb10u8 (buster), 1.0.11-0+deb11u5 (bullseye) Related CVEs : CVE-2024-38949 CVE-2024-38950 CVE-2026-45382 CVE-2026-45383 CVE-2026-49295 CVE-2026-49337 CVE-2026-49346 CVE-2026-54240 CVE-2026-54241 TEMP-0000000-BB5891 TEMP-0000000-E66AA0…
Lire l'article →
20/09/2026 09:40
Package : libarchive Version : 3.2.2-2+deb9u7 (stretch), 3.3.3-4+deb10u6 (buster) Related CVEs : CVE-2026-4424 CVE-2026-4426 CVE-2026-5121 CVE-2026-15028 CVE-2026-16517 Several vulnerabilities were discovered in libarchive, a multi-format archive and compression library CVE-2026-4424 A flaw was foun…
Lire l'article →
20/09/2026 00:00
The Debian LTS Team, funded by Freexian’s Debian LTS offering, is pleased to report its activities for August. Activity summary During the month of August, 19 contributors have been paid to work on Debian LTS (links to individual contributor reports are located below). The team released 58 DLAs fixi…
Lire l'article →
18/09/2026 11:01
Package : zip Version : 3.0-11+deb9u1 (stretch), 3.0-11+deb10u1 (buster), 3.0-12+deb11u1 (bullseye) Related CVEs : CVE-2018-13410 Multiple minor vulnerabilities was adressed together with the prime issue: Harry Sintonen discovered that the Info-ZIP zip program is prone to a command injection vulnera…
Lire l'article →
17/09/2026 08:12
Package : firefox-esr Version : 140.16.0esr-1~deb11u1 (bullseye) Related CVEs : CVE-2026-92005 CVE-2026-92006 CVE-2026-92007 CVE-2026-92008 CVE-2026-92009 CVE-2026-92010 CVE-2026-92011 CVE-2026-92012 CVE-2026-92013 CVE-2026-92014 CVE-2026-92015 CVE-2026-92016 CVE-2026-92017 CVE-2026-92018 CVE-2026-9…
Lire l'article →
16/09/2026 09:37
Package : jbig2dec Version : 0.13-4.1+deb9u2 (stretch), 0.16-1+deb10u2 (buster), 0.19-2+deb11u1 (bullseye) Related CVEs : CVE-2026-38076 It was discovered that missing input sanitising in the JBIG2 decoder library could result in denial of service.
Lire l'article →
15/09/2026 00:00
Debian Contributions: 2026-08 Contributing to Debian is part of Freexian’s mission. This article covers the latest achievements of Freexian and their collaborators. All of this is made possible by organizations subscribing to our Long Term Support contracts and consulting services. Replacing lxc wit…
Lire l'article →
11/09/2026 12:39
Package : apr-util Version : 1.5.4-3+deb9u2 (stretch) Related CVEs : CVE-2025-49506 CVE-2026-32327 CVE-2026-34191 CVE-2026-34502 Several vulnerabilities were discovered in apr-util, the Apache Portable Runtime Utility library, which could result in denial of service or potentially the execution of a…
Lire l'article →
11/09/2026 12:37
Package : apr-util Version : 1.6.1-4+deb10u2 (buster) Related CVEs : CVE-2025-49506 CVE-2026-32327 CVE-2026-34191 CVE-2026-34501 CVE-2026-34502 Several vulnerabilities were discovered in apr-util, the Apache Portable Runtime Utility library, which could result in denial of service or potentially the…
Lire l'article →
10/09/2026 09:04
Package : linux-6.1 Version : 6.1.187-1~deb9u1 (stretch), 6.1.187-1~deb10u1 (buster), 6.1.187-1~deb11u1 (bullseye) Related CVEs : CVE-2023-53706 CVE-2023-54141 CVE-2023-54263 CVE-2024-38620 CVE-2024-46754 CVE-2024-58094 CVE-2024-58095 CVE-2025-22104 CVE-2025-38117 CVE-2025-38203 CVE-2025-38206 CVE-2…
Lire l'article →
08/09/2026 10:23
Package : firefox-esr Related CVEs : CVE-2026-16365 CVE-2026-16371 CVE-2026-75874 CVE-2026-84119 CVE-2026-84120 CVE-2026-84121 CVE-2026-84122 CVE-2026-84124 CVE-2026-84131 CVE-2026-84143 CVE-2026-84145 Multiple security issues have been found in the Mozilla Firefox web browser, which could potential…
Lire l'article →
07/09/2026 10:42
Package : libssh2 Version : 1.7.0-1+deb9u4 (stretch), 1.8.0-2.1+deb10u2 (buster) Related CVEs : CVE-2025-15661 CVE-2026-7598 CVE-2026-58051 CVE-2026-66032 CVE-2026-66034 Multiple security vulnerabilities were discovered in libssh2, a client-side C library implementing the SSH2 protocol which could r…
Lire l'article →
07/09/2026 10:36
Package : libssh2 Version : 1.9.0-2+deb11u2 (bullseye) Related CVEs : CVE-2025-15661 CVE-2026-7598 CVE-2026-58050 CVE-2026-58051 CVE-2026-66032 CVE-2026-66034 Multiple security vulnerabilities were discovered in libssh2, a client-side C library implementing the SSH2 protocol which could result in me…
Lire l'article →
07/09/2026 00:00
Contributor: Jugal Patel (Jugal59) Organization: Debian Project: Provide debuginfod server Mentor: Colin Watson About the project and me Your program crashes. You open gdb and get ?? instead of a stack trace. So you go find the right -dbgsym package, for the right version, for the right architecture…
Lire l'article →
02/09/2026 08:03
Package : shim Version : 16.1-2~deb11u1 (bullseye) In order to support Secure Boot in bullseye ELTS, the shim needs to have the Freexian public certificate used to sign Linux kernels and other packages. This update adds that certificate to the shim alongside the Debian public CA, which allows to boo…
Lire l'article →
01/09/2026 08:48
Package : libdbd-csv-perl Version : 0.4900-1+deb9u1 (stretch), 0.5300-1+deb10u2 (buster) The security fix for CVE-2026-15392 (symlink escape in DBD::File), published for libdbi-perl as ELA-1816-1, broke the test suite of the libdbd-csv-perl package. The DBD::CSV Perl module itself remains unchanged …
Lire l'article →
01/09/2026 08:38
Package : libdbi-perl Version : 1.636-1+deb9u4 (stretch), 1.642-1+deb10u4 (buster) Related CVEs : CVE-2026-14380 CVE-2026-14739 CVE-2026-14740 CVE-2026-15043 CVE-2026-15392 CVE-2026-60081 CVE-2026-60082 CVE-2026-73193 CVE-2026-73194 CVE-2026-14380 Missing input validation when interpolating the pack…
Lire l'article →