LTS and ELTS report July 2026 ============================= Debian LTS ========== 1. In July I was on holiday off and on and worked on Samba, especially for the ELTS project but this also benefited bullseye and bookworm. Debian ELTS =========== 1. samba: - completed the stretch update, investigated a test failure and fixed it - worked on a new series of patches to address the Samba security advisory from July 28, 2026. After the release of the security update for buster I ran the final tests for stretch and discovered several test failures which did not happen in buster. After I investigated the problem it turned out a typo in samba's substitute code to remove unsafe characters was responsible for the failing tests. Unfortunately this delayed the release for stretch. In the meantime, at the end of July, the Samba team released a new security announcement. I took this one into consideration as well but as of now there will be two separate security updates for stretch and a new one for buster and later releases. The first one fixes CVE-2026-2340, CVE-2026-3012, CVE-2026-3238, CVE-2026-4408, CVE-2026-4480. The second one will address CVE-2026-6949, CVE-2026-58218 and CVE-2026-58224 while CVE-2026-58221 and CVE-2026-58222 will not be fixed since Active Directory Domain Controler functionality is not supported. CVE-2026-58216 and CVE-2026-15779 are of minor severity and can be fixed with the second security update or at a later point in time.