LTS and ELTS report August 2026 =============================== I have been on holiday / family visit from Mid August until the beginning of September. Debian LTS ========== 1. I continued the work on samba in the remaining time and finished the security update for bookworm to fix CVE-2026-6949, CVE-2026-58218, CVE-2026-58221, CVE-2026-58222 and CVE-2026-58224. I also prepared a security update for bullseye with a reduced patch set due to limited Active Domin Controller support for samba. I did not encounter any issues with these updates and expect them to be released shortly. Debian ELTS =========== 1. samba: After addressing build failures for the stretch security update, I have been working on fixing CVE-2026-6949, CVE-2026-58218 and CVE-2026-58224 based on the official samba security patches. The update for stretch and buster was quite similar this time. The most time consuming part was the fix for CVE-2026-58224 which also included documentation changes. Due to the nature of the ctdb-protocol, unauthenticated and unencrypted, a denial of service under very specific circumstances cannot be prevented. The private network and the ctdb socket must be secured against untrusted access which is ultimately the responsibility of the server administrator.