-
Notifications
You must be signed in to change notification settings - Fork 19
Open
Labels
bugSomething isn't workingSomething isn't workingcomponent/devguard-apiAPI RelatedAPI Relatedpriority:high
Description
Currently, the version matching for Debian packages seems a bit off. The following problem were identified:
SBOM to reproduce: sbom.json
-
Debian version annotations
+deb11u1or~deb12u2seems to be ignored.- Example: https://security-tracker.debian.org/tracker/CVE-2025-27614 where fixed version
1:2.47.3-0+deb13u1is installed - Example: https://security-tracker.debian.org/tracker/CVE-2023-23914 where fixes version
8.14.1-2+deb13u2is installed
- Example: https://security-tracker.debian.org/tracker/CVE-2025-27614 where fixed version
-
Identical as fixed version seems to be seen as smaller
- Example: https://security-tracker.debian.org/tracker/CVE-2024-8176 where fixed
2.7.1-2is installed (no suffix)
- Example: https://security-tracker.debian.org/tracker/CVE-2024-8176 where fixed
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't workingcomponent/devguard-apiAPI RelatedAPI Relatedpriority:high