linux-2.6 (2.6.26-21) stable; urgency=high

  [ Ben Hutchings ]
  * Fix false soft lockup reports for the nohz idle loop
  * nohz: Fix two bugs that can keep a processor idle and lead to a
    system hang (may fix #496917, #538158 and others)
  * usbmidi: Fix crash when device is disconnected (Closes: #513050)
  * r8169: Apply various upstream bug fixes
  * r8169: Add support for RTL8101e (v2), RTL8102e (v1,v2,v3),
    RTL8168c/8111c (v3,v4), RTL8168cp/8111cp (v2,v3), RTL8168d (v1)
    (Closes: #552465; may fix #516187)
  * Revert patch to sanitise <linux/socket.h>, which introduced
    different build failures
  * usbnet: Set link down initially for drivers that update link state
    (Closes: #444043)
  * atl1e: Remove broken implementation of TSO for TCP/IPv6
    (Closes: #558426) and allow other hardware offloads to be disabled in
    case they are also buggy

  [ dann frazier ]
  * floppy: request and release only the ports we actually use
    (Closes: #332942)
  * igb: Add 82576 MAC support (Closes: #522922), backport
    by Ben Hutchings
  * [SCSI] gdth: Prevent negative offsets in ioctl (CVE-2009-3080)
  * NFSv4: Fix a problem whereby a buggy server can oops the kernel
  * [SCSI] megaraid_sas: remove sysfs dbg_lvl world writeable permissions
  * isdn: hfc_usb: Fix read buffer overflow (CVE-2009-4005)
  * fuse: prevent fuse_put_request on invalid pointer (CVE-2009-4021)
  * hpilo: new PCI ID (Closes: #559064)
  * Avoid /proc/$pid/maps visibility during initial setuid ELF loading
  * hfs: fix a potential buffer overflow (CVE-2009-4020)
  * KVM: x86 emulator: limit instructions to 15 bytes (CVE-2009-4031)
  * firewire: ohci: handle receive packets with a data length of zero
  * ext4: Avoid null pointer dereference when decoding EROFS w/o a journal
  * s390: dasd diag - add support for read-only minidisks (Closes: #550898)

 -- dann frazier <dannf op debian.org>  Sat, 26 Dec 2009 01:06:01 -0700

linux-2.6 (2.6.26-20) stable; urgency=high

  [ Ben Hutchings ]
  * xen: Fix crash in xen_spin_wait() on busy multiprocessor domain
    (Closes: #542250), thanks to Nikita V. Youshchenko <yoush op debian.org>
  * x86: Fix crash in text_poke_early() on 486-class processors
    (Closes: #515982)
  * hppa: Ensure TLB purge runs single threaded (Closes: #539215),
    thanks to Helge Deller <deller op gmx.de>
  * virtio_balloon: Fix towards_target when deflating balloon
    (Closes: #544619)
  * dm-snap: Fix crash when using both snapshot and origin volumes
    (Closes: #545999)
  * nfs: Avoid overrun when copying client IP address string
    (Closes: #549002)
  * sis190: Correct DMA sync handling on small packets (Closes: #541169)
  * mmc: Increase power-up delay (Closes: #508599)
  * v4l2: Improve 32/64-bit ioctl translation (Closes: #508649)
  * proc: Fix truncation of entries in /proc/*/pagemap on 32-bit
    architectures (Closes: #511419)
  * Sanitise <linux/socket.h> and <linux/uio.h> (Closes: #538372)
  * nfs: Handle -ESTALE error in access() (Closes: #508866)
  * r8169: Fix rx_missed_errors statistic (Closes: #531932)
  * hfsplus: Refuse to mount volumes larger than 2TB, which may otherwise
    be corrupted (Closes: #550010)
  * acenic: Pass up error code from ace_load_firmware(), avoiding an oops
    (Closes: #521383)
  * axnet_cs: Reclaim Netgear FA411 from pcnet_cs (Closes: #550935)
  * Update bug script from trunk:
    - Update taint checks
    - Prompt submitters to run the kernel version they're reporting on
      or otherwise record boot messages
    - Include PCI device list even if the running kernel doesn't match
    - Include model information
    - Include firmware package status
    - Include network configuration and status (optional)
    - Include USB device list
  * printk: Avoid hanging when logging messages for time adjustment
    (Closes: #510478)

  [ dann frazier ]
  * autofs4: don't make expiring dentry negative, avoiding an oops
    (Closes: #530636)
  * ocfs/dlm: fix race in dlm_get_lock_resource() which can cause
    flock() to return EINVAL (Closes: #515741)
  * Increase default mmap_min_addr from 0 to 4096 (Closes: #541457)

  [ Martin Michlmayr ]
  * Disable SYS_HAS_EARLY_PRINTK on SGI IP22 to work around a hang
    during bootup (Closes: #507557)
  * USB: ftdi_sio: add product_id for Marvell OpenRD Base, Client

  [ maximilian attems ]
  * [openvz] enable SYSFS_DEPRECATED_V2 for ipv6 tunnels through sit.
    (closes: #517892)
  [ Moritz Muehlenhoff ]
  * nbd: fix I/O hang on disconnected NDBs. (Closes: #550863)
 -- dann frazier <dannf op debian.org>  Fri, 23 Oct 2009 16:31:23 -0600

spamassassin (3.2.5-2+lenny2) stable; urgency=high

  * Fix FH_DATE_PAST_20XX so dates in 2010 aren't considered "grossly
    in the future"
  * Fix a bunch of spelling errors the documentation.

 -- Noah Meyerhans <noahm op debian.org>  Fri, 01 Jan 2010 13:35:50 -0500

base-files (5lenny5) stable; urgency=low

  * Bump version in /etc/debian_version to "5.0.4".

 -- Santiago Vila <sanvila op debian.org>  Tue, 19 Jan 2010 23:45:44 +0100

dhcp3 (3.1.1-6+lenny4) lenny; urgency=low

  * Add patch from Petter Reinholdtsen to fix SIGPIPE when talking to LDAP
    server (closes: #559160)
  * Add patch from Petter Reinholdtsen to fix memory leak in LDAP code (closes:

 -- Andrew Pollock <apollock op debian.org>  Fri, 08 Jan 2010 21:49:09 -0800

dpkg (1.14.28) stable; urgency=low

  * Another round of updates concerning new source formats:
    - fix dpkg-source to not complain on binary files that are ignored and are
      not going to be included in the debian tarball of a "3.0 (quilt)" source
      package. Closes: #524375
    - let dpkg-source fail if several upstream orig.tar files are
      available (using different compression scheme) since we don't know
      which one to use.
    - before accepting to build a 3.0 (quilt) source packages, ensure that
      debian/patches is a directory (or non-existing) and that
      debian/patches/series is a file (or non-existing). Closes: #557618
    - modify implementation of "3.0 (quilt)" source format to not be
      behave differently depending on whether quilt is installed or not.
      The option --without-quilt is thus gone and dpkg-source creates and
      relies on the .pc directory to know whether patches are applied or
      not. Closes: #557667

 -- Raphael Hertzog <hertzog op debian.org>  Sun, 03 Jan 2010 19:40:09 +0100

dpkg (1.14.27) stable; urgency=low

  * Cherry-pick some fixes from squeeze concerning new source formats:
    - dpkg-source now accepts additional tarballs (in format "3.0 (quilt)")
      with a "component" name containing dashes. Closes: #524376
    - ensure that the automatic patch created in format "3.0 (quilt)" is
      always well registered with quilt even when it's updated by a new call
      to dpkg-source. Thanks to Goswin von Brederlow for the initial patch.
      Closes: #525858
    - do not update/create debian/patches/.dpkg-source-applied during build,
      it's only meant to document what patches have been applied at extraction
      time. Closes: #525835
    - call quilt only once to apply all patches instead of once per patch
      when building 3.0 (quilt) source packages. Closes: #518453

 -- Raphael Hertzog <hertzog op debian.org>  Fri, 13 Nov 2009 17:45:15 +0100

dpkg (1.14.26) unstable; urgency=low

  [ Raphael Hertzog ]
  * Fix dpkg-source to not die when uncompressor processes are killed by
    SIGPIPE due to tar closing the pipe without exhausting all the data
    available. Closes: #523329

  [ Updated scripts translations ]
  * German (Helge Kreutzmann).
  * Polish (Wiktor Wandachowicz). Closes: #514106
  * Swedish (Peter Krefting).

  [ Updated manpages translations ]
  * German (Helge Kreutzmann).
  * Polish (Wiktor Wandachowicz). Closes: #514106
  * Swedish (Peter Krefting).

 -- Raphael Hertzog <hertzog op debian.org>  Thu, 09 Apr 2009 19:07:40 +0200

glib2.0 (2.16.6-3) stable; urgency=low

  * SECURITY: 13_permissions_CVE-2009-3289.patch:
    + The g_file_copy function in glib 2.0 sets the permissions of a 
      target file to the permissions of a symbolic link (777), which 
      allows user-assisted local users to modify files of other users, 
      as demonstrated by using Nautilus to modify the permissions of the 
      user home directory.
    + Concatenation of 3 upstream patches, fixes CVE-2009-3289.

 -- Josselin Mouette <joss op debian.org>  Sat, 14 Nov 2009 16:19:20 +0100

libdbd-mysql-perl (4.007-1+lenny1) stable; urgency=low

  * Apply patch from CPAN bug 37027 to stop auto_reconnect option causing
    segmentation faults. (Closes: #520406)

 -- Tim Retout <tim op retout.co.uk>  Sat, 14 Nov 2009 14:22:31 +0000

mysql-dfsg-5.0 (5.0.51a-24+lenny2+spu1) stable-proposed-updates; urgency=low

  [ Sean Finney ]
  * New patch 64_fix-dummy-thread-race-condition.dpatch to back out an
    unneeded workaround that causes segfaults in libmysqlclient15. Thanks
    to Martin Koegler for digging up the patch. (closes: #524366, #513204)

  [ Norbert Tretkowski ]
  * New patch 65_fix_gis_functions_crash.dpatch from 5.0.82 to fix a server
    crash with arbitrary data input plus GIS functions. (closes: #477072)

 -- Sean Finney <seanius op debian.org>  Sat, 05 Sep 2009 12:15:22 +0200

shadow (1:4.1.1-6+lenny1) stable-proposed-updates; urgency=low

  * The "Soumaintrain" release.
  * debian/patches/306_long_group_lines: Fix handling of long lines in the
    user or group files. Closes: #552006

 -- Nicolas FRANCOIS (Nekral) <nicolas.francois op centraliens.net>  Fri, 13 Nov 2009 22:13:39 +0100

tzdata (2010a-0lenny1) stable; urgency=low

  * New upstream release.
    - Drop argentinas-dst-2009.diff (obsolete).

 -- Clint Adams <schizo op debian.org>  Thu, 21 Jan 2010 13:36:05 -0500

tzdata (2009o-0lenny1) stable; urgency=low

  * New upstream release.
  * Rework rules to stop using tarball-in-tarball.
  * debian/patches/argentinas-dst-2009.diff: patch from Margarita
    Manterola to fix Argentina DST again.  closes: #551195.

 -- Clint Adams <schizo op debian.org>  Mon, 19 Oct 2009 09:39:45 -0700

usbutils (0.73-10lenny1) stable; urgency=low

  * Update usb.ids:
    - Add Logitech Webcam C200 (046d:0802) (closes: bug#564035).
    - Add Verbatim External Hard Drive (18a5:0216) (closes: bug#563085).
    - Add eHome Infrared Receiver (147a:e017) Ralink rt2570 802.11g WLAN
      (14b2:3c05) (closes: bug#531274).
    - Fix entry about Netgear WG111 (0846:4240) (closes: bug#500706).
    - Add Hewlett-Packard LaserJet P1005 (03f0:3d17) (closes: bug#525629).
    - Add Benq X120 Internet Keyboard Pro (0d62:001c) (closes: bug#525628).
    - Add Dexon Mouse (15d9:0a33) (closes: bug#525582).

 -- Aurelien Jarno <aurel32 op debian.org>  Sun, 17 Jan 2010 21:23:23 +0100

