rsync (3.3.0+ds1-3) unstable; urgency=critical . * Import upstream patches for CVE-2024-12084, CVE-2024-12085, CVE-2024-12086, CVE-2024-12087, CVE-2024-12088, CVE-2024-12747 - d/p/rsync-upstream-CVE-patches-v3/CVE-2024-12084 ~ 0001-Some-checksum-buffer-fixes.patch ~ 0002-Another-cast-when-multiplying-integers.patch - d/p/rsync-upstream-CVE-patches-v3/CVE-2024-12085 ~ 0001-prevent-information-leak-off-the-stack.patch - d/p/rsync-upstream-CVE-patches-v3/CVE-2024-12086 ~ 0001-refuse-fuzzy-options-when-fuzzy-not-selected.patch ~ 0002-added-secure_relative_open.patch ~ 0003-receiver-use-secure_relative_open-for-basis-file.patch ~ 0004-disallow-.-elements-in-relpath-for-secure_relative_o.patch - d/p/rsync-upstream-CVE-patches-v3/CVE-2024-12087 ~ 0001-Refuse-a-duplicate-dirlist.patch ~ 0002-range-check-dir_ndx-before-use.patch - d/p/rsync-upstream-CVE-patches-v3/CVE-2024-12088 ~ 0001-make-safe-links-stricter.patch - d/p/rsync-upstream-CVE-patches-v3/CVE-2024-12747 ~ 0001-fixed-symlink-race-condition-in-sender.patch - d/p/rsync-upstream-CVE-patches-v3/version_update ~ 0001-raise-protocol-version-to-32.patch ~ 0002-change-version-to-3.4.0.patch ~ 0003-update-NEWS-for-3.4.0.patch REMOVED: erlang-bbmustache 1.6.1+dfsg-1 REMOVED: apt-transport-in-toto 0.1.1-5 REMOVED: golang-github-flowstack-go-jsonschema 0.1.2-2 REMOVED: python-aioopenssl 0.6.0-1 REMOVED: rhvoice 1.8.0+dfsg-4 REMOVED: editorconfig-emacs 0.11.0-1 REMOVED: python-foobot-async 1.0.1-2