<?xml version='1.0' encoding='UTF-8'?>
<oval_definitions xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:ind-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>Tuxcare Errata System</oval:product_name>
    <oval:product_version>0.0.1</oval:product_version>
    <oval:schema_version>5.10</oval:schema_version>
    <oval:timestamp>2026-09-20T10:12:01</oval:timestamp>
  </generator>
  <definitions>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1787918353" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-46113, CVE-2026-64561, CVE-2026-64564, CVE-2026-64600</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1787918353" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1787918353" source="CLSA"/>
        <reference ref_id="CVE-2026-64561" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64561" source="CVE"/>
        <reference ref_id="CVE-2026-64600" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64600" source="CVE"/>
        <reference ref_id="CVE-2026-64564" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64564" source="CVE"/>
        <reference ref_id="CVE-2026-46113" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-46113" source="CVE"/>
        <description>* TuxCare ELS build of the Debian 11 (bullseye) 5.10.262 kernel
     (x86_64/aarch64/armel).
   * Reconstructed on the newer bullseye-security 5.10.262-1 base (rolls up
     upstream stable 5.10.260 / .261 / .262), replacing the prior 5.10.259-1
     base. Debian patch set re-imported as git commits (ip6_vti patch dropped —
     now upstream; firmware log-message patch refreshed).
   * Single-source: embed the linux-latest + linux-signed meta packages into the
     source tree (debian/meta/) so one dpkg-buildpackage run produces the
     versioned kernel AND the meta/signed packages.
   * ABI: this ELS changelog entry increments the gencontrol-computed abiname
     5.10.0-46 -&gt; 5.10.0-47, so the ELS kernel ships as linux-image-5.10.0-47-*,
     a distinct, co-installable package vs Debian stock 5.10.0-46.
   * Disable the rt and cloud featuresets/flavours (not shipped by ELS).
   * Fix the duplicate pinned image/headers meta on signed arches under
     disable-signed: gate the pinned-meta emission on raw signed-code so only the
     embed's fallback meta (linux-image-5.10.0-47-amd64 | ...-unsigned) ships.
   * Backport security fixes for potentially-exploited (KCARE 0/1-day) CVEs:
     CVE-2026-46113 (KVM x86 shadow-paging UAF, unexpected GFN/role),
     CVE-2026-64561 (KVM x86: check obsolete root after making MMU pages
     available),
     CVE-2026-64564 (SCTP ASCONF DEL-IP transport use-after-free),
     CVE-2026-64600 (XFS: resample data-fork mapping after cycling ILOCK).
   * Drop the prior CVE-2026-43499 (rtmutex remove_waiter UAF) and
     CVE-2026-46331 (net/sched pedit partial-COW) backports — both are included
     upstream in the 5.10.260 / .261 / .262 stable roll-up.</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-08-28"/>
          <updated date="2026-08-28"/>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-64561" impact="unknown" public="20260804">CVE-2026-64561</cve>
          <cve cwe="CWE-362" href="https://cve.tuxcare.com/els/cve/CVE-2026-64600" impact="unknown" public="20260723">CVE-2026-64600</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-64564" impact="unknown" public="20260804">CVE-2026-64564</cve>
          <cve cvss3="5.8/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els/cve/CVE-2026-46113" impact="moderate" public="20260528">CVE-2026-46113</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="kernel earlier than linux-5.10.0-47-amd64 (or unknown) is currently running" test_ref="oval:com.tuxcare.clsa:tst:1787918353002"/>
        <criterion comment="bpftool is earlier than 0:5.10.262-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1787918353003"/>
        <criterion comment="hyperv-daemons is earlier than 0:5.10.262-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1787918353004"/>
        <criterion comment="libcpupower-dev is earlier than 0:5.10.262-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1787918353005"/>
        <criterion comment="libcpupower1 is earlier than 0:5.10.262-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1787918353006"/>
        <criterion comment="linux-compiler-gcc-10-x86 is earlier than 0:5.10.262-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1787918353007"/>
        <criterion comment="linux-config-5.10 is earlier than 0:5.10.262-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1787918353008"/>
        <criterion comment="linux-cpupower is earlier than 0:5.10.262-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1787918353009"/>
        <criterion comment="linux-doc is earlier than 0:5.10.262-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1787918353010"/>
        <criterion comment="linux-doc-5.10 is earlier than 0:5.10.262-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1787918353011"/>
        <criterion comment="linux-headers-5.10.0-47-amd64 is earlier than 0:5.10.262-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1787918353012"/>
        <criterion comment="linux-headers-5.10.0-47-common is earlier than 0:5.10.262-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1787918353013"/>
        <criterion comment="linux-headers-amd64 is earlier than 0:5.10.262-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1787918353014"/>
        <criterion comment="linux-image-5.10.0-47-amd64-unsigned is earlier than 0:5.10.262-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1787918353015"/>
        <criterion comment="linux-image-amd64 is earlier than 0:5.10.262-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1787918353016"/>
        <criterion comment="linux-image-amd64-signed-template is earlier than 0:5.10.262-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1787918353017"/>
        <criterion comment="linux-kbuild-5.10 is earlier than 0:5.10.262-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1787918353018"/>
        <criterion comment="linux-libc-dev is earlier than 0:5.10.262-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1787918353019"/>
        <criterion comment="linux-perf is earlier than 0:5.10.262-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1787918353020"/>
        <criterion comment="linux-perf-5.10 is earlier than 0:5.10.262-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1787918353021"/>
        <criterion comment="linux-source is earlier than 0:5.10.262-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1787918353022"/>
        <criterion comment="linux-source-5.10 is earlier than 0:5.10.262-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1787918353023"/>
        <criterion comment="linux-support-5.10.0-47 is earlier than 0:5.10.262-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1787918353024"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1788696775" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-11979, CVE-2026-6653</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1788696775" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1788696775" source="CLSA"/>
        <reference ref_id="CVE-2026-11979" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-11979" source="CVE"/>
        <reference ref_id="CVE-2026-6653" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-6653" source="CVE"/>
        <description>* SECURITY UPDATE: use-after-free in the DTD parser reachable through
     xmlParseInternalSubset()
     - debian/patches/CVE-2026-6653.patch: stop xmlPushInput() in parser.c
       from returning -1 when the parser has already been halted, since
       inputPush() has by then installed the input as ctxt-&gt;input and the
       caller reads -1 as "ownership not transferred" and frees it.
       xmlParsePEReference() then leaves ctxt-&gt;input dangling and
       xmlParseInternalSubset()'s loop reads through it in RAW, which is
       evaluated before the XML_PARSER_EOF test can short-circuit.  The halt
       itself comes from the amplification check in xmlParserEntityCheck()
       added by Patch-for-security-issue-CVE-2021-3541.patch and is left
       untouched
     - CVE-2026-6653
   * SECURITY UPDATE: stack buffer overflows in xmlcatalog --shell mode
     - debian/patches/CVE-2026-11979.patch: add capacity checks to the
       command, argument and argv loops of the usershell() command-line
       parser in xmlcatalog.c, so an over-long --shell command line is
       rejected instead of written past the end of the on-stack buffers
     - CVE-2026-11979</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-06"/>
          <updated date="2026-09-06"/>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-121" href="https://cve.tuxcare.com/els/cve/CVE-2026-11979" impact="important" public="20260629">CVE-2026-11979</cve>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els/cve/CVE-2026-6653" impact="critical" public="20260622">CVE-2026-6653</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="libxml2 is earlier than 0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788696775001"/>
        <criterion comment="libxml2-dev is earlier than 0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788696775002"/>
        <criterion comment="libxml2-doc is earlier than 0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788696775003"/>
        <criterion comment="libxml2-utils is earlier than 0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788696775004"/>
        <criterion comment="python3-libxml2 is earlier than 0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788696775005"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1788699858" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2023-44487, CVE-2026-42533, CVE-2026-56434, CVE-2026-60005</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1788699858" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1788699858" source="CLSA"/>
        <reference ref_id="CVE-2026-42533" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-42533" source="CVE"/>
        <reference ref_id="CVE-2026-56434" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-56434" source="CVE"/>
        <reference ref_id="CVE-2026-60005" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-60005" source="CVE"/>
        <reference ref_id="CVE-2023-44487" ref_url="https://cve.tuxcare.com/els/cve/CVE-2023-44487" source="CVE"/>
        <description>* SECURITY UPDATE: HTTP/2 denial of service via rapid stream reset
     (HTTP/2 Rapid Reset)
     - debian/patches/CVE-2023-44487.patch: limit new streams to
       2 * http2_max_concurrent_streams per event loop iteration in
       ngx_http_v2_state_headers, and cap refused streams at the
       maximum of http2_max_concurrent_streams and 100, so a client
       that opens and immediately cancels streams can no longer pin
       worker CPU
     - CVE-2023-44487
   * SECURITY UPDATE: buffer overrun in the script engine via map
     directives using regex matching with a string expression
     - debian/patches/CVE-2026-42533.patch: add an e-&gt;end bound and an
       ngx_http_script_check_length() guard to the script copy code
       paths in both the http and stream script engines, and thread a
       separate header/parameter length accumulator through the proxy
       (headers_len, body_len), grpc (headers_len), fastcgi, scgi and
       uwsgi (params_len) upstream request builders, the http and
       stream access log writers, and the index, try_files and rewrite
       modules, so an attacker-controlled map+regex expansion can no
       longer overrun the assembled request, log or result buffer.
       Also drops uninitialised trailing bytes from complex values,
       which previously leaked to the client.
     - CVE-2026-42533
   * SECURITY UPDATE: use-after-free via duplicate subrequest
     finalization in ngx_http_ssi_filter_module
     - debian/patches/CVE-2026-56434.patch: skip posting a request
       that is already on r-&gt;main-&gt;posted_requests in
       ngx_http_post_request, and reset r-&gt;write_event_handler to the
       empty handler during active subrequest finalization, so a
       subrequest posted twice can no longer be finalized twice and
       over-decrement r-&gt;main-&gt;count
     - CVE-2026-56434
   * SECURITY UPDATE: uninitialized memory read via stale regex
     captures
     - debian/patches/CVE-2026-60005.patch: reset r-&gt;ncaptures when
       ngx_http_regex_exec reallocates r-&gt;captures, so a subsequent
       unnamed capture reference after a non-matching regex no longer
       reads uninitialized memory
     - CVE-2026-60005
   * The CVE-2026-42533 patch additionally carries two upstream
     commits that are not part of the vulnerability fix but are
     required for it not to regress this package:
     - e09c0d32d51c reserves NGX_OFF_T_LEN rather than NGX_SIZE_T_LEN
       for the access log "request_length" variable, whose handler
       formats with %O. Without it the new length guard rejects every
       log line containing $request_length on 32-bit architectures
       (armel here), where off_t is 8 bytes and size_t is 4.
     - 4b90ec769235 restores the stack push in
       ngx_http_script_complex_value_code and has the new end code
       update that slot instead. Without it any module reusing
       ngx_http_script_complex_value_code without emitting the new
       end code -- which includes the ngx_devel_kit copy in
       debian/modules/http-ndk, and hence libnginx-mod-http-ndk and
       libnginx-mod-http-lua -- pops a stack slot that was never
       pushed.
   * Note for out-of-tree dynamic modules: the CVE-2023-44487 patch
     inserts two fields into ngx_http_v2_connection_t and the
     CVE-2026-42533 patch inserts one into ngx_http_script_engine_t,
     which shifts the offsets of later members in both. nginx_version
     and NGX_MODULE_SIGNATURE do not encode struct layout, so such a
     module loads without complaint. Every libnginx-mod-* package in
     this source package is rebuilt here and is unaffected; dynamic
     modules built elsewhere against 1.18.0-6.1+deb11u8 headers must
     be rebuilt.</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-06"/>
          <updated date="2026-09-06"/>
          <cve cwe="CWE-122" href="https://cve.tuxcare.com/els/cve/CVE-2026-42533" impact="unknown" public="20260715">CVE-2026-42533</cve>
          <cve cwe="CWE-416" href="https://cve.tuxcare.com/els/cve/CVE-2026-56434" impact="unknown" public="20260715">CVE-2026-56434</cve>
          <cve cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H" cwe="CWE-908" href="https://cve.tuxcare.com/els/cve/CVE-2026-60005" impact="important" public="20260715">CVE-2026-60005</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://cve.tuxcare.com/els/cve/CVE-2023-44487" impact="important" public="20231010">CVE-2023-44487</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="libnginx-mod-http-auth-pam is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858001"/>
        <criterion comment="libnginx-mod-http-cache-purge is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858002"/>
        <criterion comment="libnginx-mod-http-dav-ext is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858003"/>
        <criterion comment="libnginx-mod-http-echo is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858004"/>
        <criterion comment="libnginx-mod-http-fancyindex is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858005"/>
        <criterion comment="libnginx-mod-http-geoip is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858006"/>
        <criterion comment="libnginx-mod-http-geoip2 is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858007"/>
        <criterion comment="libnginx-mod-http-headers-more-filter is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858008"/>
        <criterion comment="libnginx-mod-http-image-filter is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858009"/>
        <criterion comment="libnginx-mod-http-lua is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858010"/>
        <criterion comment="libnginx-mod-http-ndk is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858011"/>
        <criterion comment="libnginx-mod-http-perl is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858012"/>
        <criterion comment="libnginx-mod-http-subs-filter is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858013"/>
        <criterion comment="libnginx-mod-http-uploadprogress is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858014"/>
        <criterion comment="libnginx-mod-http-upstream-fair is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858015"/>
        <criterion comment="libnginx-mod-http-xslt-filter is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858016"/>
        <criterion comment="libnginx-mod-mail is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858017"/>
        <criterion comment="libnginx-mod-nchan is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858018"/>
        <criterion comment="libnginx-mod-rtmp is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858019"/>
        <criterion comment="libnginx-mod-stream is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858020"/>
        <criterion comment="libnginx-mod-stream-geoip is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858021"/>
        <criterion comment="libnginx-mod-stream-geoip2 is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858022"/>
        <criterion comment="nginx is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858023"/>
        <criterion comment="nginx-common is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858024"/>
        <criterion comment="nginx-core is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858025"/>
        <criterion comment="nginx-doc is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858026"/>
        <criterion comment="nginx-extras is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858027"/>
        <criterion comment="nginx-full is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858028"/>
        <criterion comment="nginx-light is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788699858029"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1788773292" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-55204</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1788773292" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1788773292" source="CLSA"/>
        <reference ref_id="CVE-2026-55204" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-55204" source="CVE"/>
        <description>* SECURITY UPDATE: NULL pointer dereference in HPACK dynamic table insertion
     - debian/patches/CVE-2026-55204.patch: add missing NULL check after
       hpack_dht_defrag() in hpack_dht_insert() in src/hpack-tbl.c
     - CVE-2026-55204</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-07"/>
          <updated date="2026-09-07"/>
          <cve cwe="CWE-476" href="https://cve.tuxcare.com/els/cve/CVE-2026-55204" impact="unknown" public="20260618">CVE-2026-55204</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="haproxy is earlier than 0:2.2.9-2+deb11u7+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788773292001"/>
        <criterion comment="haproxy-doc is earlier than 0:2.2.9-2+deb11u7+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788773292002"/>
        <criterion comment="vim-haproxy is earlier than 0:2.2.9-2+deb11u7+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788773292003"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1788774752" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2023-0687</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1788774752" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1788774752" source="CLSA"/>
        <reference ref_id="CVE-2023-0687" ref_url="https://cve.tuxcare.com/els/cve/CVE-2023-0687" source="CVE"/>
        <description>* SECURITY UPDATE: Fix allocated buffer overflow in gmon __monstartup
     - debian/patches/CVE-2023-0687.patch: round up the froms hash table
       size to the froms element alignment in gmon/gmon.c
     - CVE-2023-0687</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-07"/>
          <updated date="2026-09-07"/>
          <cve cvss2="4.0/AV:A/AC:H/Au:S/C:P/I:P/A:P" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-120" href="https://cve.tuxcare.com/els/cve/CVE-2023-0687" impact="critical" public="20230206">CVE-2023-0687</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="glibc-doc is earlier than 0:2.31-13+deb11u14+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788774752001"/>
        <criterion comment="glibc-source is earlier than 0:2.31-13+deb11u14+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788774752002"/>
        <criterion comment="libc-bin is earlier than 0:2.31-13+deb11u14+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788774752003"/>
        <criterion comment="libc-dev-bin is earlier than 0:2.31-13+deb11u14+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788774752004"/>
        <criterion comment="libc-devtools is earlier than 0:2.31-13+deb11u14+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788774752005"/>
        <criterion comment="libc-l10n is earlier than 0:2.31-13+deb11u14+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788774752006"/>
        <criterion comment="libc6 is earlier than 0:2.31-13+deb11u14+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788774752007"/>
        <criterion comment="libc6-dev is earlier than 0:2.31-13+deb11u14+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788774752008"/>
        <criterion comment="libc6-dev-i386 is earlier than 0:2.31-13+deb11u14+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788774752009"/>
        <criterion comment="libc6-dev-x32 is earlier than 0:2.31-13+deb11u14+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788774752010"/>
        <criterion comment="libc6-i386 is earlier than 0:2.31-13+deb11u14+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788774752011"/>
        <criterion comment="libc6-x32 is earlier than 0:2.31-13+deb11u14+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788774752012"/>
        <criterion comment="locales is earlier than 0:2.31-13+deb11u14+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788774752013"/>
        <criterion comment="locales-all is earlier than 0:2.31-13+deb11u14+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788774752014"/>
        <criterion comment="nscd is earlier than 0:2.31-13+deb11u14+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788774752015"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1788774936" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-13698</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1788774936" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1788774936" source="CLSA"/>
        <reference ref_id="CVE-2026-13698" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-13698" source="CVE"/>
        <description>* SECURITY UPDATE: Memory leak via repeated tls-crypt key setup
     - debian/patches/CVE-2026-13698.patch: ensure tls-crypt keys are not set
       up twice by directly inferring whether the key context is already
       initialised
     - CVE-2026-13698</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-07"/>
          <updated date="2026-09-07"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-401" href="https://cve.tuxcare.com/els/cve/CVE-2026-13698" impact="important" public="20260706">CVE-2026-13698</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="openvpn is earlier than 0:2.5.1-3+deb11u4+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788774936001"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1788786309" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2018-5709</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1788786309" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1788786309" source="CLSA"/>
        <reference ref_id="CVE-2018-5709" ref_url="https://cve.tuxcare.com/els/cve/CVE-2018-5709" source="CVE"/>
        <description>* SECURITY UPDATE: Fix integer truncation in the kdb5_util dump loader
     - debian/patches/CVE-2018-5709.patch: add bounds checks in
       process_k5beta7_princ() so oversized dump file fields cannot be
       truncated when assigned to smaller structure fields
     - CVE-2018-5709</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-07"/>
          <updated date="2026-09-07"/>
          <cve cvss2="5.0/AV:N/AC:L/Au:N/C:N/I:P/A:N" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-190" href="https://cve.tuxcare.com/els/cve/CVE-2018-5709" impact="important" public="20180116">CVE-2018-5709</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="krb5-admin-server is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309001"/>
        <criterion comment="krb5-doc is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309002"/>
        <criterion comment="krb5-gss-samples is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309003"/>
        <criterion comment="krb5-k5tls is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309004"/>
        <criterion comment="krb5-kdc is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309005"/>
        <criterion comment="krb5-kdc-ldap is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309006"/>
        <criterion comment="krb5-kpropd is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309007"/>
        <criterion comment="krb5-locales is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309008"/>
        <criterion comment="krb5-multidev is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309009"/>
        <criterion comment="krb5-otp is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309010"/>
        <criterion comment="krb5-pkinit is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309011"/>
        <criterion comment="krb5-user is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309012"/>
        <criterion comment="libgssapi-krb5-2 is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309013"/>
        <criterion comment="libgssrpc4 is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309014"/>
        <criterion comment="libk5crypto3 is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309015"/>
        <criterion comment="libkadm5clnt-mit12 is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309016"/>
        <criterion comment="libkadm5srv-mit12 is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309017"/>
        <criterion comment="libkdb5-10 is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309018"/>
        <criterion comment="libkrad-dev is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309019"/>
        <criterion comment="libkrad0 is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309020"/>
        <criterion comment="libkrb5-3 is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309021"/>
        <criterion comment="libkrb5-dev is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309022"/>
        <criterion comment="libkrb5support0 is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786309023"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1788786535" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2023-42465</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1788786535" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1788786535" source="CLSA"/>
        <reference ref_id="CVE-2023-42465" ref_url="https://cve.tuxcare.com/els/cve/CVE-2023-42465" source="CVE"/>
        <description>* SECURITY UPDATE: harden sudo against ROWHAMMER bit-flip attacks
     - debian/patches/CVE-2023-42465.patch: use ROWHAMMER-resistant values for ALLOW/DENY and the AUTH_* codes and explicitly test for expected values instead of negated tests in the parser and authentication code
     - CVE-2023-42465</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-07"/>
          <updated date="2026-09-07"/>
          <cve cvss3="7.0/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://cve.tuxcare.com/els/cve/CVE-2023-42465" impact="important" public="20231222">CVE-2023-42465</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="sudo is earlier than 0:1.9.5p2-3+deb11u4+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786535001"/>
        <criterion comment="sudo-ldap is earlier than 0:1.9.5p2-3+deb11u4+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788786535002"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1788803338" version="1">
      <metadata>
        <title>Fix of 372 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1788803338" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1788803338" source="CLSA"/>
        <reference ref_id="CVE-2026-68433" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68433" source="CVE"/>
        <reference ref_id="CVE-2026-80560" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80560" source="CVE"/>
        <reference ref_id="CVE-2026-68325" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68325" source="CVE"/>
        <reference ref_id="CVE-2026-68106" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68106" source="CVE"/>
        <reference ref_id="CVE-2026-64567" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64567" source="CVE"/>
        <reference ref_id="CVE-2026-45839" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-45839" source="CVE"/>
        <reference ref_id="CVE-2026-72299" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72299" source="CVE"/>
        <reference ref_id="CVE-2026-80570" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80570" source="CVE"/>
        <reference ref_id="CVE-2026-68151" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68151" source="CVE"/>
        <reference ref_id="CVE-2026-68279" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68279" source="CVE"/>
        <reference ref_id="CVE-2026-72253" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72253" source="CVE"/>
        <reference ref_id="CVE-2026-74480" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74480" source="CVE"/>
        <reference ref_id="CVE-2026-68326" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68326" source="CVE"/>
        <reference ref_id="CVE-2026-72075" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72075" source="CVE"/>
        <reference ref_id="CVE-2026-74583" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74583" source="CVE"/>
        <reference ref_id="CVE-2026-68227" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68227" source="CVE"/>
        <reference ref_id="CVE-2026-68370" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68370" source="CVE"/>
        <reference ref_id="CVE-2026-74505" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74505" source="CVE"/>
        <reference ref_id="CVE-2026-72051" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72051" source="CVE"/>
        <reference ref_id="CVE-2026-68352" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68352" source="CVE"/>
        <reference ref_id="CVE-2026-68135" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68135" source="CVE"/>
        <reference ref_id="CVE-2026-68350" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68350" source="CVE"/>
        <reference ref_id="CVE-2026-31408" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-31408" source="CVE"/>
        <reference ref_id="CVE-2026-68157" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68157" source="CVE"/>
        <reference ref_id="CVE-2026-72096" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72096" source="CVE"/>
        <reference ref_id="CVE-2026-80573" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80573" source="CVE"/>
        <reference ref_id="CVE-2026-74671" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74671" source="CVE"/>
        <reference ref_id="CVE-2026-80718" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80718" source="CVE"/>
        <reference ref_id="CVE-2026-68199" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68199" source="CVE"/>
        <reference ref_id="CVE-2026-68480" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68480" source="CVE"/>
        <reference ref_id="CVE-2026-68344" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68344" source="CVE"/>
        <reference ref_id="CVE-2026-74647" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74647" source="CVE"/>
        <reference ref_id="CVE-2026-68204" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68204" source="CVE"/>
        <reference ref_id="CVE-2026-68188" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68188" source="CVE"/>
        <reference ref_id="CVE-2026-68217" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68217" source="CVE"/>
        <reference ref_id="CVE-2026-68406" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68406" source="CVE"/>
        <reference ref_id="CVE-2026-68403" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68403" source="CVE"/>
        <reference ref_id="CVE-2026-80558" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80558" source="CVE"/>
        <reference ref_id="CVE-2026-68180" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68180" source="CVE"/>
        <reference ref_id="CVE-2026-74601" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74601" source="CVE"/>
        <reference ref_id="CVE-2026-68142" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68142" source="CVE"/>
        <reference ref_id="CVE-2026-68327" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68327" source="CVE"/>
        <reference ref_id="CVE-2026-74628" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74628" source="CVE"/>
        <reference ref_id="CVE-2026-74566" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74566" source="CVE"/>
        <reference ref_id="CVE-2026-64571" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64571" source="CVE"/>
        <reference ref_id="CVE-2026-74569" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74569" source="CVE"/>
        <reference ref_id="CVE-2026-43491" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-43491" source="CVE"/>
        <reference ref_id="CVE-2026-74594" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74594" source="CVE"/>
        <reference ref_id="CVE-2026-64371" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64371" source="CVE"/>
        <reference ref_id="CVE-2026-68363" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68363" source="CVE"/>
        <reference ref_id="CVE-2026-64270" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64270" source="CVE"/>
        <reference ref_id="CVE-2026-68111" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68111" source="CVE"/>
        <reference ref_id="CVE-2026-74615" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74615" source="CVE"/>
        <reference ref_id="CVE-2026-74563" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74563" source="CVE"/>
        <reference ref_id="CVE-2026-68328" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68328" source="CVE"/>
        <reference ref_id="CVE-2026-80567" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80567" source="CVE"/>
        <reference ref_id="CVE-2026-68160" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68160" source="CVE"/>
        <reference ref_id="CVE-2026-68434" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68434" source="CVE"/>
        <reference ref_id="CVE-2026-74549" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74549" source="CVE"/>
        <reference ref_id="CVE-2026-74664" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74664" source="CVE"/>
        <reference ref_id="CVE-2026-68255" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68255" source="CVE"/>
        <reference ref_id="CVE-2026-72121" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72121" source="CVE"/>
        <reference ref_id="CVE-2026-80586" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80586" source="CVE"/>
        <reference ref_id="CVE-2026-68117" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68117" source="CVE"/>
        <reference ref_id="CVE-2026-74485" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74485" source="CVE"/>
        <reference ref_id="CVE-2026-68141" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68141" source="CVE"/>
        <reference ref_id="CVE-2026-68198" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68198" source="CVE"/>
        <reference ref_id="CVE-2026-80590" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80590" source="CVE"/>
        <reference ref_id="CVE-2026-68196" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68196" source="CVE"/>
        <reference ref_id="CVE-2026-74475" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74475" source="CVE"/>
        <reference ref_id="CVE-2026-68162" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68162" source="CVE"/>
        <reference ref_id="CVE-2026-74730" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74730" source="CVE"/>
        <reference ref_id="CVE-2026-74471" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74471" source="CVE"/>
        <reference ref_id="CVE-2026-68222" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68222" source="CVE"/>
        <reference ref_id="CVE-2026-68184" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68184" source="CVE"/>
        <reference ref_id="CVE-2026-74693" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74693" source="CVE"/>
        <reference ref_id="CVE-2026-68182" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68182" source="CVE"/>
        <reference ref_id="CVE-2026-68376" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68376" source="CVE"/>
        <reference ref_id="CVE-2026-74519" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74519" source="CVE"/>
        <reference ref_id="CVE-2026-72225" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72225" source="CVE"/>
        <reference ref_id="CVE-2026-68154" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68154" source="CVE"/>
        <reference ref_id="CVE-2026-68351" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68351" source="CVE"/>
        <reference ref_id="CVE-2026-80584" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80584" source="CVE"/>
        <reference ref_id="CVE-2026-68349" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68349" source="CVE"/>
        <reference ref_id="CVE-2026-64581" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64581" source="CVE"/>
        <reference ref_id="CVE-2022-3113" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-3113" source="CVE"/>
        <reference ref_id="CVE-2026-74625" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74625" source="CVE"/>
        <reference ref_id="CVE-2026-74663" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74663" source="CVE"/>
        <reference ref_id="CVE-2026-74564" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74564" source="CVE"/>
        <reference ref_id="CVE-2026-68425" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68425" source="CVE"/>
        <reference ref_id="CVE-2026-64543" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64543" source="CVE"/>
        <reference ref_id="CVE-2026-74598" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74598" source="CVE"/>
        <reference ref_id="CVE-2026-68452" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68452" source="CVE"/>
        <reference ref_id="CVE-2026-74468" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74468" source="CVE"/>
        <reference ref_id="CVE-2026-80714" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80714" source="CVE"/>
        <reference ref_id="CVE-2026-74436" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74436" source="CVE"/>
        <reference ref_id="CVE-2026-74641" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74641" source="CVE"/>
        <reference ref_id="CVE-2026-68223" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68223" source="CVE"/>
        <reference ref_id="CVE-2026-74613" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74613" source="CVE"/>
        <reference ref_id="CVE-2026-68284" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68284" source="CVE"/>
        <reference ref_id="CVE-2026-68249" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68249" source="CVE"/>
        <reference ref_id="CVE-2026-80681" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80681" source="CVE"/>
        <reference ref_id="CVE-2026-80555" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80555" source="CVE"/>
        <reference ref_id="CVE-2026-68218" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68218" source="CVE"/>
        <reference ref_id="CVE-2026-74675" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74675" source="CVE"/>
        <reference ref_id="CVE-2026-68096" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68096" source="CVE"/>
        <reference ref_id="CVE-2026-80680" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80680" source="CVE"/>
        <reference ref_id="CVE-2026-72114" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72114" source="CVE"/>
        <reference ref_id="CVE-2026-64582" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64582" source="CVE"/>
        <reference ref_id="CVE-2026-74557" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74557" source="CVE"/>
        <reference ref_id="CVE-2026-68125" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68125" source="CVE"/>
        <reference ref_id="CVE-2026-72148" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72148" source="CVE"/>
        <reference ref_id="CVE-2026-74726" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74726" source="CVE"/>
        <reference ref_id="CVE-2026-74746" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74746" source="CVE"/>
        <reference ref_id="CVE-2026-74487" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74487" source="CVE"/>
        <reference ref_id="CVE-2026-74697" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74697" source="CVE"/>
        <reference ref_id="CVE-2026-68428" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68428" source="CVE"/>
        <reference ref_id="CVE-2026-64048" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64048" source="CVE"/>
        <reference ref_id="CVE-2026-74493" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74493" source="CVE"/>
        <reference ref_id="CVE-2026-72142" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72142" source="CVE"/>
        <reference ref_id="CVE-2026-68138" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68138" source="CVE"/>
        <reference ref_id="CVE-2026-74668" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74668" source="CVE"/>
        <reference ref_id="CVE-2026-68197" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68197" source="CVE"/>
        <reference ref_id="CVE-2026-74579" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74579" source="CVE"/>
        <reference ref_id="CVE-2026-68335" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68335" source="CVE"/>
        <reference ref_id="CVE-2026-72035" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72035" source="CVE"/>
        <reference ref_id="CVE-2026-74666" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74666" source="CVE"/>
        <reference ref_id="CVE-2026-72117" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72117" source="CVE"/>
        <reference ref_id="CVE-2026-68397" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68397" source="CVE"/>
        <reference ref_id="CVE-2026-68143" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68143" source="CVE"/>
        <reference ref_id="CVE-2026-68299" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68299" source="CVE"/>
        <reference ref_id="CVE-2026-68451" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68451" source="CVE"/>
        <reference ref_id="CVE-2026-68205" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68205" source="CVE"/>
        <reference ref_id="CVE-2026-68413" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68413" source="CVE"/>
        <reference ref_id="CVE-2026-74719" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74719" source="CVE"/>
        <reference ref_id="CVE-2026-68355" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68355" source="CVE"/>
        <reference ref_id="CVE-2026-74547" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74547" source="CVE"/>
        <reference ref_id="CVE-2026-74688" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74688" source="CVE"/>
        <reference ref_id="CVE-2026-72116" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72116" source="CVE"/>
        <reference ref_id="CVE-2026-80679" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80679" source="CVE"/>
        <reference ref_id="CVE-2026-68338" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68338" source="CVE"/>
        <reference ref_id="CVE-2026-80536" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80536" source="CVE"/>
        <reference ref_id="CVE-2026-68430" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68430" source="CVE"/>
        <reference ref_id="CVE-2026-74469" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74469" source="CVE"/>
        <reference ref_id="CVE-2026-72123" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72123" source="CVE"/>
        <reference ref_id="CVE-2026-68153" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68153" source="CVE"/>
        <reference ref_id="CVE-2026-74679" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74679" source="CVE"/>
        <reference ref_id="CVE-2026-74737" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74737" source="CVE"/>
        <reference ref_id="CVE-2026-74704" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74704" source="CVE"/>
        <reference ref_id="CVE-2026-72041" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72041" source="CVE"/>
        <reference ref_id="CVE-2026-74630" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74630" source="CVE"/>
        <reference ref_id="CVE-2026-53275" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-53275" source="CVE"/>
        <reference ref_id="CVE-2026-74705" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74705" source="CVE"/>
        <reference ref_id="CVE-2026-80527" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80527" source="CVE"/>
        <reference ref_id="CVE-2026-72392" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72392" source="CVE"/>
        <reference ref_id="CVE-2026-68202" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68202" source="CVE"/>
        <reference ref_id="CVE-2026-68131" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68131" source="CVE"/>
        <reference ref_id="CVE-2026-68146" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68146" source="CVE"/>
        <reference ref_id="CVE-2026-74648" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74648" source="CVE"/>
        <reference ref_id="CVE-2026-74585" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74585" source="CVE"/>
        <reference ref_id="CVE-2026-68215" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68215" source="CVE"/>
        <reference ref_id="CVE-2026-68278" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68278" source="CVE"/>
        <reference ref_id="CVE-2026-72115" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72115" source="CVE"/>
        <reference ref_id="CVE-2026-74609" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74609" source="CVE"/>
        <reference ref_id="CVE-2026-68132" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68132" source="CVE"/>
        <reference ref_id="CVE-2026-72181" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72181" source="CVE"/>
        <reference ref_id="CVE-2026-80569" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80569" source="CVE"/>
        <reference ref_id="CVE-2026-68369" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68369" source="CVE"/>
        <reference ref_id="CVE-2026-68187" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68187" source="CVE"/>
        <reference ref_id="CVE-2026-68127" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68127" source="CVE"/>
        <reference ref_id="CVE-2026-74748" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74748" source="CVE"/>
        <reference ref_id="CVE-2026-64583" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64583" source="CVE"/>
        <reference ref_id="CVE-2026-74481" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74481" source="CVE"/>
        <reference ref_id="CVE-2026-74631" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74631" source="CVE"/>
        <reference ref_id="CVE-2026-74694" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74694" source="CVE"/>
        <reference ref_id="CVE-2026-72063" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72063" source="CVE"/>
        <reference ref_id="CVE-2026-74525" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74525" source="CVE"/>
        <reference ref_id="CVE-2026-72099" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72099" source="CVE"/>
        <reference ref_id="CVE-2024-40973" ref_url="https://cve.tuxcare.com/els/cve/CVE-2024-40973" source="CVE"/>
        <reference ref_id="CVE-2026-68377" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68377" source="CVE"/>
        <reference ref_id="CVE-2026-68476" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68476" source="CVE"/>
        <reference ref_id="CVE-2026-68082" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68082" source="CVE"/>
        <reference ref_id="CVE-2026-80574" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80574" source="CVE"/>
        <reference ref_id="CVE-2026-74580" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74580" source="CVE"/>
        <reference ref_id="CVE-2026-68212" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68212" source="CVE"/>
        <reference ref_id="CVE-2026-74676" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74676" source="CVE"/>
        <reference ref_id="CVE-2026-74443" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74443" source="CVE"/>
        <reference ref_id="CVE-2026-68104" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68104" source="CVE"/>
        <reference ref_id="CVE-2026-64572" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64572" source="CVE"/>
        <reference ref_id="CVE-2026-68186" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68186" source="CVE"/>
        <reference ref_id="CVE-2026-74667" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74667" source="CVE"/>
        <reference ref_id="CVE-2026-68156" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68156" source="CVE"/>
        <reference ref_id="CVE-2025-68794" ref_url="https://cve.tuxcare.com/els/cve/CVE-2025-68794" source="CVE"/>
        <reference ref_id="CVE-2026-74490" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74490" source="CVE"/>
        <reference ref_id="CVE-2026-68144" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68144" source="CVE"/>
        <reference ref_id="CVE-2026-72155" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72155" source="CVE"/>
        <reference ref_id="CVE-2026-64336" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64336" source="CVE"/>
        <reference ref_id="CVE-2026-68229" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68229" source="CVE"/>
        <reference ref_id="CVE-2026-74488" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74488" source="CVE"/>
        <reference ref_id="CVE-2026-68175" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68175" source="CVE"/>
        <reference ref_id="CVE-2026-74455" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74455" source="CVE"/>
        <reference ref_id="CVE-2026-68231" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68231" source="CVE"/>
        <reference ref_id="CVE-2026-68322" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68322" source="CVE"/>
        <reference ref_id="CVE-2026-80707" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80707" source="CVE"/>
        <reference ref_id="CVE-2026-74651" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74651" source="CVE"/>
        <reference ref_id="CVE-2026-68209" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68209" source="CVE"/>
        <reference ref_id="CVE-2026-74658" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74658" source="CVE"/>
        <reference ref_id="CVE-2026-72070" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72070" source="CVE"/>
        <reference ref_id="CVE-2026-74589" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74589" source="CVE"/>
        <reference ref_id="CVE-2026-74720" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74720" source="CVE"/>
        <reference ref_id="CVE-2026-74464" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74464" source="CVE"/>
        <reference ref_id="CVE-2026-68297" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68297" source="CVE"/>
        <reference ref_id="CVE-2026-74453" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74453" source="CVE"/>
        <reference ref_id="CVE-2026-80541" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80541" source="CVE"/>
        <reference ref_id="CVE-2026-68402" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68402" source="CVE"/>
        <reference ref_id="CVE-2026-72053" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72053" source="CVE"/>
        <reference ref_id="CVE-2026-74575" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74575" source="CVE"/>
        <reference ref_id="CVE-2026-68136" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68136" source="CVE"/>
        <reference ref_id="CVE-2026-68313" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68313" source="CVE"/>
        <reference ref_id="CVE-2026-74465" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74465" source="CVE"/>
        <reference ref_id="CVE-2026-74456" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74456" source="CVE"/>
        <reference ref_id="CVE-2024-46754" ref_url="https://cve.tuxcare.com/els/cve/CVE-2024-46754" source="CVE"/>
        <reference ref_id="CVE-2026-74508" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74508" source="CVE"/>
        <reference ref_id="CVE-2026-68366" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68366" source="CVE"/>
        <reference ref_id="CVE-2026-68214" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68214" source="CVE"/>
        <reference ref_id="CVE-2026-74620" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74620" source="CVE"/>
        <reference ref_id="CVE-2024-58094" ref_url="https://cve.tuxcare.com/els/cve/CVE-2024-58094" source="CVE"/>
        <reference ref_id="CVE-2026-74657" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74657" source="CVE"/>
        <reference ref_id="CVE-2026-74654" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74654" source="CVE"/>
        <reference ref_id="CVE-2026-68353" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68353" source="CVE"/>
        <reference ref_id="CVE-2026-64535" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64535" source="CVE"/>
        <reference ref_id="CVE-2026-74479" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74479" source="CVE"/>
        <reference ref_id="CVE-2026-68304" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68304" source="CVE"/>
        <reference ref_id="CVE-2026-64562" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64562" source="CVE"/>
        <reference ref_id="CVE-2026-74582" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74582" source="CVE"/>
        <reference ref_id="CVE-2026-74473" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74473" source="CVE"/>
        <reference ref_id="CVE-2026-68354" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68354" source="CVE"/>
        <reference ref_id="CVE-2026-68137" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68137" source="CVE"/>
        <reference ref_id="CVE-2026-72019" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72019" source="CVE"/>
        <reference ref_id="CVE-2026-74626" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74626" source="CVE"/>
        <reference ref_id="CVE-2026-74660" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74660" source="CVE"/>
        <reference ref_id="CVE-2026-68368" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68368" source="CVE"/>
        <reference ref_id="CVE-2026-72077" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72077" source="CVE"/>
        <reference ref_id="CVE-2026-74512" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74512" source="CVE"/>
        <reference ref_id="CVE-2026-80716" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80716" source="CVE"/>
        <reference ref_id="CVE-2026-74682" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74682" source="CVE"/>
        <reference ref_id="CVE-2026-74635" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74635" source="CVE"/>
        <reference ref_id="CVE-2026-80708" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80708" source="CVE"/>
        <reference ref_id="CVE-2026-68315" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68315" source="CVE"/>
        <reference ref_id="CVE-2026-68388" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68388" source="CVE"/>
        <reference ref_id="CVE-2026-72125" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72125" source="CVE"/>
        <reference ref_id="CVE-2026-74498" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74498" source="CVE"/>
        <reference ref_id="CVE-2026-64584" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64584" source="CVE"/>
        <reference ref_id="CVE-2024-58095" ref_url="https://cve.tuxcare.com/els/cve/CVE-2024-58095" source="CVE"/>
        <reference ref_id="CVE-2026-74457" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74457" source="CVE"/>
        <reference ref_id="CVE-2026-53089" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-53089" source="CVE"/>
        <reference ref_id="CVE-2026-68432" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68432" source="CVE"/>
        <reference ref_id="CVE-2026-74717" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74717" source="CVE"/>
        <reference ref_id="CVE-2026-68320" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68320" source="CVE"/>
        <reference ref_id="CVE-2026-74586" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74586" source="CVE"/>
        <reference ref_id="CVE-2026-68234" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68234" source="CVE"/>
        <reference ref_id="CVE-2026-68159" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68159" source="CVE"/>
        <reference ref_id="CVE-2026-46003" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-46003" source="CVE"/>
        <reference ref_id="CVE-2026-74463" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74463" source="CVE"/>
        <reference ref_id="CVE-2026-72166" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72166" source="CVE"/>
        <reference ref_id="CVE-2026-74599" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74599" source="CVE"/>
        <reference ref_id="CVE-2026-74470" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74470" source="CVE"/>
        <reference ref_id="CVE-2026-74683" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74683" source="CVE"/>
        <reference ref_id="CVE-2026-68365" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68365" source="CVE"/>
        <reference ref_id="CVE-2026-74499" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74499" source="CVE"/>
        <reference ref_id="CVE-2025-38524" ref_url="https://cve.tuxcare.com/els/cve/CVE-2025-38524" source="CVE"/>
        <reference ref_id="CVE-2026-74669" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74669" source="CVE"/>
        <reference ref_id="CVE-2026-74622" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74622" source="CVE"/>
        <reference ref_id="CVE-2026-64586" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64586" source="CVE"/>
        <reference ref_id="CVE-2026-68405" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68405" source="CVE"/>
        <reference ref_id="CVE-2026-68446" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68446" source="CVE"/>
        <reference ref_id="CVE-2026-80706" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80706" source="CVE"/>
        <reference ref_id="CVE-2026-68367" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68367" source="CVE"/>
        <reference ref_id="CVE-2026-72087" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72087" source="CVE"/>
        <reference ref_id="CVE-2026-68410" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68410" source="CVE"/>
        <reference ref_id="CVE-2026-68140" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68140" source="CVE"/>
        <reference ref_id="CVE-2026-68213" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68213" source="CVE"/>
        <reference ref_id="CVE-2026-74495" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74495" source="CVE"/>
        <reference ref_id="CVE-2026-74577" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74577" source="CVE"/>
        <reference ref_id="CVE-2026-74701" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74701" source="CVE"/>
        <reference ref_id="CVE-2026-68115" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68115" source="CVE"/>
        <reference ref_id="CVE-2026-80565" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80565" source="CVE"/>
        <reference ref_id="CVE-2026-74523" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74523" source="CVE"/>
        <reference ref_id="CVE-2026-80717" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80717" source="CVE"/>
        <reference ref_id="CVE-2026-64280" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64280" source="CVE"/>
        <reference ref_id="CVE-2026-74507" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74507" source="CVE"/>
        <reference ref_id="CVE-2026-68411" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68411" source="CVE"/>
        <reference ref_id="CVE-2026-46026" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-46026" source="CVE"/>
        <reference ref_id="CVE-2026-74478" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74478" source="CVE"/>
        <reference ref_id="CVE-2026-68195" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68195" source="CVE"/>
        <reference ref_id="CVE-2026-72118" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72118" source="CVE"/>
        <reference ref_id="CVE-2026-68192" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68192" source="CVE"/>
        <reference ref_id="CVE-2026-72084" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72084" source="CVE"/>
        <reference ref_id="CVE-2026-68300" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68300" source="CVE"/>
        <reference ref_id="CVE-2026-68216" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68216" source="CVE"/>
        <reference ref_id="CVE-2026-72323" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72323" source="CVE"/>
        <reference ref_id="CVE-2026-72157" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72157" source="CVE"/>
        <reference ref_id="CVE-2024-58240" ref_url="https://cve.tuxcare.com/els/cve/CVE-2024-58240" source="CVE"/>
        <reference ref_id="CVE-2026-64565" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64565" source="CVE"/>
        <reference ref_id="CVE-2026-80540" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80540" source="CVE"/>
        <reference ref_id="CVE-2026-74637" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74637" source="CVE"/>
        <reference ref_id="CVE-2026-80568" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80568" source="CVE"/>
        <reference ref_id="CVE-2026-72124" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72124" source="CVE"/>
        <reference ref_id="CVE-2026-80528" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80528" source="CVE"/>
        <reference ref_id="CVE-2026-64434" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64434" source="CVE"/>
        <reference ref_id="CVE-2026-74587" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74587" source="CVE"/>
        <reference ref_id="CVE-2026-74597" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74597" source="CVE"/>
        <reference ref_id="CVE-2026-68121" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68121" source="CVE"/>
        <reference ref_id="CVE-2026-80534" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80534" source="CVE"/>
        <reference ref_id="CVE-2026-68360" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68360" source="CVE"/>
        <reference ref_id="CVE-2026-80561" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80561" source="CVE"/>
        <reference ref_id="CVE-2026-80557" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80557" source="CVE"/>
        <reference ref_id="CVE-2026-72113" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72113" source="CVE"/>
        <reference ref_id="CVE-2026-72066" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72066" source="CVE"/>
        <reference ref_id="CVE-2026-68183" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68183" source="CVE"/>
        <reference ref_id="CVE-2026-68250" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68250" source="CVE"/>
        <reference ref_id="CVE-2026-72242" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72242" source="CVE"/>
        <reference ref_id="CVE-2026-74497" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74497" source="CVE"/>
        <reference ref_id="CVE-2026-74632" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74632" source="CVE"/>
        <reference ref_id="CVE-2026-72023" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72023" source="CVE"/>
        <reference ref_id="CVE-2025-40054" ref_url="https://cve.tuxcare.com/els/cve/CVE-2025-40054" source="CVE"/>
        <reference ref_id="CVE-2026-72168" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72168" source="CVE"/>
        <reference ref_id="CVE-2026-74581" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74581" source="CVE"/>
        <reference ref_id="CVE-2026-74680" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74680" source="CVE"/>
        <reference ref_id="CVE-2026-74623" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74623" source="CVE"/>
        <reference ref_id="CVE-2026-80553" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80553" source="CVE"/>
        <reference ref_id="CVE-2026-74656" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74656" source="CVE"/>
        <reference ref_id="CVE-2026-68158" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68158" source="CVE"/>
        <reference ref_id="CVE-2026-74482" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74482" source="CVE"/>
        <reference ref_id="CVE-2026-74567" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74567" source="CVE"/>
        <reference ref_id="CVE-2026-68123" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68123" source="CVE"/>
        <reference ref_id="CVE-2026-68226" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68226" source="CVE"/>
        <reference ref_id="CVE-2026-64192" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64192" source="CVE"/>
        <reference ref_id="CVE-2026-68294" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68294" source="CVE"/>
        <reference ref_id="CVE-2026-72015" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72015" source="CVE"/>
        <reference ref_id="CVE-2026-72073" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72073" source="CVE"/>
        <reference ref_id="CVE-2026-74650" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74650" source="CVE"/>
        <reference ref_id="CVE-2026-64269" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64269" source="CVE"/>
        <reference ref_id="CVE-2026-74662" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74662" source="CVE"/>
        <reference ref_id="CVE-2026-74540" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74540" source="CVE"/>
        <reference ref_id="CVE-2026-74556" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74556" source="CVE"/>
        <reference ref_id="CVE-2026-80562" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80562" source="CVE"/>
        <reference ref_id="CVE-2026-64579" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64579" source="CVE"/>
        <reference ref_id="CVE-2026-64569" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64569" source="CVE"/>
        <reference ref_id="CVE-2026-68395" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68395" source="CVE"/>
        <reference ref_id="CVE-2026-68449" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68449" source="CVE"/>
        <reference ref_id="CVE-2026-68373" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68373" source="CVE"/>
        <reference ref_id="CVE-2026-72170" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72170" source="CVE"/>
        <reference ref_id="CVE-2026-64563" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64563" source="CVE"/>
        <reference ref_id="CVE-2026-72119" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72119" source="CVE"/>
        <reference ref_id="CVE-2026-74548" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74548" source="CVE"/>
        <reference ref_id="CVE-2026-74588" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74588" source="CVE"/>
        <reference ref_id="CVE-2026-74518" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74518" source="CVE"/>
        <reference ref_id="CVE-2026-74492" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74492" source="CVE"/>
        <reference ref_id="CVE-2026-64590" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-64590" source="CVE"/>
        <reference ref_id="CVE-2026-74673" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74673" source="CVE"/>
        <reference ref_id="CVE-2026-72308" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72308" source="CVE"/>
        <reference ref_id="CVE-2026-53090" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-53090" source="CVE"/>
        <reference ref_id="CVE-2026-68176" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68176" source="CVE"/>
        <reference ref_id="CVE-2026-80559" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80559" source="CVE"/>
        <reference ref_id="CVE-2026-68357" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68357" source="CVE"/>
        <reference ref_id="CVE-2026-68277" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68277" source="CVE"/>
        <reference ref_id="CVE-2026-80550" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-80550" source="CVE"/>
        <reference ref_id="CVE-2024-50125" ref_url="https://cve.tuxcare.com/els/cve/CVE-2024-50125" source="CVE"/>
        <reference ref_id="CVE-2026-74444" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74444" source="CVE"/>
        <reference ref_id="CVE-2026-72152" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72152" source="CVE"/>
        <reference ref_id="CVE-2026-74458" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-74458" source="CVE"/>
        <description>* Update to upstream stable Linux 5.10.269 (from 5.10.262).
   * Bump kernel ABI to 48: ship the ELS kernel as 5.10.0-48-*, distinct from
     the prior 5.10.0-47.
   * CVE-2024-40973
     - media: mtk-vcodec: potential null pointer deference in SCP
       {CVE-2024-40973}
   * CVE-2024-46754
     - bpf: Remove tst_run from lwt_seg6local_prog_ops. {CVE-2024-46754}
   * CVE-2024-50125
     - Bluetooth: SCO: Fix UAF on sco_sock_timeout {CVE-2024-50125}
   * CVE-2024-58094
     - jfs: add check read-only before truncation in
       jfs_truncate_nolock() {CVE-2024-58094}
   * CVE-2024-58095
     - jfs: add check read-only before txBeginAnon() call
       {CVE-2024-58095}
   * CVE-2024-58240
     - tls: separate no-async decryption request handling from async
       {CVE-2024-58240}
   * CVE-2025-23160
     - media: mediatek: vcodec: Fix a resource leak related to the scp
       device in FW initialization {CVE-2025-23160}
   * CVE-2025-38524
     - rxrpc: Fix recv-recv race of completed call {CVE-2025-38524}
   * CVE-2025-40054
     - f2fs: fix UAF issue in f2fs_merge_page_bio() {CVE-2025-40054}
   * CVE-2025-40102
     - KVM: arm64: Prevent access to vCPU events before init
       {CVE-2025-40102}
   * CVE-2025-68794
     - iomap: adjust read range correctly for non-block-aligned positions
       {CVE-2025-68794}
   * CVE-2026-31408
     - Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to
       missing sock_hold {CVE-2026-31408}
   * CVE-2026-31650
     - mmc: vub300: fix use-after-free on disconnect {CVE-2026-31650}
   * CVE-2026-43491
     - net: qrtr: ns: Limit the maximum server registration per node
       {CVE-2026-43491}
   * CVE-2026-45839
     - bpf: reject negative CO-RE accessor indices in
       bpf_core_parse_spec() {CVE-2026-45839}
   * CVE-2026-46003
     - net: qrtr: ns: Raise node count limit to 512 {CVE-2026-46003}
   * CVE-2026-46026
     - net: qrtr: ns: Raise lookup limit to 128 {CVE-2026-46026}
   * CVE-2026-53089
     - bpf: Fix use-after-free in offloaded map/prog info fill
       {CVE-2026-53089}
   * CVE-2026-53090
     - bpf: Fix ld_{abs,ind} failure path analysis in subprogs
       {CVE-2026-53090}
   * CVE-2026-53275
     - ipv6: mcast: Fix use-after-free when processing MLD queries
       {CVE-2026-53275}
   * CVE-2026-64048
     - net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot
       {CVE-2026-64048}
   * CVE-2026-64192
     - bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is
       uninitialized {CVE-2026-64192}
   * CVE-2026-64269
     - RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in
       rdma_write_sg {CVE-2026-64269}
   * CVE-2026-64270
     - Input: mms114 - reject an oversized device packet size
       {CVE-2026-64270}
   * CVE-2026-64280
     - fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
       {CVE-2026-64280}
   * CVE-2026-64336
     - USB: serial: keyspan_pda: fix information leak {CVE-2026-64336}
   * CVE-2026-64371
     - proc: Fix broken error paths for namespace links {CVE-2026-64371}
   * CVE-2026-64427
     - HID: logitech-dj: Fix maxfield check in DJ short report validation
       {CVE-2026-64427}
   * CVE-2026-64434
     - Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref
       {CVE-2026-64434}
     - Bluetooth: 6lowpan: Fix using chan-&gt;conn as indication to no
       remote netdev {CVE-2026-64434}
   * CVE-2026-64535
     - nvmet-tcp: Fix potential UAF when ddgst mismatch {CVE-2026-64535}
   * CVE-2026-64543
     - tipc: fix use-after-free of the discoverer in tipc_disc_rcv()
       {CVE-2026-64543}
   * CVE-2026-64562
     - KVM: nVMX: Hide shadow VMCS right after VMCLEAR {CVE-2026-64562}
   * CVE-2026-64563
     - rhashtable: clear stale iter-&gt;p on table restart {CVE-2026-64563}
   * CVE-2026-64565
     - Input: ims-pcu - fix heap-buffer-overflow in
       ims_pcu_process_data() {CVE-2026-64565}
     - Input: ims-pcu - fix logic error in packet reset {CVE-2026-64565}
   * CVE-2026-64567
     - btrfs: reject free space cache with more entries than pages
       {CVE-2026-64567}
   * CVE-2026-64569
     - mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
       {CVE-2026-64569}
   * CVE-2026-64571
     - wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
       {CVE-2026-64571}
   * CVE-2026-64572
     - ipv4: fib: free fib_alias with kfree_rcu() on insert error path
       {CVE-2026-64572}
   * CVE-2026-64579
     - xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild
       reinsert {CVE-2026-64579}
   * CVE-2026-64581
     - xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
       {CVE-2026-64581}
   * CVE-2026-64582
     - RDMA/rxe: Fix a use-after-free problem in rxe_mmap
       {CVE-2026-64582}
   * CVE-2026-64583
     - usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before
       teardown {CVE-2026-64583}
   * CVE-2026-64584
     - usb: gadget: f_midi: cancel pending IN work before freeing the
       midi object {CVE-2026-64584}
   * CVE-2026-64586
     - wifi: brcmfmac: drain bus_reset work on device removal
       {CVE-2026-64586}
   * CVE-2026-64590
     - dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST
       warning {CVE-2026-64590}
     - udmabuf: Ensure to perform cache synchronisation in
       begin_cpu_udmabuf() {CVE-2026-64590}
   * CVE-2026-68082
     - libceph: fix two unsafe bare decodes in decode_lockers()
       {CVE-2026-68082}
   * CVE-2026-68096
     - audit: fix recursive locking deadlock in audit_dupe_exe()
       {CVE-2026-68096}
   * CVE-2026-68104
     - drm/amdgpu: invoke pm_genpd_remove() before freeing genpd
       {CVE-2026-68104}
   * CVE-2026-68106
     - drm/amdgpu: fix division by zero with invalid uvd dimensions
       {CVE-2026-68106}
   * CVE-2026-68111
     - drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() {CVE-2026-68111}
   * CVE-2026-68115
     - drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() {CVE-2026-68115}
   * CVE-2026-68117
     - tipc: clear sock-&gt;sk on the failed-insert path in tipc_sk_create()
       {CVE-2026-68117}
   * CVE-2026-68121
     - pppoe: reload header pointer after dev_hard_header()
       {CVE-2026-68121}
   * CVE-2026-68123
     - openvswitch: fix GSO userspace truncation underflow
       {CVE-2026-68123}
   * CVE-2026-68125
     - mac802154: llsec: reject frames shorter than the authentication
       tag {CVE-2026-68125}
   * CVE-2026-68127
     - ila: reload IPv6 header after pskb_may_pull in checksum adjust
       {CVE-2026-68127}
   * CVE-2026-68131
     - rbd: Reset positive result codes to zero in object map update path
       {CVE-2026-68131}
   * CVE-2026-68132
     - super: fix emergency thaw deadlock on frozen block devices
       {CVE-2026-68132}
   * CVE-2026-68135
     - net: hip04: fix RX buffer leak on build_skb failure
       {CVE-2026-68135}
   * CVE-2026-68136
     - net: gro: fix double aggregation of flush-marked skbs
       {CVE-2026-68136}
   * CVE-2026-68137
     - net/x25: fix use-after-free in x25_kill_by_neigh()
       {CVE-2026-68137}
   * CVE-2026-68138
     - net/sched: serialize qdisc_rtab_list against concurrent get/put
       {CVE-2026-68138}
   * CVE-2026-68140
     - net/iucv: fix use-after-free of a severed iucv_path
       {CVE-2026-68140}
   * CVE-2026-68141
     - net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()
       {CVE-2026-68141}
   * CVE-2026-68142
     - geneve: require CAP_NET_ADMIN in the device netns for changelink
       {CVE-2026-68142}
   * CVE-2026-68143
     - net: slip: serialize receive against buffer reallocation
       {CVE-2026-68143}
   * CVE-2026-68144
     - phonet: pep: fix use-after-free in pep_get_sb() {CVE-2026-68144}
   * CVE-2026-68146
     - ftrace: Add global mutex to serialize trace_parser access
       {CVE-2026-68146}
   * CVE-2026-68151
     - binfmt_elf_fdpic: only honour the first PT_INTERP {CVE-2026-68151}
   * CVE-2026-68153
     - libceph: remove debugfs files before client teardown
       {CVE-2026-68153}
   * CVE-2026-68154
     - libceph: reject zero bucket types in crush_decode {CVE-2026-68154}
   * CVE-2026-68156
     - libceph: refresh auth-&gt;authorizer_buf{,_len} after authorizer
       update {CVE-2026-68156}
   * CVE-2026-68157
     - libceph: guard missing CRUSH type name lookup {CVE-2026-68157}
   * CVE-2026-68158
     - libceph: Fix multiplication overflow in
       decode_new_up_state_weight() {CVE-2026-68158}
   * CVE-2026-68159
     - libceph: bound pg_{temp,upmap,upmap_items} length to
       CEPH_PG_MAX_SIZE {CVE-2026-68159}
   * CVE-2026-68160
     - ceph: fix pre-auth out-of-bounds read on snaptrace in
       ceph_handle_caps() {CVE-2026-68160}
   * CVE-2026-68162
     - sctp: avoid auth_enable sysctl UAF during netns teardown
       {CVE-2026-68162}
   * CVE-2026-68175
     - tracing: Fix resource leak on mmiotrace trace_pipe close
       {CVE-2026-68175}
   * CVE-2026-68176
     - tracing: Fix mmiotrace possible NULL dereferencing of hiter-&gt;dev
       {CVE-2026-68176}
   * CVE-2026-68180
     - intel_th: fix MSC output device reference leak {CVE-2026-68180}
   * CVE-2026-68182
     - comedi: comedi_parport: deal with premature interrupt
       {CVE-2026-68182}
   * CVE-2026-68183
     - firmware: stratix10-svc: fix memory leaks and list corruption bugs
       {CVE-2026-68183}
   * CVE-2026-68184
     - cdrom: fix stack out-of-bounds read in CDROMVOLCTRL
       {CVE-2026-68184}
   * CVE-2026-68186
     - binfmt_misc: set have_execfd only once the interpreter is opened
       {CVE-2026-68186}
   * CVE-2026-68187
     - exec: fix unsigned loop counter wrap in transfer_args_to_stack()
       {CVE-2026-68187}
   * CVE-2026-68188
     - Bluetooth: RFCOMM: Fix session UAF in set_termios {CVE-2026-68188}
   * CVE-2026-68192
     - wifi: brcmfmac: make release_scratchbuffers idempotent
       {CVE-2026-68192}
   * CVE-2026-68195
     - wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses
       {CVE-2026-68195}
   * CVE-2026-68196
     - wifi: wilc1000: validate assoc response length before subtracting
       header {CVE-2026-68196}
   * CVE-2026-68197
     - wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no
       HT-oper {CVE-2026-68197}
   * CVE-2026-68198
     - wifi: ath6kl: fix use-after-free in aggr_reset_state()
       {CVE-2026-68198}
   * CVE-2026-68199
     - wifi: ath6kl: fix OOB access from firmware ADDBA window size
       {CVE-2026-68199}
   * CVE-2026-68202
     - ALSA: seq: close a re-opened queue timer in the destructor
       {CVE-2026-68202}
   * CVE-2026-68204
     - media: vivid: check for vb2_is_busy() when toggling caps
       {CVE-2026-68204}
   * CVE-2026-68205
     - media: v4l2-fwnode: Fix subdev owner overwritten in
       v4l2_async_register_subdev_sensor() {CVE-2026-68205}
   * CVE-2026-68209
     - media: sun4i-csi: Return queued buffers on start_streaming()
       failure {CVE-2026-68209}
   * CVE-2026-68212
     - media: saa7134: Fix a possible memory leak in saa7134_video_init1
       {CVE-2026-68212}
   * CVE-2026-68213
     - media: rtl2832_sdr: Return queued buffers on start_streaming()
       failure {CVE-2026-68213}
   * CVE-2026-68214
     - media: rtl2832: fix use-after-free in rtl2832_remove()
       {CVE-2026-68214}
   * CVE-2026-68215
     - media: radio-si476x: Unregister v4l2_device on probe failure
       {CVE-2026-68215}
   * CVE-2026-68216
     - media: pwc: Return queued buffers on start_streaming() failure
       {CVE-2026-68216}
   * CVE-2026-68217
     - media: pwc: Drain fill_buf on start_streaming() failure
       {CVE-2026-68217}
   * CVE-2026-68218
     - media: pci: dm1105: Free allocated workqueue {CVE-2026-68218}
   * CVE-2026-68222
     - media: msi2500: Return queued buffers on start_streaming() failure
       {CVE-2026-68222}
   * CVE-2026-68223
     - media: meson: vdec: Fix memory leak in error path of vdec_open
       {CVE-2026-68223}
   * CVE-2026-68226
     - media: cx23885: add ioremap return check and cleanup
       {CVE-2026-68226}
   * CVE-2026-68227
     - media: cx231xx: fix devres lifetime {CVE-2026-68227}
   * CVE-2026-68229
     - media: cedrus: skip invalid H.264 reference list entries
       {CVE-2026-68229}
   * CVE-2026-68231
     - media: airspy: Return queued buffers on start_streaming() failure
       {CVE-2026-68231}
   * CVE-2026-68234
     - drm/amdgpu: fix bo-&gt;pin leaking in amdgpu_bo_create_reserved
       {CVE-2026-68234}
   * CVE-2026-68249
     - drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()
       {CVE-2026-68249}
   * CVE-2026-68250
     - drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()
       {CVE-2026-68250}
   * CVE-2026-68255
     - drm/virtio: bound EDID block reads to the response buffer
       {CVE-2026-68255}
   * CVE-2026-68277
     - drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply
       parsers {CVE-2026-68277}
   * CVE-2026-68278
     - drm/dp/mst: fix buffer overflows in sideband chunk accumulation
       {CVE-2026-68278}
   * CVE-2026-68279
     - drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply
       parsers {CVE-2026-68279}
   * CVE-2026-68284
     - bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()
       {CVE-2026-68284}
   * CVE-2026-68294
     - net: qrtr: restrict socket creation to the initial network
       namespace {CVE-2026-68294}
   * CVE-2026-68297
     - tipc: fix u16 MTU truncation in media and bearer MTU validation
       {CVE-2026-68297}
   * CVE-2026-68299
     - vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
       {CVE-2026-68299}
   * CVE-2026-68300
     - sctp: auth: verify auth requirement when auth_chunk is NULL
       {CVE-2026-68300}
   * CVE-2026-68304
     - wifi: brcmfmac: fix 802.1X-SHA256 call trace warning
       {CVE-2026-68304}
   * CVE-2026-68313
     - tipc: fix infinite loop in __tipc_nl_compat_dumpit
       {CVE-2026-68313}
   * CVE-2026-68315
     - sctp: validate stream count in sctp_process_strreset_inreq()
       {CVE-2026-68315}
   * CVE-2026-68320
     - sctp: fix auth_chunk_list capacity check in
       sctp_auth_ep_add_chunkid {CVE-2026-68320}
   * CVE-2026-68322
     - rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled
       {CVE-2026-68322}
   * CVE-2026-68325
     - iommu/amd: Bound the early ACPI HID map {CVE-2026-68325}
   * CVE-2026-68326
     - wifi: mwifiex: bound uAP association event IEs to the event buffer
       {CVE-2026-68326}
   * CVE-2026-68327
     - wan: wanxl: Only reset hardware after BAR mapping {CVE-2026-68327}
   * CVE-2026-68328
     - nfp: Check resource mutex allocation {CVE-2026-68328}
   * CVE-2026-68335
     - rds: drop incoming messages that cross network namespace
       boundaries {CVE-2026-68335}
   * CVE-2026-68338
     - net/packet: avoid fanout hook re-registration after unregister
       {CVE-2026-68338}
   * CVE-2026-68344
     - usb: atm: ueagle-atm: reject descriptors that confuse probe and
       disconnect {CVE-2026-68344}
   * CVE-2026-68349
     - wifi: carl9170: fix buffer overflow in rx_stream failover path
       {CVE-2026-68349}
   * CVE-2026-68350
     - wifi: carl9170: fix OOB read from off-by-two in TX status handler
       {CVE-2026-68350}
   * CVE-2026-68351
     - wifi: carl9170: bound memcpy length in cmd callback to prevent OOB
       read {CVE-2026-68351}
   * CVE-2026-68352
     - wifi: ath6kl: fix OOB read from firmware IE lengths in connect
       event {CVE-2026-68352}
   * CVE-2026-68353
     - wifi: ath6kl: fix OOB read from firmware num_msg in TX complete
       handler {CVE-2026-68353}
   * CVE-2026-68354
     - firewire: net: Fix fragmented datagram reassembly {CVE-2026-68354}
   * CVE-2026-68355
     - wifi: ath11k: fix potential buffer underflow in
       ath11k_hal_rx_msdu_list_get() {CVE-2026-68355}
   * CVE-2026-68357
     - watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()
       {CVE-2026-68357}
   * CVE-2026-68360
     - hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
       {CVE-2026-68360}
   * CVE-2026-68363
     - wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming
       firmware request {CVE-2026-68363}
   * CVE-2026-68365
     - USB: serial: io_edgeport: cap received transmit credits
       {CVE-2026-68365}
   * CVE-2026-68366
     - usb: gadget: uvc: clamp SEND_RESPONSE length to the response
       buffer {CVE-2026-68366}
   * CVE-2026-68367
     - usb: gadget: f_tcm: synchronize delayed set_alt with teardown
       {CVE-2026-68367}
   * CVE-2026-68368
     - usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
       {CVE-2026-68368}
   * CVE-2026-68369
     - usb: gadget: printer: fix infinite loop in printer_read()
       {CVE-2026-68369}
   * CVE-2026-68370
     - usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback
       {CVE-2026-68370}
   * CVE-2026-68373
     - wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
       {CVE-2026-68373}
   * CVE-2026-68376
     - sctp: fix auth_hmacs array size in struct sctp_cookie
       {CVE-2026-68376}
   * CVE-2026-68377
     - net/sched: act_tunnel_key: Defer dst_release to RCU callback
       {CVE-2026-68377}
   * CVE-2026-68388
     - smb/client: handle overlapping allocated ranges in fallocate
       {CVE-2026-68388}
   * CVE-2026-68395
     - ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler
       is registered {CVE-2026-68395}
   * CVE-2026-68397
     - net/iucv: take a reference on the socket found in afiucv_hs_rcv()
       {CVE-2026-68397}
   * CVE-2026-68402
     - wifi: cfg80211: bound element ID read when checking
       non-inheritance {CVE-2026-68402}
   * CVE-2026-68403
     - wifi: brcmfmac: initialize SDIO data work before cleanup
       {CVE-2026-68403}
   * CVE-2026-68405
     - wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock
       {CVE-2026-68405}
   * CVE-2026-68406
     - wifi: cfg80211: validate PMSR FTM preamble range {CVE-2026-68406}
   * CVE-2026-68410
     - wifi: libertas: fix memory leak in helper_firmware_cb()
       {CVE-2026-68410}
   * CVE-2026-68411
     - wifi: mac80211_hwsim: clamp virtio RX length before skb_put
       {CVE-2026-68411}
   * CVE-2026-68413
     - wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
       {CVE-2026-68413}
   * CVE-2026-68425
     - IB/mad: Drop unmatched RMPP responses before reassembly
       {CVE-2026-68425}
   * CVE-2026-68428
     - KVM: x86/mmu: Fix use-after-free on vendor module reload
       {CVE-2026-68428}
   * CVE-2026-68430
     - drm/amdgpu/gfx8: drop unecessary BUG_ON() {CVE-2026-68430}
   * CVE-2026-68432
     - vxlan: require CAP_NET_ADMIN in the device netns for changelink
       {CVE-2026-68432}
   * CVE-2026-68433
     - libceph: bound get_version reply decode to front len
       {CVE-2026-68433}
   * CVE-2026-68434
     - serial: 8250_mid: Fix NULL function pointer dereference on
       DNV/ICX-D/SNR platforms {CVE-2026-68434}
   * CVE-2026-68446
     - drm/vmwgfx: Validate vmw_surface_metadata::array_size
       {CVE-2026-68446}
   * CVE-2026-68449
     - ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion
       bit-scanning {CVE-2026-68449}
   * CVE-2026-68451
     - s390/zcrypt: Validate length for CCA ECC private key requests
       {CVE-2026-68451}
   * CVE-2026-68452
     - s390/zcrypt: Validate length for CCA AES cipher key requests
       {CVE-2026-68452}
   * CVE-2026-68476
     - ipvs: reload ip header after head reallocation {CVE-2026-68476}
   * CVE-2026-68480
     - x86/bugs: Make Safe-RET robust against interrupt injection
       {CVE-2026-68480}
   * CVE-2026-72015
     - fs/resctrl: Fix double-add of pseudo-locked region's RMID to free
       list {CVE-2026-72015}
   * CVE-2026-72019
     - macsec: don't read an unset MAC header in macsec_encrypt()
       {CVE-2026-72019}
   * CVE-2026-72023
     - octeontx2-pf: fix SQB pointer leak on init failure
       {CVE-2026-72023}
   * CVE-2026-72035
     - net/sched: sch_taprio: Replace direct dequeue call with peek and
       qdisc_dequeue_peeked {CVE-2026-72035}
   * CVE-2026-72041
     - espintcp: use sk_msg_free_partial to fix partial send
       {CVE-2026-72041}
   * CVE-2026-72051
     - net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for
       changelink {CVE-2026-72051}
   * CVE-2026-72053
     - net: ipip: require CAP_NET_ADMIN in the device netns for
       changelink {CVE-2026-72053}
   * CVE-2026-72063
     - gpio: tegra: do not call pinctrl for GPIO direction
       {CVE-2026-72063}
   * CVE-2026-72066
     - cpu: hotplug: Bound hotplug states sysfs output {CVE-2026-72066}
   * CVE-2026-72070
     - wifi: libertas_tf: fix use-after-free in lbtf_free_adapter()
       {CVE-2026-72070}
   * CVE-2026-72073
     - mmc: vub300: fix use-after-free on probe failure {CVE-2026-72073}
   * CVE-2026-72075
     - Input: ims-pcu - fix race condition in reset_device sysfs callback
       {CVE-2026-72075}
   * CVE-2026-72077
     - Input: ims-pcu - fix firmware leak in async update
       {CVE-2026-72077}
   * CVE-2026-72084
     - scsi: target: Bound PR-OUT TransportID parsing to the received
       buffer {CVE-2026-72084}
   * CVE-2026-72087
     - scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup()
       {CVE-2026-72087}
   * CVE-2026-72096
     - dm-verity: make error counter atomic {CVE-2026-72096}
   * CVE-2026-72099
     - dm-integrity: don't increment hash_offset twice {CVE-2026-72099}
   * CVE-2026-72113
     - can: bcm: add missing device refcount for CAN filter removal
       {CVE-2026-72113}
   * CVE-2026-72114
     - can: bcm: validate frame length in bcm_rx_setup() for RTR replies
       {CVE-2026-72114}
   * CVE-2026-72115
     - can: bcm: track a single source interface for ANYDEV
       timeout/throttle ops {CVE-2026-72115}
   * CVE-2026-72116
     - can: bcm: fix stale rx/tx ops after device removal
       {CVE-2026-72116}
   * CVE-2026-72117
     - can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()
       {CVE-2026-72117}
   * CVE-2026-72118
     - can: bcm: fix CAN frame rx/tx statistics {CVE-2026-72118}
   * CVE-2026-72119
     - can: bcm: extend bcm_tx_lock usage for data and timer updates
       {CVE-2026-72119}
   * CVE-2026-72121
     - can: bcm: add locking when updating filter and timer values
       {CVE-2026-72121}
   * CVE-2026-72123
     - can: bcm: defer rx_op deallocation to workqueue to fix thrtimer
       UAF {CVE-2026-72123}
   * CVE-2026-72124
     - can: isotp: serialize TX state transitions under so-&gt;rx_lock
       {CVE-2026-72124}
     - can: isotp: fix timer drain order, wakeup handling and tx_gen
       ordering {CVE-2026-72124}
   * CVE-2026-72125
     - can: isotp: fix use-after-free race with concurrent
       NETDEV_UNREGISTER {CVE-2026-72125}
   * CVE-2026-72142
     - i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)
       {CVE-2026-72142}
   * CVE-2026-72148
     - dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and
       ABORT_INT_MASK {CVE-2026-72148}
   * CVE-2026-72152
     - tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat()
       {CVE-2026-72152}
   * CVE-2026-72155
     - mtd: spi-nor: swp: Improve locking user experience
       {CVE-2026-72155}
   * CVE-2026-72157
     - net: thunderbolt: Fix frags[] overflow by bounding frame_count
       {CVE-2026-72157}
   * CVE-2026-72166
     - net/9p: fix infinite loop in p9_client_rpc on fatal signal
       {CVE-2026-72166}
   * CVE-2026-72168
     - mtd: maps: vmu-flash: fix fault in unaligned fixup
       {CVE-2026-72168}
   * CVE-2026-72170
     - 9p: skip nlink update in cacheless mode to fix WARN_ON
       {CVE-2026-72170}
   * CVE-2026-72181
     - mips: sched: Fix CPUMASK_OFFSTACK memory corruption
       {CVE-2026-72181}
   * CVE-2026-72225
     - jbd2: fix integer underflow in
       jbd2_journal_initialize_fast_commit() {CVE-2026-72225}
   * CVE-2026-72242
     - selinux: avoid sk_socket dereference in
       selinux_sctp_bind_connect() {CVE-2026-72242}
   * CVE-2026-72253
     - netfilter: nf_conntrack_sip: validate skb_dst() before accessing
       it {CVE-2026-72253}
   * CVE-2026-72299
     - tipc: restrict socket queue dumps in enqueue tracepoints
       {CVE-2026-72299}
   * CVE-2026-72308
     - mlxsw: fix refcount leak in mlxsw_sp_port_lag_join()
       {CVE-2026-72308}
   * CVE-2026-72323
     - ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
       {CVE-2026-72323}
   * CVE-2026-72392
     - ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch
       dump {CVE-2026-72392}
   * CVE-2026-74436
     - rxrpc: serialize kernel accept preallocation with socket teardown
       {CVE-2026-74436}
   * CVE-2026-74443
     - drm/vmwgfx: bound DMA command body size against suffix pointer
       {CVE-2026-74443}
   * CVE-2026-74444
     - drm/vmwgfx: validate DRAW_PRIMITIVES header size before division
       {CVE-2026-74444}
   * CVE-2026-74453
     - drm/vc4: Zero the tile state data array before each BIN job
       {CVE-2026-74453}
   * CVE-2026-74455
     - can: peak_usb: validate uCAN receive record lengths
       {CVE-2026-74455}
   * CVE-2026-74456
     - can: peak_usb: peak_usb_start(): fix double free of transfer
       buffer on URB submit error {CVE-2026-74456}
   * CVE-2026-74457
     - can: peak_usb: add bounds check for USB channel index
       {CVE-2026-74457}
   * CVE-2026-74458
     - can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate
       received command extents {CVE-2026-74458}
   * CVE-2026-74463
     - i2c: jz4780: Cache host clock rate at probe to prevent CCF
       prepare_lock deadlock {CVE-2026-74463}
   * CVE-2026-74464
     - net: openvswitch: fix skb leak on flow key update failure during
       ct {CVE-2026-74464}
   * CVE-2026-74465
     - net: openvswitch: fix potential UAF on meter attach failure
       {CVE-2026-74465}
   * CVE-2026-74468
     - gpio: pch: use raw_spinlock_t for the register lock
       {CVE-2026-74468}
   * CVE-2026-74469
     - sctp: prevent peer transport count overflow {CVE-2026-74469}
   * CVE-2026-74470
     - scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write
       {CVE-2026-74470}
   * CVE-2026-74471
     - tracing: Check return value of __register_event() in
       trace_module_add_events() {CVE-2026-74471}
   * CVE-2026-74473
     - vxlan: use pskb_network_may_pull() in route_shortcircuit()
       {CVE-2026-74473}
   * CVE-2026-74475
     - vxlan: use neigh_ha_snapshot() in route_shortcircuit()
       {CVE-2026-74475}
   * CVE-2026-74478
     - um: vector: fix use-after-free in vector_mmsg_rx()
       {CVE-2026-74478}
   * CVE-2026-74479
     - net: pktgen: fix proc entry use-after-free {CVE-2026-74479}
   * CVE-2026-74480
     - net: bridge: stop fast-leave after deleting a port group
       {CVE-2026-74480}
   * CVE-2026-74481
     - mm/page_reporting: use system_freezable_wq to fix UAF during
       suspend {CVE-2026-74481}
   * CVE-2026-74482
     - mm/huge_memory: unlock i_mmap_rwsem before releasing after-split
       folios {CVE-2026-74482}
   * CVE-2026-74485
     - binfmt_misc: reject a flag character as the field delimiter
       {CVE-2026-74485}
   * CVE-2026-74486
     - binfmt_misc: use exe_file_deny_write_access() for the interpreter
       clone {CVE-2026-74486}
   * CVE-2026-74487
     - binfmt_misc: restore write access when removing an entry
       {CVE-2026-74487}
   * CVE-2026-74488
     - wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS
       frames {CVE-2026-74488}
   * CVE-2026-74490
     - tipc: avoid use-after-free in poll trace queue dumps
       {CVE-2026-74490}
   * CVE-2026-74492
     - netfilter: ipset: do not update comments from kernel-side hash
       adds {CVE-2026-74492}
   * CVE-2026-74493
     - net/smc: fix socket use-after-free during link group termination
       {CVE-2026-74493}
   * CVE-2026-74495
     - igbvf: Fix leak in TX DMA error cleanup {CVE-2026-74495}
   * CVE-2026-74497
     - ALSA: usb-audio: Clamp frame size in implicit-feedback mode
       {CVE-2026-74497}
   * CVE-2026-74498
     - ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max
       is set {CVE-2026-74498}
   * CVE-2026-74499
     - ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()
       {CVE-2026-74499}
   * CVE-2026-74505
     - ALSA: 6fire: Fix UAF at error handling during probe
       {CVE-2026-74505}
   * CVE-2026-74507
     - Bluetooth: HIDP: validate numbered report payloads
       {CVE-2026-74507}
   * CVE-2026-74508
     - Bluetooth: HIDP: reject frames without a transaction header
       {CVE-2026-74508}
   * CVE-2026-74512
     - audit: fix potential use-after-free in audit_del_rule()
       {CVE-2026-74512}
   * CVE-2026-74518
     - mm/hugetlb: fix list corruption in allocate_file_region_entries()
       {CVE-2026-74518}
   * CVE-2026-74519
     - pinctrl: devicetree: don't free uninitialized dev_name on error
       path {CVE-2026-74519}
   * CVE-2026-74523
     - qede: sync udp_tunnel ports outside qede_lock in the recovery path
       {CVE-2026-74523}
   * CVE-2026-74525
     - net: sxgbe: free TX rings on RX allocation failure
       {CVE-2026-74525}
   * CVE-2026-74540
     - Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp {CVE-2026-74540}
   * CVE-2026-74547
     - hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread
       {CVE-2026-74547}
   * CVE-2026-74548
     - forcedeth: fix UAF of txrx_stats in nv_remove {CVE-2026-74548}
   * CVE-2026-74549
     - hwmon: (nct6775-core) Prevent access to unsupported weight
       registers {CVE-2026-74549}
   * CVE-2026-74556
     - scsi: libiscsi_tcp: Bound SCSI Response data segment to the
       connection buffer {CVE-2026-74556}
   * CVE-2026-74557
     - scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer
       {CVE-2026-74557}
   * CVE-2026-74563
     - rds: tcp: hold the RCU lock across ipv6_chk_addr() in
       rds_tcp_laddr_check() {CVE-2026-74563}
   * CVE-2026-74564
     - netfilter: xt_hashlimit: validate hashtable supports
       XT_HASHLIMIT_RATE_MATCH {CVE-2026-74564}
   * CVE-2026-74566
     - keys: make keyring key-chunk byte order agree with
       keyring_diff_objects() {CVE-2026-74566}
   * CVE-2026-74567
     - keys: fix out-of-bounds read in keyring_get_key_chunk()
       {CVE-2026-74567}
   * CVE-2026-74569
     - netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in
       sip_help_tcp() {CVE-2026-74569}
   * CVE-2026-74575
     - thunderbolt: Prevent XDomain delayed work use-after-free on
       disconnect {CVE-2026-74575}
   * CVE-2026-74577
     - net: mpls: initialize rtm_tos in mpls_getroute() {CVE-2026-74577}
   * CVE-2026-74579
     - netfilter: nft_payload: fix mask build for partial field offload
       {CVE-2026-74579}
   * CVE-2026-74580
     - vhost: reset the vring metadata cache on vring reconfiguration
       {CVE-2026-74580}
   * CVE-2026-74581
     - net: ipv6: clear suppressed fib6 rule result {CVE-2026-74581}
   * CVE-2026-74582
     - packet: use consistent hard_header_len in non-ring send paths
       {CVE-2026-74582}
   * CVE-2026-74583
     - net/sched: cls_route: fix fastmap use-after-free on filter
       {CVE-2026-74583}
   * CVE-2026-74585
     - thunderbolt: Bound the DROM dual link port number before indexing
       sw-&gt;ports {CVE-2026-74585}
   * CVE-2026-74586
     - sctp: clear new_transport when removing a peer {CVE-2026-74586}
   * CVE-2026-74587
     - sctp: fix use-after-free of cached ASCONF chunk {CVE-2026-74587}
   * CVE-2026-74588
     - sctp: keep chunk-&gt;transport in step with the list it is queued on
       {CVE-2026-74588}
   * CVE-2026-74589
     - bpf, sockmap: Fix sk_redir use-after-free in send verdict
       {CVE-2026-74589}
   * CVE-2026-74594
     - sched/psi: Shut down rtpoll_timer in psi_cgroup_free()
       {CVE-2026-74594}
   * CVE-2026-74597
     - ip6_tunnel: clear skb2-&gt;cb[] in ip6ip6_err() {CVE-2026-74597}
   * CVE-2026-74598
     - ipv6: fix Route Information option length validation
       {CVE-2026-74598}
   * CVE-2026-74599
     - mm/ptdump: always stabilise against page table freeing using
       init_mm {CVE-2026-74599}
   * CVE-2026-74601
     - ring-buffer: Use current_context for safe per-CPU buffer swap
       {CVE-2026-74601}
   * CVE-2026-74609
     - tipc: read le-&gt;link under the node lock in tipc_node_link_down()
       {CVE-2026-74609}
   * CVE-2026-74613
     - vsock/virtio: avoid refilling the RX queue after teardown
       {CVE-2026-74613}
   * CVE-2026-74615
     - vxlan: do not arm the ageing timer on a device that is down
       {CVE-2026-74615}
   * CVE-2026-74620
     - net/sched: act_gact, act_police: range check the fallback control
       action {CVE-2026-74620}
   * CVE-2026-74622
     - net: atlantic: free RX pages of consumed but not refilled buffers
       {CVE-2026-74622}
   * CVE-2026-74623
     - net: atlantic: free stranded TX buffers on ring deinit
       {CVE-2026-74623}
   * CVE-2026-74625
     - netfilter: bridge: release template ct on non-IP path
       {CVE-2026-74625}
   * CVE-2026-74626
     - NTB: ntb_netdev: Preserve RX queue depth on allocation failure
       {CVE-2026-74626}
   * CVE-2026-74628
     - net/x25: fix use-after-free of the socket by its timers
       {CVE-2026-74628}
   * CVE-2026-74630
     - ipv6: prevent in6_dev_get() from resurrecting inet6_dev
       {CVE-2026-74630}
   * CVE-2026-74631
     - net: smc: fix splice entry lifetime imbalance in smc_rx_splice
       {CVE-2026-74631}
   * CVE-2026-74632
     - mm/huge_memory: fix huge_zero_pfn race {CVE-2026-74632}
   * CVE-2026-74635
     - fbdev: bitblit: bound-check glyph index in bit_cursor()
       {CVE-2026-74635}
   * CVE-2026-74637
     - perf/core: Fix group leader use-after-free after sibling detach
       {CVE-2026-74637}
   * CVE-2026-74641
     - ALSA: usx2y: bound the hwdep mmap fault offset {CVE-2026-74641}
   * CVE-2026-74647
     - misc: fastrpc: Remove buffer from list prior to unmap operation
       {CVE-2026-74647}
   * CVE-2026-74648
     - staging: rtl8723bs: validate monitor transmit frame lengths
       {CVE-2026-74648}
   * CVE-2026-74650
     - staging: rtl8723bs: fix OOB read in WMM_param_handler()
       {CVE-2026-74650}
   * CVE-2026-74651
     - staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie()
       {CVE-2026-74651}
   * CVE-2026-74654
     - serial: 8250_dma: Clear stale RX state on shutdown
       {CVE-2026-74654}
   * CVE-2026-74656
     - ipv4: fix use-after-free in fib_nhc_update_mtu() {CVE-2026-74656}
   * CVE-2026-74657
     - ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops {CVE-2026-74657}
   * CVE-2026-74658
     - futex: Prevent robust futex exit race some more {CVE-2026-74658}
   * CVE-2026-74660
     - netfilter: ebt_nflog: pin the NFLOG backend {CVE-2026-74660}
   * CVE-2026-74662
     - inet: frags: publish queues before arming timer {CVE-2026-74662}
   * CVE-2026-74663
     - net/sched: reject overly deep qdisc hierarchies {CVE-2026-74663}
   * CVE-2026-74664
     - net: openvswitch: reallocate update replies for mismatched IDs
       {CVE-2026-74664}
   * CVE-2026-74666
     - packet: synchronize pressure clearing with ring reconfiguration
       {CVE-2026-74666}
   * CVE-2026-74667
     - net/packet: reset the MAC header on the packet-socket transmit
       path {CVE-2026-74667}
   * CVE-2026-74668
     - packet: use consistent hard_header_len in TX_RING send path
       {CVE-2026-74668}
   * CVE-2026-74669
     - ipvs: clear IPv4 options after rebasing tunnel ICMP errors
       {CVE-2026-74669}
   * CVE-2026-74671
     - ima: fix out-of-bounds read in xattr_verify() {CVE-2026-74671}
   * CVE-2026-74673
     - Input: evdev - fix information leak in evdev_pass_values()
       {CVE-2026-74673}
   * CVE-2026-74675
     - vt: stabilize tty reference in kbd_keycode with tty_port_tty_get
       {CVE-2026-74675}
   * CVE-2026-74676
     - vt: add permission check for KDSKBMETA ioctl {CVE-2026-74676}
   * CVE-2026-74679
     - usb: gadget: f_ncm: Use unsigned int for ndp_index
       {CVE-2026-74679}
   * CVE-2026-74680
     - usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()
       {CVE-2026-74680}
   * CVE-2026-74682
     - ALSA: usb-audio: fix OOB write on Type II inbound URBs
       {CVE-2026-74682}
   * CVE-2026-74683
     - Input: evdev - sanitize event type index when fetching event masks
       {CVE-2026-74683}
   * CVE-2026-74688
     - sctp: clear control chunk transport if it is being removed
       {CVE-2026-74688}
   * CVE-2026-74693
     - net: prestera: validate firmware header length {CVE-2026-74693}
   * CVE-2026-74694
     - net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length
       {CVE-2026-74694}
   * CVE-2026-74697
     - bnxt_en: Disable EOP for TPA on all chips to prevent data
       corruption {CVE-2026-74697}
   * CVE-2026-74701
     - net/openvswitch: check Ethernet header length in key_extract()
       {CVE-2026-74701}
   * CVE-2026-74704
     - net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK
       filter {CVE-2026-74704}
   * CVE-2026-74705
     - udp: fix potential use-after-free in tunnel segmentation
       {CVE-2026-74705}
   * CVE-2026-74717
     - net/mlx5: fw_tracer, return NULL on create error {CVE-2026-74717}
   * CVE-2026-74719
     - net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT
       in smc_llc_event_handler() {CVE-2026-74719}
   * CVE-2026-74720
     - bpf: Preserve pointer state for commuted arithmetic
       {CVE-2026-74720}
   * CVE-2026-74726
     - bonding: alb: re-check primary_is_promisc under RTNL in
       bond_alb_monitor {CVE-2026-74726}
   * CVE-2026-74730
     - NFS: Pin the 'struct nfs_server' during a FREE_STATEID call
       {CVE-2026-74730}
   * CVE-2026-74737
     - net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC
       TAG {CVE-2026-74737}
   * CVE-2026-74746
     - netfilter: flowtable: publish GC-visible tuple last
       {CVE-2026-74746}
   * CVE-2026-74748
     - netfilter: ipset: fix refcount race between list:set GC and swap
       {CVE-2026-74748}
   * CVE-2026-80527
     - ceph: fix hanging __ceph_get_caps() with stale mds_wanted
       {CVE-2026-80527}
   * CVE-2026-80528
     - ceph: avoid fs reclaim while using current-&gt;journal_info
       {CVE-2026-80528}
   * CVE-2026-80534
     - xfs: fix ilock leak on error in xfs_dq_get_next_id
       {CVE-2026-80534}
   * CVE-2026-80536
     - xfs: bounds-check buffer log item's dirty bitmap {CVE-2026-80536}
   * CVE-2026-80540
     - drm/amdgpu: Fix UVD decode image min size calculation
       {CVE-2026-80540}
   * CVE-2026-80541
     - drm/amdgpu: validate GEM_CREATE domain combinations
       {CVE-2026-80541}
   * CVE-2026-80550
     - s390/vfio_ccw: Fix out of bounds check on CCW array
       {CVE-2026-80550}
   * CVE-2026-80553
     - s390/vfio_ccw: Cancel existing workqueues {CVE-2026-80553}
   * CVE-2026-80555
     - s390/vfio_ccw: Free all memory if cp_init() fails {CVE-2026-80555}
   * CVE-2026-80557
     - libceph: fix OOB read in decode_watchers() via missing bounds
       check {CVE-2026-80557}
   * CVE-2026-80558
     - libceph: Avoid using invalid osd indices from primary_temp
       {CVE-2026-80558}
   * CVE-2026-80559
     - Input: sur40 - fix input device registration ordering
       {CVE-2026-80559}
   * CVE-2026-80560
     - openrisc: signal: do not restore privileged SR bits on sigreturn
       {CVE-2026-80560}
   * CVE-2026-80561
     - libceph: fix multiple unsafe decodes in decode_locker()
       {CVE-2026-80561}
   * CVE-2026-80562
     - gpio: ml-ioh: use raw_spinlock_t for the register lock
       {CVE-2026-80562}
   * CVE-2026-80565
     - crypto: qce - fix error path in devm_qce_register_algs
       {CVE-2026-80565}
   * CVE-2026-80567
     - Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue
       {CVE-2026-80567}
   * CVE-2026-80568
     - Input: synaptics-rmi4 - block s_input when F54 queue is busy
       {CVE-2026-80568}
   * CVE-2026-80569
     - Input: synaptics-rmi4 - bound the F54 report size to the allocated
       buffer {CVE-2026-80569}
   * CVE-2026-80570
     - Input: synaptics-rmi4 - zero report size on F54 work error
       {CVE-2026-80570}
   * CVE-2026-80573
     - Input: iforce - validate input packet lengths {CVE-2026-80573}
   * CVE-2026-80574
     - Input: focaltech - fix array out-of-bounds in
       focaltech_process_rel_packet {CVE-2026-80574}
   * CVE-2026-80584
     - s390/qeth: validate user buffer length in SNMP and ARP query
       ioctls {CVE-2026-80584}
   * CVE-2026-80586
     - mptcp: options: reset DSS fields in case of unexpected size
       {CVE-2026-80586}
   * CVE-2026-80590
     - inet: frags: strip GSO state from fragments before reassembly
       {CVE-2026-80590}
   * CVE-2026-80679
     - s390/dasd: Fix potential NULL pointer dereference {CVE-2026-80679}
   * CVE-2026-80680
     - i2c: amd-mp2: Unregister callback on adapter add failure
       {CVE-2026-80680}
   * CVE-2026-80681
     - vxlan: re-fetch eth header after route_shortcircuit()
       {CVE-2026-80681}
   * CVE-2026-80706
     - can: softing: fw_parse(): validate firmware record spans
       {CVE-2026-80706}
   * CVE-2026-80707
     - can: j1939: transport: j1939_session_fresh_new(): initialize
       receive buffer {CVE-2026-80707}
   * CVE-2026-80708
     - s390/zcrypt: Fix missing mem scrub at clear key import in
       cca_clr2cipherkey() {CVE-2026-80708}
   * CVE-2026-80714
     - ipvs: do not propagate one-packet flag to synced conns
       {CVE-2026-80714}
   * CVE-2026-80716
     - ALSA: pcm: wake linked drain waiters on unlink {CVE-2026-80716}
   * CVE-2026-80717
     - sctp: validate Adaptation Indication parameter length
       {CVE-2026-80717}
   * CVE-2026-80718
     - mm/percpu-km: fix bitmap overflow and accounting in
       pcpu_create_chunk() {CVE-2026-80718}
   * CVE-2026-80731
     - net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header
       {CVE-2026-80731}
   * CVE-2026-80732
     - ata: pata_sl82c105: fix bridge revision use-after-free
       {CVE-2026-80732}
   * CVE-2026-80733
     - net: remove WARN_ON_ONCE() from sk_mc_loop() {CVE-2026-80733}
   * CVE-2026-80737
     - serial: amba-pl011: synchronize DMA teardown {CVE-2026-80737}
   * CVE-2026-80742
     - af_packet: Don't send zero-byte data in tpacket_snd().
       {CVE-2026-80742}
   * CVE-2026-80743
     - ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers
       {CVE-2026-80743}
   * CVE-2026-80744
     - netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in
       abort path {CVE-2026-80744}
   * CVE-2026-80752
     - Input: psxpad-spi - set driver data before use {CVE-2026-80752}
   * CVE-2026-80754
     - Input: synaptics-rmi4 - fix F55 transmitter electrode count typo
       {CVE-2026-80754}
   * CVE-2026-80756
     - selinux: do not cancel a policy conversion that never started
       {CVE-2026-80756}
   * CVE-2026-80757
     - selinux: reject a class permission count below its inherited
       common {CVE-2026-80757}
   * Miscellaneous upstream changes
     - debian: build a version-unique source package (source format 1.0)
     - Linux 5.10.263
     - Revert "x86/bugs: Make Safe-RET robust against interrupt
       injection"
     - x86/bugs: Make Safe-RET robust against interrupt injection
     - Linux 5.10.264
     - KVM: VMX: Make vmread_error_trampoline() uncallable from C code
     - mtd: mtdswap: remove debugfs stats file on teardown
     - mtd: nand: mtk-ecc: stop on ECC idle timeouts
     - btrfs: remove crc_check logic from free space
     - RDMA/hns: Fix potential integer overflow in mhop hem cleanup
     - mac80211_hwsim: add 6GHz channels
     - wifi: cfg80211: validate PMSR measurement type data
     - wifi: cfg80211: reject unsupported PMSR FTM location requests
     - ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on
       start/stop
     - ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared
       after lookup
     - firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context
     - ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all
       pending interrupts
     - ata: sata_dwc_460ex: remove variable num_processed
     - drm/i915/gt: use correct selftest config symbol
     - can: j1939: fix lockless local-destination check
     - drm/i915/selftests: Fix GT PM sort comparators
     - USB: storage: add NO_ATA_1X quirk for Longmai USB Key
     - usb: chipidea: fix usage_count leak when autosuspend_delay is
       negative
     - USB: gadget: snps-udc: fix device name leak on probe failure
     - USB: gadget: fsl-udc: fix device name leak on probe failure
     - USB: serial: ftdi_sio: add support for E+H FXA291
     - USB: serial: option: add TDTECH MT5710-CN
     - crypto: rsa-pkcs1pad: Don't WARN on an empty digest
     - usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits
     - ASoC: bt-sco: fix bt-sco-pcm-wb dai widget don't connect to the
       endpoint
     - ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI
     - wifi: mac80211: recalculate TIM when a station enters power save
     - amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN
     - net: bridge: vlan: add support for global options
     - net: bridge: vlan: add support for dumping global vlan options
     - net: bridge: vlan: fix vlan range dumps starting with pvid
     - net: stmmac: reset residual action in L3L4 filters on delete
     - ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup
     - hinic: remove unused ethtool RSS user configuration buffers
     - net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule
     - net/mlx5e: Report zero bandwidth for non-ETS traffic classes
     - net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation
     - raw: use more conventional iterators
     - drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video()
     - drm/nouveau/acr: fix missing nvkm_done() in error path of
       nvkm_acr_oneinit()
     - drm/radeon: fix r100_copy_blit for large BOs
     - net: ipv6: fix dif and sdif mismatch in raw6_icmp_error
     - drm/amdgpu: Fix VFCT bus number matching with soft filter
     - drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X)
     - media: cec: seco: unregister adapter on IR probe failure
     - media: cedrus: clean up media device on probe failure
     - media: cedrus: Fix missing cleanup in error path
     - media: tegra-video: vi: fix invalid u32 return value in format
       lookup
     - media: vb2: use ssize_t for vb2_read/vb2_write
     - media: vidtv: fix reference leak on failed device registration
     - media: vimc: fix reference leak on failed device registration
     - tracing/probes: Avoid temporary buffer truncation in
       trace_probe_match_command_args()
     - tracing/probes: Fix potential underflow in LEN_OR_ZERO macro
     - tracing/probes: Prevent out-of-bounds write in
       __trace_probe_log_err()
     - arm64: syscall: Ensure saved x0 is kept in-sync with tracer
       updates
     - Revert "arm64: syscall: Ensure saved x0 is kept in-sync with
       tracer updates"
     - iommu/vt-d: Disallow SVA if page walk is not coherent
     - raw: remove unused variables from raw6_icmp_error()
     - raw: fix a typo in raw_icmp_error()
     - net: bridge: vlan: fix global vlan option range dumping
     - media: uvcvideo: Implement dual stream quirk to fix loss of usb
       packets
     - media: uvcvideo: Fix sequence number when no EOF
     - HID: logitech-dj: Standardise hid_report_enum variable
       nomenclature
     - HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user
       initiated OOB write
     - HID: logitech-dj: fix wrong detection of bad DJ_SHORT output
       report
     - dmaengine: sun6i-dma: Fix reclaim descriptors while terminating
       DMA
     - ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk
       lookup
     - ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk
       lookup
     - assoc_array: trim the final shortcut word using the current chunk
       end
     - smb: client: fix buffer leaks in SMB1 read and write
     - hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks
     - hwmon: (adt7470) Create functions for updating readings and limits
     - hwmon: (adt7470) Fix some style issues
     - hwmon: (adt7470) Convert to use regmap
     - hwmon: (adt7470) Fix PWM auto temp state array and bounds check
     - powerpc/boot: Fix simpleboot CPU node lookup check
     - powerpc/boot: Fix treeboot-currituck CPU node lookup check
     - powerpc/boot: Fix treeboot-akebono CPU node lookup check
     - hwmon: (pmbus) Fix return value from pmbus_update_byte_data()
     - net: phylink: put link_gpio if phylink_create fails
     - scsi: zfcp: Fix memory leak during adapter release by destroying
       gid_pn_req
     - net: sxgbe: check descriptor ring allocation failures
     - can: isotp: check register_netdevice_notifier() error in module
       init
     - tracing/mmiotrace: Reset dropped_count in mmio_reset_data()
     - octeontx2-pf: Set correct sequence for carrier off and tx queue
       stop
     - pinctrl: bm1880: add missing select GENERIC_PINCONF
     - audit: fix potential integer overflow in audit_log_n_string()
     - bpf: lwt: Fix dst reference leak on reroute failure
     - ALSA: lx6464es: fix period byte count for 16-bit streams
     - ASoC: tas2562: fix DVC coefficient write order
     - ASoC: tas2562: fix broken entries in the volume lookup table
     - dmaengine: qcom: bam_dma: Fix command element mask field for BAM
       v1.6.0+
     - e1000: fix memory leak in e1000_probe()
     - powerpc/ps3: Fix map failure path in dma_ioc0_map_pages()
     - vxlan: unclone skb head before modifying eth header in
       route_shortcircuit()
     - tracing/filters: Fix false positive match in regex_match_full()
     - selftests/clone3: fix wild pointer access of getline due to
       missing init
     - sctp: reject stale cookies with mismatched verification tags
     - cpufreq: powernow-k8: Fix possible memory leak in
       powernowk8_cpu_init()
     - phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask
     - phy: zynqmp: use read-modify-write for SERDES scrambler bypass
     - phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB
     - can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak
       in kvaser_usb_hydra_get_busparams()
     - drm/amdgpu: cap GTT size to physical RAM on APUs
     - net: openvswitch: fix skb leak on flow key update failure during
       recirculation
     - mount: honour SB_NOUSER in the new mount API
     - nfs4: take a reference on the nfs_client when running FREE_STATEID
     - ARM: npcm: Fix OF node refcount leaks in SMP setup
     - net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete
     - net/mlx5: Remove second FW tracer check
     - counter: microchip-tcb-capture: Fix DT channel validation
     - net: openvswitch: Fix kerneldoc warnings
     - net: openvswitch: fix kernel-doc warnings in flow.c
     - bnxt_en: Do not set EOP on RX AGG BDs on 5760X chips
     - sctp: fix addip_serial increment on ASCONF_ACK allocation failure
     - net: marvell: prestera: try to load previous fw version
     - sctp: remove the unessessary hold for idev in sctp_v6_err
     - sctp: extract sctp_v6_err_handle function from sctp_v6_err
     - sctp: extract sctp_v4_err_handle function from sctp_v4_err
     - tls: don't abort the connection on signal-interrupted sends
     - spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers
     - ALSA: usb-audio: Evaluate packsize caps at the right place
     - ipvs: add totalconns for dest
     - ipvs: properly update the overload flag on dest edit
     - fscrypt: Replace mk_users keyring with simple list
     - misc: fastrpc: fix channel ctx ref leak when session alloc fails
     - misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free
     - scsi: scsi_debug: Negate wrapped memcmp() result
     - prestera: fix fallback to previous version on same major version
     - hwmon: (adt7470) Add missing dependency on REGMAP_I2C
     - hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors
     - Linux 5.10.265
     - ipvs: separate destination availability state
     - selinux: require every boolean value to be defined
     - ASoC: cs4265: sort the register default table
     - powerpc/pseries: pci - logic bug
     - Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal
       keyboard
     - powerpc/pseries: lparcfg - fix kbuf[] underflow
     - ftrace: Fix off-by-one fentry site disable in ftrace_free_mem()
     - Input: sur40 - fix V4L error path cleanup
     - ceph: fix MDS random selection readiness predicate
     - mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on
       32-bit
     - mmc: sdhci: unmap the bounce buffer before device release
     - mmc: sdhci: make tuning_err a signed int
     - drm/radeon: fix autosuspend cleanup during teardown
     - drm/amdgpu: Reject UVD message with invalid number of h265 refs
     - drm/amdgpu: Reject UVD message with dimensions above 4096
     - drm/amdgpu: Implement insert_end for VCE 3
     - xfs: check v5 superblock features early
     - udmabuf: Do not create malformed scatterlists
     - i2c: davinci: Unregister cpufreq notifier on probe failure
     - device property: Add fwnode_irq_get_byname
     - i2c: smbus: Use device_*() functions instead of of_*()
     - VFS/audit: introduce kern_path_parent() for audit
     - audit: widen ino fields to u64
     - audit: use 'unsigned int' instead of 'unsigned'
     - ALSA: hda: Fix cached processing coefficient verbs
     - serial: max310x: replace bare use of 'unsigned' with 'unsigned
       int' (checkpatch)
     - serial: max310x: implement gpio_chip::get_direction()
     - rxrpc: Fix notification vs call-release vs recvmsg
     - rxrpc: Fix socket notification race
     - mlxsw: spectrum: Apply RIF configuration when joining a LAG
     - mlxsw: spectrum: On port enslavement to a LAG, join upper's
       bridges
     - octeontx2: Annotate mmio regions as __iomem
     - octeontx2-pf: clear stale mailbox IRQ state before request_irq()
     - ASoC: mediatek: mt8183: Check runtime resume during probe
     - octeontx2-vf: clear stale mailbox IRQ state before request_irq()
     - netfilter: nf_conntrack_sip: remove net variable shadowing
     - jbd2: add a helper to find out number of fast commit blocks
     - lsm: use default hook return value in call_int_hook()
     - lsm: infrastructure management of the sock security
     - taskstats: fill_stats_for_tgid: use for_each_thread()
     - taskstats: retain dead thread stats in TGID queries
     - mtd: spi-nor: sst: remove global protection flag
     - mtd: spi-nor: intel: remove global protection flag
     - mtd: spi-nor: Move Software Write Protection logic out of the core
     - mtd: spi-nor: Fix spi_nor_try_unlock_all()
     - smb: client: use kvzalloc() for megabyte buffer in simple
       fallocate
     - PCI: Add pci_find_vsec_capability() to find a specific VSEC
     - dmaengine: dw-edma: Improve the linked list and data blocks
       definition
     - dmaengine: dw-edma: Remove unused irq field in struct dw_edma_chip
     - i2c: imx: separate atomic, dma and non-dma use case
     - thunderbolt: Keep XDomain reference during the lifetime of a
       service
     - thunderbolt: Remove XDomain from the bus without holding tb-&gt;lock
     - ovl: use linked upper dentry in copy-up tmpfile
     - scsi: target: core: pr: Initialize arrays at declaration time
     - scsi: target: core: Generate correct identifiers for PR OUT
       transport IDs
     - mmc: vub300: rename probe error labels
     - firmware_loader: introduce __free() cleanup hanler
     - net: Add helper function to parse netlink msg of ip_tunnel_encap
     - net/sched: taprio: avoid calling child-&gt;ops-&gt;dequeue(child) twice
     - bootconfig: do not put quotes on cmdline items unless necessary
     - bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c
     - bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline()
     - net: ipa: fix SMEM state handle leaks in SMP2P init
     - usb: gadget: bdc: fix checkpatch.pl spacing error
     - USB: serial: keyspan_pda: refactor write-room handling
     - USB: serial: keyspan_pda: fix write implementation
     - USB: serial: keyspan_pda: add write-fifo support
     - USB: serial: keyspan_pda: clean up comments and whitespace
     - USB: serial: keyspan_pda: fix data loss on receive throttling
     - KVM: x86: Drop @vcpu parameter from
       kvm_x86_ops.hwapic_isr_update()
     - KVM: x86: Check for in-kernel xAPIC when querying APICv for
       directed yield
     - KVM: x86: Move "apicv_active" into "struct kvm_lapic"
     - KVM: Introduce vcpu-&gt;wants_to_run
     - KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on
       KVM_RUN
     - dma-buf/drivers: make reserving a shared slot mandatory v4
     - drm/virtio: use uninterruptible resv lock for plane updates
     - drm/displayid: fix Tiled Display Topology ID size
     - drm/tegra: fbdev: Remove offset into framebuffer memory
     - drm/virtio: Return proper error codes instead of -1
     - media: aspeed: fix missing of_reserved_mem_device_release() on
       probe failure
     - drm/i915/hdcp: require monotonically increasing seq_num_v
     - media: marvell-cam: fix missing pci_disable_device() on remove
     - media: i2c: imx219: Drop IMX219_VTS_* macros
     - media: i2c: imx219: Correct the minimum vblanking value
     - media: i2c: imx219: Rename VTS to FRM_LENGTH
     - media: imx219: Fix maximum frame length in lines
     - media: v4l: async: Set owner for async sub-devices
     - serial: 8250_mid: Remove unneeded test for -&gt;setup() presence
     - mptcp: only set DATA_FIN when a mapping is present
     - sc16is7xx: Properly resume TX after stop
     - serial: sc16is7xx: Fill in rs485_supported
     - serial: sc16is7xx: remove obsolete out_thread label
     - serial: sc16is7xx: fix regression with GPIO configuration
     - serial: sc16is7xx: implement gpio get_direction() callback
     - mptcp: fix subflow accounting on close
     - mptcp: decrement subflows counter on failed passive join
     - libceph: Amend checking to fix `make W=1` build breakage
     - libceph: add doutc and *_client debug macros support
     - ceph: rename _to_client() to _to_fs_client()
     - skbuff: introduce skb_pull_data
     - mm/vmstat: fold stranded per-cpu node stats when a node comes
       online
     - net: pktgen: fix code style (WARNING: Block comments)
     - scsi: sd: sd_zbc: Improve source code documentation
     - scsi: sd: sd_zbc: Use logical blocks as unit when querying zones
     - scsi: sd: sd_zbc: Return early in
       sd_zbc_check_zoned_characteristics()
     - scsi: scsi_debug: Rename zone type constants
     - ice: fix VF interrupts cleanup
     - ice: fix memory leak in ice_lbtest_prepare_rings()
     - i2c: bcm-iproc: remove printout on handled timeouts
     - i2c: iproc: reset bus after timeout if START_BUSY is stuck
     - fsnotify: opt-in for permission events at file open time
     - fs: don't block write during exec on pre-content watched files
     - can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb
       allocation failure
     - hwmon: (npcm750-pwm-fan): stop fan timer on device detach
     - drm/amd/pm: fix torn gpu metrics reads
     - ALSA: usx2y: Fix potential leaks of uninitialized memory
     - arm64: tegra: Add EL2 virtual timer interrupt for Tegra194
     - crypto: ccm - Set rfc4309 maxauthsize from child
     - netfilter: ipset: fix list type element drift bug
     - net: packet: fix wrong transport_header when sending VLAN-tagged
       frame
     - net: ethernet: ti: am65-cpsw: move ale selection in pdata
     - net: ethernet: ti: am65-cpsw: move free desc queue mode selection
       in pdata
     - net: ethernet: ti: am65-cpsw: add multi port support in mac-only
       mode
     - net/smc: rdma write inline if qp has sufficient inline space
     - i2c: smbus: Check for parent device before dereference
     - net: ethernet: ti: am65-cpsw: fix error handling in
       am65_cpsw_nuss_probe()
     - ring-buffer: Remove jump to out label in ring_buffer_swap_cpu()
     - Linux 5.10.266
     - Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept
     - rndis_host: add overflow check in rndis_rx_fixup()
     - ocfs2: fix missing metadata reservation for large xattrs
     - ext4: stop retrying saturated xattr cache entries
     - ext4: clear error before retrying inode xattr space fallback
     - xfs: validate attr entry pointer before field access
     - misc: fastrpc: separate fastrpc device from channel context
     - misc: fastrpc: Rework fastrpc_req_munmap
     - net: ipv4: Publish fib_nlmsg_size()
     - perf: Fix cgroup state vs ERROR
     - perf: Fix dangling cgroup pointer in cpuctx
     - KVM: arm64: Retry fault if vma_lookup() results become invalid
     - nfc: digital: clamp SENSF_RES length to the destination buffer
     - nfc: fdp: bound the device-reported read length and fix an skb
       leak
     - nfc: microread: validate target discovery payload lengths
     - nfc: llcp: bound the connect_sn TLV walk to the skb
     - nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers
     - nfc: llcp: reject PDUs shorter than the LLCP header
     - nfc: pn533: purge fragmented skbs during cleanup
     - nfc: st21nfca: validate ATR_REQ length against the received frame
     - nfc: nci: fix out-of-bounds write in nci_target_auto_activated()
     - nfc: nci: free destination parameters when closing a connection
     - ipv4: reject undersized MTUs in ip_do_fragment()
     - ipv6: fix use-after-free in ip6_finish_output2()
     - nvmet-fc: fix invalid free in LS IOD error path
     - nvmet-tcp: Do not WARN on remotely-controlled oversized SGL
       allocations
     - HID: magicmouse: Prevent out-of-bounds (OOB) read during
       DOUBLE_REPORT_ID
     - HID: core: fix OOB read of field-&gt;usage in hid_set_field()
     - Revert "Input: ims-pcu - fix race condition in reset_device sysfs
       callback"
     - can: use skb hash instead of private variable in headroom
     - HID: core: fix number/pointer type confusion on long items
     - HID: sensor: custom: Fix use-after-free in enable_sensor
     - HID: hyperv: validate initial device info bounds
     - Revert "ALSA: aoa: Use guard() for mutex locks"
     - Linux 5.10.267
     - Linux 5.10.268
     - RDMA/rxe: Fix OOB in free_rd_atomic_resources()
     - ext4: don't enable DAX on new encrypted files
     - io_uring/io-wq: fix worker accounting when canceling creation
       callbacks
     - Revert "PM: sleep: Use complete() in device_pm_sleep_init()"
     - selinux: switch two allocations to use kzalloc_objs()
     - Revert "mtd: maps: vmu-flash: fix fault in unaligned fixup"
     - Revert "smb: client: use kvzalloc() for megabyte buffer in simple
       fallocate"
     - kcov: fix data corruption and race conditions on PREEMPT_RT
     - ext4: propagate errors from fast commit range replay
     - nilfs2: reject invalid block index in GC ioctl
     - nfc: nci: fix uninit-value in the RF discover/activated NTF
       handlers
     - HID: magicmouse: do not keep a stale msc-&gt;input if no input is
       claimed
     - nfc: nci: add data_len bound checks to activation parameter
       extractors
     - nvmet-tcp: bound SGL data length before allocating command buffers
     - HID: input: read battery capacity from its actual report offset
     - fpga: dfl: fme: add error handling
     - accessibility: speakup: unregister tty ldisc on later init
       failures
     - usb: usbtest: disable dynamic ID support
     - usb: gadget: f_tcm: keep port count until LUN teardown completes
     - xfrm: espintcp: fix UAF during close
     - xfrm: drop ESP-in-TCP packets with no ingress device
     - xfrm: ah6: validate routing header segments_left
     - xfrm: fix xfrm_state_construct() auth-trunc leak
     - ipv6: seg6: clear IPv4 control block on IPIP decapsulation
     - mm/swap: reject swapon() on filesystem-level encrypted files
     - crypto: atmel-tdes - use scatterlist length before DMA mapping
     - crypto: mxs-dcp - fix source scatterlist length access
     - KVM: s390: vsie: zero stale crypto bits
     - usb: core: Add lock to usb_wakeup_notification()
     - usb: core: Strengthen error handling in hub_hub_status()
     - ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
     - USB: serial: option: fix slab OOB read in interrupt URB callback
     - USB: serial: spcp8x5: drop broken carrier detect support
     - USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
     - usb: usbfs: fix use-after-free of usb_device in usbdev_release()
     - Linux 5.10.269</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-07"/>
          <updated date="2026-09-07"/>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68433" impact="unknown" public="20260812">CVE-2026-68433</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80560" impact="unknown" public="20260826">CVE-2026-80560</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68325" impact="unknown" public="20260810">CVE-2026-68325</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68106" impact="unknown" public="20260810">CVE-2026-68106</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-64567" impact="unknown" public="20260805">CVE-2026-64567</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-129" href="https://cve.tuxcare.com/els/cve/CVE-2026-45839" impact="important" public="20260527">CVE-2026-45839</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72299" impact="unknown" public="20260815">CVE-2026-72299</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80570" impact="unknown" public="20260826">CVE-2026-80570</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68151" impact="unknown" public="20260810">CVE-2026-68151</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68279" impact="unknown" public="20260810">CVE-2026-68279</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72253" impact="unknown" public="20260815">CVE-2026-72253</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74480" impact="unknown" public="20260815">CVE-2026-74480</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68326" impact="unknown" public="20260810">CVE-2026-68326</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72075" impact="unknown" public="20260815">CVE-2026-72075</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74583" impact="unknown" public="20260821">CVE-2026-74583</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68227" impact="unknown" public="20260810">CVE-2026-68227</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68370" impact="unknown" public="20260810">CVE-2026-68370</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74505" impact="unknown" public="20260815">CVE-2026-74505</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72051" impact="unknown" public="20260815">CVE-2026-72051</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68352" impact="unknown" public="20260810">CVE-2026-68352</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68135" impact="unknown" public="20260810">CVE-2026-68135</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68350" impact="unknown" public="20260810">CVE-2026-68350</cve>
          <cve cvss3="7.0/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els/cve/CVE-2026-31408" impact="important" public="20260406">CVE-2026-31408</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68157" impact="unknown" public="20260810">CVE-2026-68157</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72096" impact="unknown" public="20260815">CVE-2026-72096</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80573" impact="unknown" public="20260826">CVE-2026-80573</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74671" impact="unknown" public="20260822">CVE-2026-74671</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80718" impact="unknown" public="20260828">CVE-2026-80718</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68199" impact="unknown" public="20260810">CVE-2026-68199</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68480" impact="unknown" public="20260806">CVE-2026-68480</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68344" impact="unknown" public="20260810">CVE-2026-68344</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74647" impact="unknown" public="20260822">CVE-2026-74647</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68204" impact="unknown" public="20260810">CVE-2026-68204</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68188" impact="unknown" public="20260810">CVE-2026-68188</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68217" impact="unknown" public="20260810">CVE-2026-68217</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68406" impact="unknown" public="20260810">CVE-2026-68406</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68403" impact="unknown" public="20260810">CVE-2026-68403</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80558" impact="unknown" public="20260826">CVE-2026-80558</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68180" impact="unknown" public="20260810">CVE-2026-68180</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74601" impact="unknown" public="20260822">CVE-2026-74601</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68142" impact="unknown" public="20260810">CVE-2026-68142</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68327" impact="unknown" public="20260810">CVE-2026-68327</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74628" impact="unknown" public="20260822">CVE-2026-74628</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74566" impact="unknown" public="20260815">CVE-2026-74566</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-64571" impact="unknown" public="20260805">CVE-2026-64571</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74569" impact="unknown" public="20260815">CVE-2026-74569</cve>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://cve.tuxcare.com/els/cve/CVE-2026-43491" impact="moderate" public="20260519">CVE-2026-43491</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74594" impact="unknown" public="20260822">CVE-2026-74594</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-64371" impact="unknown" public="20260725">CVE-2026-64371</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68363" impact="unknown" public="20260810">CVE-2026-68363</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-787" href="https://cve.tuxcare.com/els/cve/CVE-2026-64270" impact="important" public="20260725">CVE-2026-64270</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68111" impact="unknown" public="20260810">CVE-2026-68111</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74615" impact="unknown" public="20260822">CVE-2026-74615</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74563" impact="unknown" public="20260815">CVE-2026-74563</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68328" impact="unknown" public="20260810">CVE-2026-68328</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80567" impact="unknown" public="20260826">CVE-2026-80567</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68160" impact="unknown" public="20260810">CVE-2026-68160</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68434" impact="unknown" public="20260812">CVE-2026-68434</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74549" impact="unknown" public="20260815">CVE-2026-74549</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74664" impact="unknown" public="20260822">CVE-2026-74664</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68255" impact="unknown" public="20260810">CVE-2026-68255</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72121" impact="unknown" public="20260815">CVE-2026-72121</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80586" impact="unknown" public="20260826">CVE-2026-80586</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68117" impact="unknown" public="20260810">CVE-2026-68117</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74485" impact="unknown" public="20260815">CVE-2026-74485</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68141" impact="unknown" public="20260810">CVE-2026-68141</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68198" impact="unknown" public="20260810">CVE-2026-68198</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80590" impact="unknown" public="20260828">CVE-2026-80590</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68196" impact="unknown" public="20260810">CVE-2026-68196</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74475" impact="unknown" public="20260815">CVE-2026-74475</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68162" impact="unknown" public="20260810">CVE-2026-68162</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74730" impact="unknown" public="20260822">CVE-2026-74730</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74471" impact="unknown" public="20260815">CVE-2026-74471</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68222" impact="unknown" public="20260810">CVE-2026-68222</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68184" impact="unknown" public="20260810">CVE-2026-68184</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74693" impact="unknown" public="20260822">CVE-2026-74693</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68182" impact="unknown" public="20260810">CVE-2026-68182</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68376" impact="unknown" public="20260810">CVE-2026-68376</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74519" impact="unknown" public="20260815">CVE-2026-74519</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72225" impact="unknown" public="20260815">CVE-2026-72225</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68154" impact="unknown" public="20260810">CVE-2026-68154</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68351" impact="unknown" public="20260810">CVE-2026-68351</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80584" impact="unknown" public="20260826">CVE-2026-80584</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68349" impact="unknown" public="20260810">CVE-2026-68349</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-64581" impact="unknown" public="20260805">CVE-2026-64581</cve>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-476" href="https://cve.tuxcare.com/els/cve/CVE-2022-3113" impact="moderate" public="20221214">CVE-2022-3113</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74625" impact="unknown" public="20260822">CVE-2026-74625</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74663" impact="unknown" public="20260822">CVE-2026-74663</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74564" impact="unknown" public="20260815">CVE-2026-74564</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68425" impact="unknown" public="20260810">CVE-2026-68425</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-64543" impact="unknown" public="20260727">CVE-2026-64543</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74598" impact="unknown" public="20260822">CVE-2026-74598</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68452" impact="unknown" public="20260813">CVE-2026-68452</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74468" impact="unknown" public="20260815">CVE-2026-74468</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80714" impact="unknown" public="20260828">CVE-2026-80714</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74436" impact="unknown" public="20260815">CVE-2026-74436</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74641" impact="unknown" public="20260822">CVE-2026-74641</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68223" impact="unknown" public="20260810">CVE-2026-68223</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74613" impact="unknown" public="20260822">CVE-2026-74613</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68284" impact="unknown" public="20260810">CVE-2026-68284</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68249" impact="unknown" public="20260810">CVE-2026-68249</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80681" impact="unknown" public="20260828">CVE-2026-80681</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80555" impact="unknown" public="20260826">CVE-2026-80555</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68218" impact="unknown" public="20260810">CVE-2026-68218</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74675" impact="unknown" public="20260822">CVE-2026-74675</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68096" impact="unknown" public="20260810">CVE-2026-68096</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80680" impact="unknown" public="20260828">CVE-2026-80680</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72114" impact="unknown" public="20260815">CVE-2026-72114</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-64582" impact="unknown" public="20260805">CVE-2026-64582</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74557" impact="unknown" public="20260815">CVE-2026-74557</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68125" impact="unknown" public="20260810">CVE-2026-68125</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72148" impact="unknown" public="20260815">CVE-2026-72148</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74726" impact="unknown" public="20260822">CVE-2026-74726</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74746" impact="unknown" public="20260826">CVE-2026-74746</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74487" impact="unknown" public="20260815">CVE-2026-74487</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74697" impact="unknown" public="20260822">CVE-2026-74697</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68428" impact="unknown" public="20260810">CVE-2026-68428</cve>
          <cve cwe="CWE-476" href="https://cve.tuxcare.com/els/cve/CVE-2026-64048" impact="unknown" public="20260719">CVE-2026-64048</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74493" impact="unknown" public="20260815">CVE-2026-74493</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72142" impact="unknown" public="20260815">CVE-2026-72142</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68138" impact="unknown" public="20260810">CVE-2026-68138</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74668" impact="unknown" public="20260822">CVE-2026-74668</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68197" impact="unknown" public="20260810">CVE-2026-68197</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74579" impact="unknown" public="20260817">CVE-2026-74579</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68335" impact="unknown" public="20260810">CVE-2026-68335</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72035" impact="unknown" public="20260815">CVE-2026-72035</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74666" impact="unknown" public="20260822">CVE-2026-74666</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72117" impact="unknown" public="20260815">CVE-2026-72117</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68397" impact="unknown" public="20260810">CVE-2026-68397</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68143" impact="unknown" public="20260810">CVE-2026-68143</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68299" impact="unknown" public="20260810">CVE-2026-68299</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68451" impact="unknown" public="20260813">CVE-2026-68451</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68205" impact="unknown" public="20260810">CVE-2026-68205</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68413" impact="unknown" public="20260810">CVE-2026-68413</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74719" impact="unknown" public="20260822">CVE-2026-74719</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68355" impact="unknown" public="20260810">CVE-2026-68355</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74547" impact="unknown" public="20260815">CVE-2026-74547</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74688" impact="unknown" public="20260822">CVE-2026-74688</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72116" impact="unknown" public="20260815">CVE-2026-72116</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80679" impact="unknown" public="20260828">CVE-2026-80679</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68338" impact="unknown" public="20260810">CVE-2026-68338</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80536" impact="unknown" public="20260826">CVE-2026-80536</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68430" impact="unknown" public="20260812">CVE-2026-68430</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74469" impact="unknown" public="20260815">CVE-2026-74469</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72123" impact="unknown" public="20260815">CVE-2026-72123</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68153" impact="unknown" public="20260810">CVE-2026-68153</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74679" impact="unknown" public="20260822">CVE-2026-74679</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74737" impact="unknown" public="20260826">CVE-2026-74737</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74704" impact="unknown" public="20260822">CVE-2026-74704</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72041" impact="unknown" public="20260815">CVE-2026-72041</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74630" impact="unknown" public="20260822">CVE-2026-74630</cve>
          <cve cvss3="7.0/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els/cve/CVE-2026-53275" impact="important" public="20260625">CVE-2026-53275</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74705" impact="unknown" public="20260822">CVE-2026-74705</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80527" impact="unknown" public="20260826">CVE-2026-80527</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72392" impact="unknown" public="20260815">CVE-2026-72392</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68202" impact="unknown" public="20260810">CVE-2026-68202</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68131" impact="unknown" public="20260810">CVE-2026-68131</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68146" impact="unknown" public="20260810">CVE-2026-68146</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74648" impact="unknown" public="20260822">CVE-2026-74648</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74585" impact="unknown" public="20260822">CVE-2026-74585</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68215" impact="unknown" public="20260810">CVE-2026-68215</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68278" impact="unknown" public="20260810">CVE-2026-68278</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72115" impact="unknown" public="20260815">CVE-2026-72115</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74609" impact="unknown" public="20260822">CVE-2026-74609</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68132" impact="unknown" public="20260810">CVE-2026-68132</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72181" impact="unknown" public="20260815">CVE-2026-72181</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80569" impact="unknown" public="20260826">CVE-2026-80569</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68369" impact="unknown" public="20260810">CVE-2026-68369</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68187" impact="unknown" public="20260810">CVE-2026-68187</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68127" impact="unknown" public="20260810">CVE-2026-68127</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74748" impact="unknown" public="20260826">CVE-2026-74748</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-64583" impact="unknown" public="20260806">CVE-2026-64583</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74481" impact="unknown" public="20260815">CVE-2026-74481</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74631" impact="unknown" public="20260822">CVE-2026-74631</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74694" impact="unknown" public="20260822">CVE-2026-74694</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72063" impact="unknown" public="20260815">CVE-2026-72063</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74525" impact="unknown" public="20260815">CVE-2026-74525</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72099" impact="unknown" public="20260815">CVE-2026-72099</cve>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-476" href="https://cve.tuxcare.com/els/cve/CVE-2024-40973" impact="moderate" public="20240712">CVE-2024-40973</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68377" impact="unknown" public="20260810">CVE-2026-68377</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68476" impact="unknown" public="20260815">CVE-2026-68476</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68082" impact="unknown" public="20260808">CVE-2026-68082</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80574" impact="unknown" public="20260826">CVE-2026-80574</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74580" impact="unknown" public="20260821">CVE-2026-74580</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68212" impact="unknown" public="20260810">CVE-2026-68212</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74676" impact="unknown" public="20260822">CVE-2026-74676</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74443" impact="unknown" public="20260815">CVE-2026-74443</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68104" impact="unknown" public="20260810">CVE-2026-68104</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-64572" impact="unknown" public="20260805">CVE-2026-64572</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68186" impact="unknown" public="20260810">CVE-2026-68186</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74667" impact="unknown" public="20260822">CVE-2026-74667</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68156" impact="unknown" public="20260810">CVE-2026-68156</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2025-68794" impact="unknown" public="20260113">CVE-2025-68794</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74490" impact="unknown" public="20260815">CVE-2026-74490</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68144" impact="unknown" public="20260810">CVE-2026-68144</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72155" impact="unknown" public="20260815">CVE-2026-72155</cve>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-401" href="https://cve.tuxcare.com/els/cve/CVE-2026-64336" impact="moderate" public="20260725">CVE-2026-64336</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68229" impact="unknown" public="20260810">CVE-2026-68229</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74488" impact="unknown" public="20260815">CVE-2026-74488</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68175" impact="unknown" public="20260810">CVE-2026-68175</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74455" impact="unknown" public="20260815">CVE-2026-74455</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68231" impact="unknown" public="20260810">CVE-2026-68231</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68322" impact="unknown" public="20260810">CVE-2026-68322</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80707" impact="unknown" public="20260828">CVE-2026-80707</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74651" impact="unknown" public="20260822">CVE-2026-74651</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68209" impact="unknown" public="20260810">CVE-2026-68209</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74658" impact="unknown" public="20260822">CVE-2026-74658</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72070" impact="unknown" public="20260815">CVE-2026-72070</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74589" impact="unknown" public="20260822">CVE-2026-74589</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74720" impact="unknown" public="20260822">CVE-2026-74720</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74464" impact="unknown" public="20260815">CVE-2026-74464</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68297" impact="unknown" public="20260810">CVE-2026-68297</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74453" impact="unknown" public="20260815">CVE-2026-74453</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80541" impact="unknown" public="20260826">CVE-2026-80541</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68402" impact="unknown" public="20260810">CVE-2026-68402</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72053" impact="unknown" public="20260815">CVE-2026-72053</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74575" impact="unknown" public="20260815">CVE-2026-74575</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68136" impact="unknown" public="20260810">CVE-2026-68136</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68313" impact="unknown" public="20260810">CVE-2026-68313</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74465" impact="unknown" public="20260815">CVE-2026-74465</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74456" impact="unknown" public="20260815">CVE-2026-74456</cve>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://cve.tuxcare.com/els/cve/CVE-2024-46754" impact="moderate" public="20240918">CVE-2024-46754</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74508" impact="unknown" public="20260815">CVE-2026-74508</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68366" impact="unknown" public="20260810">CVE-2026-68366</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68214" impact="unknown" public="20260810">CVE-2026-68214</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74620" impact="unknown" public="20260822">CVE-2026-74620</cve>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://cve.tuxcare.com/els/cve/CVE-2024-58094" impact="moderate" public="20250416">CVE-2024-58094</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74657" impact="unknown" public="20260822">CVE-2026-74657</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74654" impact="unknown" public="20260822">CVE-2026-74654</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68353" impact="unknown" public="20260810">CVE-2026-68353</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-64535" impact="unknown" public="20260727">CVE-2026-64535</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74479" impact="unknown" public="20260815">CVE-2026-74479</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68304" impact="unknown" public="20260810">CVE-2026-68304</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-64562" impact="unknown" public="20260804">CVE-2026-64562</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74582" impact="unknown" public="20260821">CVE-2026-74582</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74473" impact="unknown" public="20260815">CVE-2026-74473</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68354" impact="unknown" public="20260810">CVE-2026-68354</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68137" impact="unknown" public="20260810">CVE-2026-68137</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72019" impact="unknown" public="20260815">CVE-2026-72019</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74626" impact="unknown" public="20260822">CVE-2026-74626</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74660" impact="unknown" public="20260822">CVE-2026-74660</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68368" impact="unknown" public="20260810">CVE-2026-68368</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72077" impact="unknown" public="20260815">CVE-2026-72077</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74512" impact="unknown" public="20260815">CVE-2026-74512</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80716" impact="unknown" public="20260828">CVE-2026-80716</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74682" impact="unknown" public="20260822">CVE-2026-74682</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74635" impact="unknown" public="20260822">CVE-2026-74635</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80708" impact="unknown" public="20260828">CVE-2026-80708</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68315" impact="unknown" public="20260810">CVE-2026-68315</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68388" impact="unknown" public="20260810">CVE-2026-68388</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72125" impact="unknown" public="20260815">CVE-2026-72125</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74498" impact="unknown" public="20260815">CVE-2026-74498</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-64584" impact="unknown" public="20260806">CVE-2026-64584</cve>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://cve.tuxcare.com/els/cve/CVE-2024-58095" impact="moderate" public="20250416">CVE-2024-58095</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74457" impact="unknown" public="20260815">CVE-2026-74457</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els/cve/CVE-2026-53089" impact="important" public="20260624">CVE-2026-53089</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68432" impact="unknown" public="20260812">CVE-2026-68432</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74717" impact="unknown" public="20260822">CVE-2026-74717</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68320" impact="unknown" public="20260810">CVE-2026-68320</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74586" impact="unknown" public="20260822">CVE-2026-74586</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68234" impact="unknown" public="20260810">CVE-2026-68234</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68159" impact="unknown" public="20260810">CVE-2026-68159</cve>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://cve.tuxcare.com/els/cve/CVE-2026-46003" impact="moderate" public="20260527">CVE-2026-46003</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74463" impact="unknown" public="20260815">CVE-2026-74463</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72166" impact="unknown" public="20260815">CVE-2026-72166</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74599" impact="unknown" public="20260822">CVE-2026-74599</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74470" impact="unknown" public="20260815">CVE-2026-74470</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74683" impact="unknown" public="20260822">CVE-2026-74683</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68365" impact="unknown" public="20260810">CVE-2026-68365</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74499" impact="unknown" public="20260815">CVE-2026-74499</cve>
          <cve cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-362" href="https://cve.tuxcare.com/els/cve/CVE-2025-38524" impact="moderate" public="20250816">CVE-2025-38524</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74669" impact="unknown" public="20260822">CVE-2026-74669</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74622" impact="unknown" public="20260822">CVE-2026-74622</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-64586" impact="unknown" public="20260806">CVE-2026-64586</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68405" impact="unknown" public="20260810">CVE-2026-68405</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68446" impact="unknown" public="20260812">CVE-2026-68446</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80706" impact="unknown" public="20260828">CVE-2026-80706</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68367" impact="unknown" public="20260810">CVE-2026-68367</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72087" impact="unknown" public="20260815">CVE-2026-72087</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68410" impact="unknown" public="20260810">CVE-2026-68410</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68140" impact="unknown" public="20260810">CVE-2026-68140</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68213" impact="unknown" public="20260810">CVE-2026-68213</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74495" impact="unknown" public="20260815">CVE-2026-74495</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74577" impact="unknown" public="20260815">CVE-2026-74577</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74701" impact="unknown" public="20260822">CVE-2026-74701</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68115" impact="unknown" public="20260810">CVE-2026-68115</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80565" impact="unknown" public="20260826">CVE-2026-80565</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74523" impact="unknown" public="20260815">CVE-2026-74523</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80717" impact="unknown" public="20260828">CVE-2026-80717</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-64280" impact="unknown" public="20260725">CVE-2026-64280</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74507" impact="unknown" public="20260815">CVE-2026-74507</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68411" impact="unknown" public="20260810">CVE-2026-68411</cve>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://cve.tuxcare.com/els/cve/CVE-2026-46026" impact="moderate" public="20260527">CVE-2026-46026</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74478" impact="unknown" public="20260815">CVE-2026-74478</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68195" impact="unknown" public="20260810">CVE-2026-68195</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72118" impact="unknown" public="20260815">CVE-2026-72118</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68192" impact="unknown" public="20260810">CVE-2026-68192</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72084" impact="unknown" public="20260815">CVE-2026-72084</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68300" impact="unknown" public="20260810">CVE-2026-68300</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68216" impact="unknown" public="20260810">CVE-2026-68216</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72323" impact="unknown" public="20260815">CVE-2026-72323</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72157" impact="unknown" public="20260815">CVE-2026-72157</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els/cve/CVE-2024-58240" impact="important" public="20250828">CVE-2024-58240</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-64565" impact="unknown" public="20260804">CVE-2026-64565</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80540" impact="unknown" public="20260826">CVE-2026-80540</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74637" impact="unknown" public="20260822">CVE-2026-74637</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80568" impact="unknown" public="20260826">CVE-2026-80568</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72124" impact="unknown" public="20260815">CVE-2026-72124</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80528" impact="unknown" public="20260826">CVE-2026-80528</cve>
          <cve cwe="CWE-416" href="https://cve.tuxcare.com/els/cve/CVE-2026-64434" impact="unknown" public="20260725">CVE-2026-64434</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74587" impact="unknown" public="20260822">CVE-2026-74587</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74597" impact="unknown" public="20260822">CVE-2026-74597</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68121" impact="unknown" public="20260810">CVE-2026-68121</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80534" impact="unknown" public="20260826">CVE-2026-80534</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68360" impact="unknown" public="20260810">CVE-2026-68360</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80561" impact="unknown" public="20260826">CVE-2026-80561</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80557" impact="unknown" public="20260826">CVE-2026-80557</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72113" impact="unknown" public="20260815">CVE-2026-72113</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72066" impact="unknown" public="20260815">CVE-2026-72066</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68183" impact="unknown" public="20260810">CVE-2026-68183</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68250" impact="unknown" public="20260810">CVE-2026-68250</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72242" impact="unknown" public="20260815">CVE-2026-72242</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74497" impact="unknown" public="20260815">CVE-2026-74497</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74632" impact="unknown" public="20260822">CVE-2026-74632</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72023" impact="unknown" public="20260815">CVE-2026-72023</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2025-40054" impact="unknown" public="20251028">CVE-2025-40054</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72168" impact="unknown" public="20260815">CVE-2026-72168</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74581" impact="unknown" public="20260821">CVE-2026-74581</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74680" impact="unknown" public="20260822">CVE-2026-74680</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74623" impact="unknown" public="20260822">CVE-2026-74623</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80553" impact="unknown" public="20260826">CVE-2026-80553</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74656" impact="unknown" public="20260822">CVE-2026-74656</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68158" impact="unknown" public="20260810">CVE-2026-68158</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74482" impact="unknown" public="20260815">CVE-2026-74482</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74567" impact="unknown" public="20260815">CVE-2026-74567</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68123" impact="unknown" public="20260810">CVE-2026-68123</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68226" impact="unknown" public="20260810">CVE-2026-68226</cve>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-476" href="https://cve.tuxcare.com/els/cve/CVE-2026-64192" impact="moderate" public="20260720">CVE-2026-64192</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68294" impact="unknown" public="20260810">CVE-2026-68294</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72015" impact="unknown" public="20260815">CVE-2026-72015</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72073" impact="unknown" public="20260815">CVE-2026-72073</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74650" impact="unknown" public="20260822">CVE-2026-74650</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-64269" impact="unknown" public="20260725">CVE-2026-64269</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74662" impact="unknown" public="20260822">CVE-2026-74662</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74540" impact="unknown" public="20260815">CVE-2026-74540</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74556" impact="unknown" public="20260815">CVE-2026-74556</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80562" impact="unknown" public="20260826">CVE-2026-80562</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-64579" impact="unknown" public="20260805">CVE-2026-64579</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-64569" impact="unknown" public="20260805">CVE-2026-64569</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68395" impact="unknown" public="20260810">CVE-2026-68395</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68449" impact="unknown" public="20260812">CVE-2026-68449</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68373" impact="unknown" public="20260810">CVE-2026-68373</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72170" impact="unknown" public="20260815">CVE-2026-72170</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-64563" impact="unknown" public="20260804">CVE-2026-64563</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72119" impact="unknown" public="20260815">CVE-2026-72119</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74548" impact="unknown" public="20260815">CVE-2026-74548</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74588" impact="unknown" public="20260822">CVE-2026-74588</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74518" impact="unknown" public="20260815">CVE-2026-74518</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74492" impact="unknown" public="20260815">CVE-2026-74492</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-64590" impact="unknown" public="20260806">CVE-2026-64590</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74673" impact="unknown" public="20260822">CVE-2026-74673</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72308" impact="unknown" public="20260815">CVE-2026-72308</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-53090" impact="unknown" public="20260624">CVE-2026-53090</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68176" impact="unknown" public="20260810">CVE-2026-68176</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80559" impact="unknown" public="20260826">CVE-2026-80559</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68357" impact="unknown" public="20260810">CVE-2026-68357</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-68277" impact="unknown" public="20260810">CVE-2026-68277</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-80550" impact="unknown" public="20260826">CVE-2026-80550</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els/cve/CVE-2024-50125" impact="important" public="20241105">CVE-2024-50125</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74444" impact="unknown" public="20260815">CVE-2026-74444</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-72152" impact="unknown" public="20260815">CVE-2026-72152</cve>
          <cve href="https://cve.tuxcare.com/els/cve/CVE-2026-74458" impact="unknown" public="20260815">CVE-2026-74458</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="kernel earlier than linux-5.10.0-48-amd64 (or unknown) is currently running" test_ref="oval:com.tuxcare.clsa:tst:1788803338001"/>
        <criterion comment="bpftool is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338002"/>
        <criterion comment="hyperv-daemons is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338003"/>
        <criterion comment="libcpupower-dev is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338004"/>
        <criterion comment="libcpupower1 is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338005"/>
        <criterion comment="linux-compiler-gcc-10-arm is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338006"/>
        <criterion comment="linux-compiler-gcc-10-x86 is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338007"/>
        <criterion comment="linux-config-5.10 is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338008"/>
        <criterion comment="linux-cpupower is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338009"/>
        <criterion comment="linux-doc is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338010"/>
        <criterion comment="linux-doc-5.10 is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338011"/>
        <criterion comment="linux-headers-5.10.0-48-amd64 is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338012"/>
        <criterion comment="linux-headers-5.10.0-48-arm64 is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338013"/>
        <criterion comment="linux-headers-5.10.0-48-common is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338014"/>
        <criterion comment="linux-headers-5.10.0-48-marvell is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338015"/>
        <criterion comment="linux-headers-5.10.0-48-rpi is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338016"/>
        <criterion comment="linux-headers-amd64 is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338017"/>
        <criterion comment="linux-headers-arm64 is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338018"/>
        <criterion comment="linux-headers-marvell is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338019"/>
        <criterion comment="linux-headers-rpi is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338020"/>
        <criterion comment="linux-image-5.10.0-48-amd64-unsigned is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338021"/>
        <criterion comment="linux-image-5.10.0-48-arm64-unsigned is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338022"/>
        <criterion comment="linux-image-5.10.0-48-marvell is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338023"/>
        <criterion comment="linux-image-5.10.0-48-rpi is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338024"/>
        <criterion comment="linux-image-amd64 is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338025"/>
        <criterion comment="linux-image-amd64-signed-template is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338026"/>
        <criterion comment="linux-image-arm64 is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338027"/>
        <criterion comment="linux-image-arm64-signed-template is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338028"/>
        <criterion comment="linux-image-marvell is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338029"/>
        <criterion comment="linux-image-rpi is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338030"/>
        <criterion comment="linux-kbuild-5.10 is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338031"/>
        <criterion comment="linux-libc-dev is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338032"/>
        <criterion comment="linux-perf is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338033"/>
        <criterion comment="linux-perf-5.10 is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338034"/>
        <criterion comment="linux-source is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338035"/>
        <criterion comment="linux-source-5.10 is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338036"/>
        <criterion comment="linux-support-5.10.0-48 is earlier than 0:5.10.269-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788803338037"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1788819939" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-58016</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1788819939" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1788819939" source="CLSA"/>
        <reference ref_id="CVE-2026-58016" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-58016" source="CVE"/>
        <description>* SECURITY UPDATE: Out-of-bounds read in the D-Bus introspection XML parser
     - debian/patches/CVE-2026-58016.patch: fix the inverted &lt;node&gt; nesting
       check in parser_start_element() in gio/gdbusintrospection.c, which
       accepted a &lt;node&gt; element inside &lt;method&gt;/&lt;signal&gt;/&lt;property&gt;/&lt;arg&gt;
       and left the parser reading X-&gt;pdata[X-&gt;len - 1] with len == 0
     - CVE-2026-58016
   * debian/rules: add arm to the qemu-buildd architecture list, raising
     test_timeout_multiplier from 5 to 20 on armel. Debian builds armel on real
     ARM hardware and so left it in the "slow architecture" tier, but this
     platform builds it under emulation, where the +slow suite exceeds the
     resulting 900s cap non-deterministically (gvariant 435s/262s/timeout,
     642026 488s/501s/timeout across three runs of the same tree). No test is
     skipped and no other architecture is affected: arm64 and amd64 do not
     match the arm filter word.</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-07"/>
          <updated date="2026-09-07"/>
          <cve cvss3="9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" cwe="CWE-191" href="https://cve.tuxcare.com/els/cve/CVE-2026-58016" impact="critical" public="20260630">CVE-2026-58016</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="libglib2.0-0 is earlier than 0:2.66.8-1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788819939001"/>
        <criterion comment="libglib2.0-bin is earlier than 0:2.66.8-1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788819939002"/>
        <criterion comment="libglib2.0-data is earlier than 0:2.66.8-1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788819939003"/>
        <criterion comment="libglib2.0-dev is earlier than 0:2.66.8-1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788819939004"/>
        <criterion comment="libglib2.0-dev-bin is earlier than 0:2.66.8-1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788819939005"/>
        <criterion comment="libglib2.0-doc is earlier than 0:2.66.8-1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788819939006"/>
        <criterion comment="libglib2.0-tests is earlier than 0:2.66.8-1+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788819939007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1788884663" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-32748</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1788884663" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1788884663" source="CLSA"/>
        <reference ref_id="CVE-2026-32748" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-32748" source="CVE"/>
        <description>* SECURITY UPDATE: Fix HttpRequest use-after-free for ICP v3 queries
     - debian/patches/CVE-2026-32748.patch: move the icp_access check inside
       icpGetRequest() and return an HttpRequest::Pointer so the request
       survives the on-stack ACLFilledChecklist, eliminating the
       use-after-free in src/ICP.h, src/icp_v2.cc, src/icp_v3.cc and
       src/tests/stub_icp.cc
     - CVE-2026-32748</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-08"/>
          <updated date="2026-09-08"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-413" href="https://cve.tuxcare.com/els/cve/CVE-2026-32748" impact="important" public="20260326">CVE-2026-32748</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="squid is earlier than 0:4.13-10+deb11u7+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788884663001"/>
        <criterion comment="squid-cgi is earlier than 0:4.13-10+deb11u7+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788884663002"/>
        <criterion comment="squid-common is earlier than 0:4.13-10+deb11u7+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788884663003"/>
        <criterion comment="squid-openssl is earlier than 0:4.13-10+deb11u7+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788884663004"/>
        <criterion comment="squid-purge is earlier than 0:4.13-10+deb11u7+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788884663005"/>
        <criterion comment="squidclient is earlier than 0:4.13-10+deb11u7+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788884663006"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1788856712" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-55203</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1788856712" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1788856712" source="CLSA"/>
        <reference ref_id="CVE-2026-55203" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-55203" source="CVE"/>
        <description>* SECURITY UPDATE: FCGI demux record length integer overflow
     - debian/patches/CVE-2026-55203.patch: widen fcgi_conn.drl from uint16_t
       to uint32_t in src/mux_fcgi.c to prevent drl += drp overflow to 0
     - CVE-2026-55203</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-08"/>
          <updated date="2026-09-08"/>
          <cve cvss3="9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" cwe="CWE-190" href="https://cve.tuxcare.com/els/cve/CVE-2026-55203" impact="critical" public="20260618">CVE-2026-55203</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="haproxy is earlier than 0:2.2.9-2+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1788856712001"/>
        <criterion comment="haproxy-doc is earlier than 0:2.2.9-2+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1788856712002"/>
        <criterion comment="vim-haproxy is earlier than 0:2.2.9-2+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1788856712003"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1788943086" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-7598</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1788943086" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1788943086" source="CLSA"/>
        <reference ref_id="CVE-2026-7598" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-7598" source="CVE"/>
        <description>* SECURITY UPDATE: unchecked userauth input lengths let crafted username,
     password, hostname, method-name or public-key sizes wrap the packet-size
     arithmetic and produce an undersized heap allocation that is then
     overflowed
     - debian/patches/CVE-2026-7598.patch: cap every caller-supplied userauth
       input at MAX_INPUT_LEN before the allocation size is computed and
       return LIBSSH2_ERROR_OUT_OF_BOUNDARY instead, in userauth_list(),
       userauth_password(), userauth_hostbased_fromfile(),
       _libssh2_userauth_publickey() and userauth_keyboard_interactive() in
       src/userauth.c
     - CVE-2026-7598</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-09"/>
          <updated date="2026-09-09"/>
          <cve cvss3="9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" href="https://cve.tuxcare.com/els/cve/CVE-2026-7598" impact="critical" public="20260501">CVE-2026-7598</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="libssh2-1 is earlier than 0:1.9.0-2+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788943086001"/>
        <criterion comment="libssh2-1-dev is earlier than 0:1.9.0-2+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788943086002"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1788966943" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2022-45141</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1788966943" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1788966943" source="CLSA"/>
        <reference ref_id="CVE-2022-45141" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-45141" source="CVE"/>
        <description>* SECURITY UPDATE: AD DC can be forced to issue rc4-hmac Kerberos tickets
     even when the target server supports stronger encryption
     - debian/patches/CVE-2022-45141.patch: select the TGS ticket enc-part
       key from the server's preferred key rather than from the session key,
       so a server supporting aes256-cts-hmac-sha1-96 is no longer handed an
       rc4-hmac ticket
     - CVE-2022-45141</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-09"/>
          <updated date="2026-09-09"/>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-328" href="https://cve.tuxcare.com/els/cve/CVE-2022-45141" impact="critical" public="20230306">CVE-2022-45141</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="ctdb is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788966943001"/>
        <criterion comment="libnss-winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788966943002"/>
        <criterion comment="libpam-winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788966943003"/>
        <criterion comment="libsmbclient is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788966943004"/>
        <criterion comment="libsmbclient-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788966943005"/>
        <criterion comment="libwbclient-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788966943006"/>
        <criterion comment="libwbclient0 is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788966943007"/>
        <criterion comment="python3-samba is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788966943008"/>
        <criterion comment="registry-tools is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788966943009"/>
        <criterion comment="samba is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788966943010"/>
        <criterion comment="samba-common is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788966943011"/>
        <criterion comment="samba-common-bin is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788966943012"/>
        <criterion comment="samba-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788966943013"/>
        <criterion comment="samba-dsdb-modules is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788966943014"/>
        <criterion comment="samba-libs is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788966943015"/>
        <criterion comment="samba-testsuite is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788966943016"/>
        <criterion comment="samba-vfs-modules is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788966943017"/>
        <criterion comment="smbclient is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788966943018"/>
        <criterion comment="winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788966943019"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1788967622" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-34980</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1788967622" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1788967622" source="CLSA"/>
        <reference ref_id="CVE-2026-34980" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-34980" source="CVE"/>
        <description>* SECURITY UPDATE: filter control characters from option values in the
     scheduler to prevent PPD keyword injection via Print-Job.
     - debian/patches/CVE-2026-34980.patch: filter out control characters
       from IPP option values in scheduler/job.c and allowlist-filter
       special PPD keywords in the CUPSD_LOG_PPD branch of update_job();
       includes the upstream follow-ups for Issue #1532 (get_options() no
       longer loops forever on a value holding whitespace or a dropped
       control character), Issue #1562 (the allowlist advances its keyword
       pointer instead of testing keywords[0] repeatedly), Issue #1630
       (whitespace stays backslash-escaped, so cupsParseOptions() in the
       filters no longer truncates option values containing spaces) and
       the case-insensitive keyword comparison that closes a
       "cupsfilter2" spelling bypass of the allowlist.
     - CVE-2026-34980.
   * Make the package testable on the ELS build nodes.  None of these
     three changes is a CVE fix; the two patches are also carried by
     tuxcare-current/debian10els.
     - debian/patches/maxfds-limit.patch: cap MaxFDs at 65535 in
       scheduler/main.c, backported from upstream Issue #989
       (beb84401c6698dfe937178d8ac8fa38505468dbb), so cupsd stops
       aborting at startup with "cupsdDoSelect() failed - Bad address!"
       on hosts whose RLIMIT_NOFILE hard limit is very large but not
       RLIM_INFINITY.
     - debian/patches/waiting-limit.patch: bound the "waiting for the
       scheduler" loop in test/run-stp-tests.sh at 60 seconds and take
       the test user from "id -un", so a scheduler that will not start
       fails the build with a diagnostic instead of hanging until the
       build system's 12 hour task limit.
     - debian/rules: hand test/run-stp-tests.sh a free TCP port instead of
       letting its cupsd default to 8631.  CUPS_TESTBASE already keeps the
       config, spool, logs and domain socket of a run private, but pbuilder
       chroots share the host network namespace, so two cups builds on one
       node used to fight over that one port -- the second scheduler could
       not bind, the first answered its "lpstat -r" anyway, and both suites
       then drove a single cupsd, inflating every absolute count in the
       test summary.</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-09"/>
          <updated date="2026-09-09"/>
          <cve cvss3="7.5/CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-20" href="https://cve.tuxcare.com/els/cve/CVE-2026-34980" impact="important" public="20260403">CVE-2026-34980</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="cups is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788967622001"/>
        <criterion comment="cups-bsd is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788967622002"/>
        <criterion comment="cups-client is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788967622003"/>
        <criterion comment="cups-common is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788967622004"/>
        <criterion comment="cups-core-drivers is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788967622005"/>
        <criterion comment="cups-daemon is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788967622006"/>
        <criterion comment="cups-ipp-utils is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788967622007"/>
        <criterion comment="cups-ppdc is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788967622008"/>
        <criterion comment="cups-server-common is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788967622009"/>
        <criterion comment="libcups2 is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788967622010"/>
        <criterion comment="libcups2-dev is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788967622011"/>
        <criterion comment="libcupsimage2 is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788967622012"/>
        <criterion comment="libcupsimage2-dev is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788967622013"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1788968222" version="1">
      <metadata>
        <title>Fix of 5 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1788968222" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1788968222" source="CLSA"/>
        <reference ref_id="CVE-2026-56131" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-56131" source="CVE"/>
        <reference ref_id="CVE-2026-45186" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-45186" source="CVE"/>
        <reference ref_id="CVE-2026-56408" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-56408" source="CVE"/>
        <reference ref_id="CVE-2026-25210" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-25210" source="CVE"/>
        <reference ref_id="CVE-2026-56407" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-56407" source="CVE"/>
        <description>* SECURITY UPDATE: Use-after-free because handler call depth tracking
     was absent entirely, leaving XML_Parse, XML_ParseBuffer,
     XML_GetBuffer, XML_ParserFree, XML_ParserReset and XML_ResumeParser
     callable on the running parser from inside an application handler,
     and the XML_TOK_DATA_CHARS handler calls in doCdataSection() left
     untracked (libexpat before 2.8.2)
     - debian/patches/CVE-2026-56131.patch: introduce the handler call
       depth counter m_handlerCallDepth with the beforeHandler() /
       afterHandler() / isCalledFromInsideHandler() helpers from upstream
       PR #1246, wrap all 55 handler call sites in expat/lib/xmlparse.c,
       and reject the six affected entry points with XML_STATUS_ERROR /
       NULL when the counter is non-zero; XML_StopParser and
       XML_ExternalEntityParserCreate are deliberately left unguarded, as
       upstream intends.  Also carries upstream PR #1278, which wraps the
       two doCdataSection XML_TOK_DATA_CHARS charDataHandler calls that
       the original framework missed and through which the depth guard
       was otherwise bypassable.  Of the 55 wrapped call sites 53 are
       live; the other two sit inside expat's pre-existing
       "else if (0 &amp;&amp; ...)" disabled branches, which upstream 2.8.2 wraps
       as well.  Carries upstream's regression test into
       expat/tests/runtests.c.  Behaviour change inherited from upstream:
       leaving a handler through a non-local exit, such as a C++
       exception or longjmp(), skips afterHandler(), so the counter stays
       non-zero and every guarded entry point refuses from then on,
       XML_ParserFree() included.  Upstream accepts the resulting leak in
       place of a use-after-free and provides no way to clear the counter
     - CVE-2026-56131
     - CVE-2026-50219
     - CVE-2026-56412
   * SECURITY UPDATE: Quadratic runtime when detecting duplicate default
     attributes, allowing denial of service through a crafted DTD
     (libexpat before 2.8.1)
     - debian/patches/CVE-2026-45186.patch: add
       ELEMENT_TYPE.defaultAttsNames and resolve default-attribute
       collisions through a hash table lookup instead of a linear scan
       over defaultAtts in defineAttribute(), with matching
       hashTableInit()/hashTableDestroy() calls in storeAtts(),
       getElementType(), dtdCopy(), dtdReset() and dtdDestroy() in
       expat/lib/xmlparse.c.  The trade-off, upstream's as well, is one
       hash table per element type: a constant extra amount of memory and
       setup work per element type and per tag, linear in document size,
       in exchange for removing the quadratic term
     - CVE-2026-45186
   * SECURITY UPDATE: Integer overflow when reallocating the tag name
     conversion buffer (libexpat before 2.7.4)
     - debian/patches/CVE-2026-25210.patch: reject a doubling that would
       overflow before it happens (SIZE_MAX / 2 pre-check) and widen
       doContent()'s bufSize from int to size_t in expat/lib/xmlparse.c.
       Also carries the storeRawNames() half of upstream commit
       25ec4f1b, which widens that function's bufSize and nameLen to
       size_t.  Upstream released 25ec4f1b in 2.7.2, ahead of this fix in
       2.7.4, and it is a prerequisite rather than cosmetics: once
       tag-&gt;buf is allowed past INT_MAX bytes, the (int) narrowing of
       convLen in doContent() can store a negative tag-&gt;name.strLen, and
       storeRawNames() would then compute a negative int bufSize, skip
       its reallocation and memcpy() below the buffer.  Widened, the same
       value becomes a huge size_t, the reallocation fails and the
       function returns XML_FALSE, which is how upstream 2.7.4 behaves
     - CVE-2026-25210
   * SECURITY UPDATE: Integer overflow in doProlog related to
     storeEntityValue and entity textLen (libexpat before 2.8.2)
     - debian/patches/CVE-2026-56407.patch: cap the entity value pool
       length against INT_MAX before assigning m_declEntity-&gt;textLen in
       expat/lib/xmlparse.c.  The second hunk of upstream commit
       30c2fc17 is omitted because it targets storeSelfEntityValue(),
       which arrived in expat 2.6.0 and does not exist here
     - CVE-2026-56407
   * SECURITY UPDATE: Integer overflow in copyString (libexpat before
     2.8.2)
     - debian/patches/CVE-2026-56408.patch: reject
       charsRequired &gt; SIZE_MAX / sizeof(XML_Char) before the allocation
       in copyString() in expat/lib/xmlparse.c.  This is upstream parity
       hardening rather than a live fix on 2.2.10: charsRequired is a
       size_t holding the length of the application-supplied encoding
       name rather than of document content, so tripping the guard would
       need a string larger than the address space even in the
       -DXML_UNICODE (buildw) library that debian/rules also builds,
       where sizeof(XML_Char) is 2
     - CVE-2026-56408</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-09"/>
          <updated date="2026-09-09"/>
          <cve cwe="CWE-416" href="https://cve.tuxcare.com/els/cve/CVE-2026-56131" impact="unknown" public="20260619">CVE-2026-56131</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-407" href="https://cve.tuxcare.com/els/cve/CVE-2026-45186" impact="important" public="20260510">CVE-2026-45186</cve>
          <cve cwe="CWE-190" href="https://cve.tuxcare.com/els/cve/CVE-2026-56408" impact="unknown" public="20260621">CVE-2026-56408</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-190" href="https://cve.tuxcare.com/els/cve/CVE-2026-25210" impact="important" public="20260130">CVE-2026-25210</cve>
          <cve cwe="CWE-190" href="https://cve.tuxcare.com/els/cve/CVE-2026-56407" impact="unknown" public="20260621">CVE-2026-56407</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="expat is earlier than 0:2.2.10-2+deb11u7+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788968222001"/>
        <criterion comment="libexpat1 is earlier than 0:2.2.10-2+deb11u7+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788968222002"/>
        <criterion comment="libexpat1-dev is earlier than 0:2.2.10-2+deb11u7+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1788968222003"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789049274" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-23631</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789049274" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789049274" source="CLSA"/>
        <reference ref_id="CVE-2026-23631" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-23631" source="CVE"/>
        <description>* SECURITY UPDATE: Lua VM re-entry when a resync payload is processed while a
     timed-out script is still on the stack
     - debian/patches/0027-CVE-2026-23631.patch: return early from
       readSyncBulkPayload() in src/replication.c while server.lua_timedout is
       set, so rdbLoadRio() cannot reach luaCreateFunction() on the lua_State
       that is paused inside the running script. Backport of upstream redis
       commit 80c2b5a0a, substituting server.lua_timedout for the 7.0
       isInsideYieldingLongCommand() helper. Applied as defence in depth: the
       use-after-free CVE-2026-23631 describes is not reachable on 6.0.16, where
       scriptingReset() is reached only via SCRIPT FLUSH and not from the resync
       path.
     - CVE-2026-23631</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-10"/>
          <updated date="2026-09-10"/>
          <cve cvss3="8.1/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els/cve/CVE-2026-23631" impact="important" public="20260505">CVE-2026-23631</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="redis is earlier than 5:6.0.16-1+deb11u9+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789049274001"/>
        <criterion comment="redis-sentinel is earlier than 5:6.0.16-1+deb11u9+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789049274002"/>
        <criterion comment="redis-server is earlier than 5:6.0.16-1+deb11u9+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789049274003"/>
        <criterion comment="redis-tools is earlier than 5:6.0.16-1+deb11u9+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789049274004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789116242" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2018-6952</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789116242" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789116242" source="CLSA"/>
        <reference ref_id="CVE-2018-6952" ref_url="https://cve.tuxcare.com/els/cve/CVE-2018-6952" source="CVE"/>
        <description>* SECURITY UPDATE: Double free in another_hunk() via pch_swap()
     - debian/patches/CVE-2018-6952.patch: in pch_swap(), src/pch.c, derive
       the non-freeable pointer range shift from p_ptrn_lines instead of the
       already-incremented line index, so p_bfake/p_efake keep bracketing the
       aliased fill lines after a swap. With a blank line in the middle of a
       context-diff hunk the range was off by one and the next
       another_hunk() call freed an aliased line twice
     - CVE-2018-6952</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-11"/>
          <updated date="2026-09-11"/>
          <cve cvss2="5.0/AV:N/AC:L/Au:N/C:N/I:N/A:P" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-415" href="https://cve.tuxcare.com/els/cve/CVE-2018-6952" impact="important" public="20180213">CVE-2018-6952</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="patch is earlier than 0:2.7.6-7+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789116242001"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789142195" version="1">
      <metadata>
        <title>Fix of 6 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789142195" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789142195" source="CLSA"/>
        <reference ref_id="CVE-2026-66141" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-66141" source="CVE"/>
        <reference ref_id="CVE-2026-40684" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-40684" source="CVE"/>
        <reference ref_id="CVE-2026-40687" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-40687" source="CVE"/>
        <reference ref_id="CVE-2026-66140" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-66140" source="CVE"/>
        <reference ref_id="CVE-2026-40685" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-40685" source="CVE"/>
        <reference ref_id="CVE-2026-40686" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-40686" source="CVE"/>
        <description>* SECURITY UPDATE: out-of-bounds read in DNS name escape decoding when
     running against musl libc
     - debian/patches/CVE-2026-40684.patch: rewrite the escape-decoding loop
       of string_copy_dnsdomain() to consume one, two or three digits as
       available instead of blindly indexing s[1], s[2], s[3] and advancing
       four bytes, and drop the second pointer advance in the non-digit
       branch so a trailing lone backslash cannot read past the terminating
       NUL
     - CVE-2026-40684
   * SECURITY UPDATE: heap out-of-bounds write in JSON string expansions
     - debian/patches/CVE-2026-40685.patch: in dewrap(), only skip a
       backslash when a non-NUL character follows it, so a value ending in a
       single trailing backslash can no longer walk past the end of the
       string and write beyond the destination buffer
     - CVE-2026-40685
   * SECURITY UPDATE: heap read past the end of the input in UTF-8 expansion
     operators, allowing data exfiltration through an SMTP rejection message
     - debian/patches/CVE-2026-40686.patch: stop the continuation-byte loop
       of the GETUTF8INC macro at the terminating NUL, so malformed UTF-8
       that declares more continuation bytes than are present no longer
       reads into adjacent heap
     - CVE-2026-40686
   * SECURITY UPDATE: uninitialised-memory disclosure and static buffer
     overflows in the SPA (NTLM) authenticator
     - debian/patches/CVE-2026-40687.patch: zero the output buffer at the
       top of spa_base64_to_bits() so a short encoded input no longer leaves
       previous heap contents in the SPA challenge/response flow, and
       replace the assert() guards in unicodeToString(), strToUnicode() and
       toString() with explicit length clamping, since assert() compiles
       away under NDEBUG and leaves an unchecked write past the end of the
       1024-byte static buffers; also clamp the length used by the
       spa_unicode_add_string macro, which states the truncation contract
       at the call site (spa_bytes_add() already bounds-checks the copy
       itself)
     - CVE-2026-40687
   * SECURITY UPDATE: directory traversal outside the spool area through
     mishandled named-queue arguments, leading to privilege escalation
     - debian/patches/CVE-2026-66140.patch: add validate_queue_name() and
       apply it to both command-line sources of a queue name, -MCG &lt;name&gt;
       and -q[f][f][l]G&lt;name&gt;, rejecting a name that contains '/', is longer
       than 32 characters, or collides with one of the reserved spool
       subdirectories input, db, msglog and scan; mark -MC and every -MCx
       argument as admin-only and refuse them for a non-admin caller
     - CVE-2026-66140
   * SECURITY UPDATE: .forward privilege escalation caused by expansion of
     the pipe command under force_command
     - debian/patches/CVE-2026-66141.patch: stop passing addr-&gt;local_part
       through expand_string() in the $address_pipe special case of a pipe
       transport that has force_command set, so command text supplied by a
       local user in a .forward file is only dequoted and split into
       arguments instead of being evaluated with the transport's privileges
     - CVE-2026-66141</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-11"/>
          <updated date="2026-09-11"/>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-829" href="https://cve.tuxcare.com/els/cve/CVE-2026-66141" impact="important" public="20260724">CVE-2026-66141</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-684" href="https://cve.tuxcare.com/els/cve/CVE-2026-40684" impact="important" public="20260430">CVE-2026-40684</cve>
          <cve cvss3="9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" cwe="CWE-909" href="https://cve.tuxcare.com/els/cve/CVE-2026-40687" impact="critical" public="20260430">CVE-2026-40687</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-24" href="https://cve.tuxcare.com/els/cve/CVE-2026-66140" impact="important" public="20260724">CVE-2026-66140</cve>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-684" href="https://cve.tuxcare.com/els/cve/CVE-2026-40685" impact="critical" public="20260430">CVE-2026-40685</cve>
          <cve cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" cwe="CWE-125" href="https://cve.tuxcare.com/els/cve/CVE-2026-40686" impact="moderate" public="20260430">CVE-2026-40686</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="exim4 is earlier than 0:4.94.2-7+deb11u6+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789142195001"/>
        <criterion comment="exim4-base is earlier than 0:4.94.2-7+deb11u6+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789142195002"/>
        <criterion comment="exim4-config is earlier than 0:4.94.2-7+deb11u6+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789142195003"/>
        <criterion comment="exim4-daemon-heavy is earlier than 0:4.94.2-7+deb11u6+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789142195004"/>
        <criterion comment="exim4-daemon-light is earlier than 0:4.94.2-7+deb11u6+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789142195005"/>
        <criterion comment="exim4-dev is earlier than 0:4.94.2-7+deb11u6+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789142195006"/>
        <criterion comment="eximon4 is earlier than 0:4.94.2-7+deb11u6+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789142195007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789202428" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2018-1000500, CVE-2021-42383, CVE-2022-28391, CVE-2023-39810</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789202428" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789202428" source="CLSA"/>
        <reference ref_id="CVE-2022-28391" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-28391" source="CVE"/>
        <reference ref_id="CVE-2023-39810" ref_url="https://cve.tuxcare.com/els/cve/CVE-2023-39810" source="CVE"/>
        <reference ref_id="CVE-2018-1000500" ref_url="https://cve.tuxcare.com/els/cve/CVE-2018-1000500" source="CVE"/>
        <reference ref_id="CVE-2021-42383" ref_url="https://cve.tuxcare.com/els/cve/CVE-2021-42383" source="CVE"/>
        <description>* SECURITY UPDATE
     - CVE-2018-1000500: missing TLS certificate verification in
       spawn_https_helper_openssl()
     - CVE-2021-42383: use-after-free in evaluate() on field concatenation
     - CVE-2022-28391: terminal escape injection in sockaddr2str() and
       nslookup parse_reply()
     - CVE-2023-39810: directory traversal in data_extract_all()
   * debian/config/pkg/{deb,static,udeb}: FEATURE_PATH_TRAVERSAL_PROTECTION=y,
     the CVE-2023-39810 guard is compiled out without it
   * debian/testsuite-linux.diff: disable the cpio uid/gid test, it is
     environment dependent and fails the same way on an unpatched tree</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-12"/>
          <updated date="2026-09-12"/>
          <cve cvss2="6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P" cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://cve.tuxcare.com/els/cve/CVE-2022-28391" impact="important" public="20220403">CVE-2022-28391</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-22" href="https://cve.tuxcare.com/els/cve/CVE-2023-39810" impact="important" public="20230828">CVE-2023-39810</cve>
          <cve cvss2="6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P" cvss3="8.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-295" href="https://cve.tuxcare.com/els/cve/CVE-2018-1000500" impact="important" public="20180626">CVE-2018-1000500</cve>
          <cve cvss2="6.5/AV:N/AC:L/Au:S/C:P/I:P/A:P" cvss3="7.2/CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els/cve/CVE-2021-42383" impact="important" public="20211115">CVE-2021-42383</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="busybox is earlier than 1:1.30.1-6+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789202428001"/>
        <criterion comment="busybox-static is earlier than 1:1.30.1-6+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789202428002"/>
        <criterion comment="busybox-syslogd is earlier than 1:1.30.1-6+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789202428003"/>
        <criterion comment="udhcpc is earlier than 1:1.30.1-6+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789202428004"/>
        <criterion comment="udhcpd is earlier than 1:1.30.1-6+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789202428005"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789205560" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-41992</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789205560" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789205560" source="CLSA"/>
        <reference ref_id="CVE-2026-41992" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-41992" source="CVE"/>
        <description>* SECURITY UPDATE: out-of-bounds read in the LZH decoder
     - debian/patches/CVE-2026-41992.patch: clear left, right and c_table in
       huf_decode_start() in unlzh.c
     - CVE-2026-41992</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-12"/>
          <updated date="2026-09-12"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" cwe="CWE-126" href="https://cve.tuxcare.com/els/cve/CVE-2026-41992" impact="important" public="20260629">CVE-2026-41992</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="gzip is earlier than 0:1.10-4+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789205560001"/>
        <criterion comment="gzip-win32 is earlier than 0:1.10-4+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789205560002"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789205759" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-58050, CVE-2026-66032</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789205759" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789205759" source="CLSA"/>
        <reference ref_id="CVE-2026-66032" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-66032" source="CVE"/>
        <reference ref_id="CVE-2026-58050" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-58050" source="CVE"/>
        <description>* SECURITY UPDATE: unchecked 32-bit attribute count from a publickey
     subsystem response is multiplied by the attribute size without a
     bounds check, so on 32-bit builds the product wraps to an undersized
     allocation that the parsing loop then overflows
     - debian/patches/CVE-2026-58050.patch: cap the attribute count at
       1024 and fail with LIBSSH2_ERROR_OUT_OF_BOUNDARY before the
       allocation, and zero-initialise the freshly reallocated list entry
       so the new error path cannot free uninitialised attrs/packet
       pointers in libssh2_publickey_list_free(), in
       libssh2_publickey_list_fetch() in src/publickey.c
     - CVE-2026-58050
   * SECURITY UPDATE: double free in sftp_open() lets a malicious SSH
     server corrupt the heap of an authenticated client opening an SFTP
     session
     - debian/patches/CVE-2026-66032.patch: set data to NULL after freeing
       the SSH_FXP_STATUS response buffer on the FX_OK path, so the
       if(badness) arm cannot free the same pointer a second time when the
       follow-up sftp_packet_require() for SSH_FXP_HANDLE fails, in
       sftp_open() in src/sftp.c
     - CVE-2026-66032</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-12"/>
          <updated date="2026-09-12"/>
          <cve cwe="CWE-415" href="https://cve.tuxcare.com/els/cve/CVE-2026-66032" impact="unknown" public="20260724">CVE-2026-66032</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-190" href="https://cve.tuxcare.com/els/cve/CVE-2026-58050" impact="important" public="20260628">CVE-2026-58050</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="libssh2-1 is earlier than 0:1.9.0-2+deb11u1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789205759001"/>
        <criterion comment="libssh2-1-dev is earlier than 0:1.9.0-2+deb11u1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789205759002"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789206875" version="1">
      <metadata>
        <title>Fix of 10 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789206875" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789206875" source="CLSA"/>
        <reference ref_id="CVE-2022-0368" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-0368" source="CVE"/>
        <reference ref_id="CVE-2022-1629" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-1629" source="CVE"/>
        <reference ref_id="CVE-2022-2182" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-2182" source="CVE"/>
        <reference ref_id="CVE-2022-1621" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-1621" source="CVE"/>
        <reference ref_id="CVE-2026-57456" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-57456" source="CVE"/>
        <reference ref_id="CVE-2026-59858" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-59858" source="CVE"/>
        <reference ref_id="CVE-2022-2257" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-2257" source="CVE"/>
        <reference ref_id="CVE-2022-1968" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-1968" source="CVE"/>
        <reference ref_id="CVE-2026-55895" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-55895" source="CVE"/>
        <reference ref_id="CVE-2022-1735" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-1735" source="CVE"/>
        <description>* SECURITY UPDATE: out-of-bounds read when undo makes the Visual area
     invalid
     - debian/patches/CVE-2022-0368.patch: correct the Visual area after undo
       in src/undo.c, add test to src/testdir/test_visual.vim.
     - CVE-2022-0368
   * SECURITY UPDATE: buffer overflow in the spell suggest code after invalid
     bytes are added with :spellgood
     - debian/patches/CVE-2022-1621.patch: reject words that are not a valid
       utf-8 string in store_word() and spell_add_word() in src/spellfile.c,
       add the E1280 message to src/errors.h, build utf_valid_string() when
       FEAT_SPELL is enabled in src/mbyte.c, add test to
       src/testdir/test_spell_utf8.vim.
     - CVE-2022-1621
   * SECURITY UPDATE: buffer over-read on a trailing escape character in
     quote text objects
     - debian/patches/CVE-2022-1629.patch: check for NUL after the escape
       character in find_next_quote() in src/textobject.c, add test to
       src/testdir/test_textobjects.vim.
     - CVE-2022-1629
   * SECURITY UPDATE: heap buffer overflow when text is changed in Visual
     mode
     - debian/patches/CVE-2022-1735.patch: revalidate the Visual start
       position after a buffer change; add check_visual_pos() in src/misc2.c,
       src/proto/misc2.pro and call it from changed_common() in src/change.c
       and stop_insert() in src/edit.c; add test to
       src/testdir/test_visual.vim.
     - CVE-2022-1735
   * SECURITY UPDATE: use-after-free when searching for a pattern in path
     - debian/patches/CVE-2022-1968.patch: copy the buffer line into the
       file_line buffer before matching in find_pattern_in_path(), in
       src/search.c; add test in src/testdir/test_tagjump.vim.
     - CVE-2022-1968
   * SECURITY UPDATE: heap buffer over-read with a line-zero address ("0;'(")
     - debian/patches/CVE-2022-2182.patch: check that the cursor column is
       valid for line one when the address is zero, in parse_cmd_address() in
       src/ex_docmd.c; add regression test in src/testdir/test_cmdline.vim.
     - CVE-2022-2182
   * SECURITY UPDATE: out-of-bounds read with a menu item consisting of only
     a modifier
     - debian/patches/CVE-2022-2257.patch: check for NUL before advancing
       past the end of the string in str2special() in src/message.c, add test
       to src/testdir/test_menu.vim.
     - CVE-2022-2257
   * SECURITY UPDATE: Ex command injection in netrw remote file browsing
     - debian/patches/CVE-2026-55895.patch: use fnameescape() on the buffer
       name before passing it to :execute in s:NetrwBrowse() in
       runtime/autoload/netrw.vim.
     - CVE-2026-55895
   * SECURITY UPDATE: arbitrary code execution via a crafted doc string in
     python omni-completion
     - debian/patches/CVE-2026-57456.patch: quote reconstructed doc strings
       with repr() instead of pasting them between literal triple quotes, in
       the Scope, Class and Function get_code() methods in
       runtime/autoload/python3complete.vim and
       runtime/autoload/pythoncomplete.vim.
     - CVE-2026-57456
   * SECURITY UPDATE: arbitrary Ex command execution during C omni-completion
     - debian/patches/CVE-2026-59858.patch: escape the tags typeref/typename
       field with escape(typename, '/\') before interpolating it into the
       :vimgrep pattern in s:StructMembers() in
       runtime/autoload/ccomplete.vim; add test in
       src/testdir/test_plugin_ccomplete.vim, src/testdir/Make_all.mak.
     - CVE-2026-59858
   * Fix the failing Test_terminal_cwd()
     - debian/patches/fix-Test_terminal_cwd.patch: join two lines to prevent
       fail on a long pathname
   * Fix the failing Test_quit_long_message()
     - debian/patches/fix-Test_quit_long_message.patch: wait for the more
       prompt instead of the ruler and dump 10 screen rows, so a long build
       pathname in the error message does not overflow the test terminal
   * Fix the tests that fail when the package is built as root
     - debian/patches/fix-tests-run-as-root.patch: guard the four
       permission-dependent tests with CheckNotRoot, splitting the read-only
       cases of Test_redir_cmd() and Test_helptag_cmd() into their own tests
   * Fix the tests that fail on the timing of the arm builders
     - debian/patches/fix-mouse-click-test-timing.patch: raise 'mousetime' in
       the two multiple-click mouse tests
     - debian/patches/fix-tests-tolerate-flaky-giveup.patch: add
       $TEST_MAY_FAIL_FLAKY, set by debian/rules on the non-amd64 targets, to
       report a given-up flaky test instead of failing the build
     - debian/patches/fix-tests-stray-swapfiles.patch: drop leftover scratch
       swap files between test files, so E325 cannot cascade</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-12"/>
          <updated date="2026-09-12"/>
          <cve cvss2="6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-125" href="https://cve.tuxcare.com/els/cve/CVE-2022-0368" impact="important" public="20220126">CVE-2022-0368</cve>
          <cve cvss2="6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-126" href="https://cve.tuxcare.com/els/cve/CVE-2022-1629" impact="important" public="20220510">CVE-2022-1629</cve>
          <cve cvss2="6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-122" href="https://cve.tuxcare.com/els/cve/CVE-2022-2182" impact="important" public="20220623">CVE-2022-2182</cve>
          <cve cvss2="6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-122" href="https://cve.tuxcare.com/els/cve/CVE-2022-1621" impact="important" public="20220510">CVE-2022-1621</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-94" href="https://cve.tuxcare.com/els/cve/CVE-2026-57456" impact="important" public="20260625">CVE-2026-57456</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-94" href="https://cve.tuxcare.com/els/cve/CVE-2026-59858" impact="important" public="20260709">CVE-2026-59858</cve>
          <cve cvss2="6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-125" href="https://cve.tuxcare.com/els/cve/CVE-2022-2257" impact="important" public="20220630">CVE-2022-2257</cve>
          <cve cvss2="6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els/cve/CVE-2022-1968" impact="important" public="20220602">CVE-2022-1968</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-78" href="https://cve.tuxcare.com/els/cve/CVE-2026-55895" impact="important" public="20260625">CVE-2026-55895</cve>
          <cve cvss2="6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-120" href="https://cve.tuxcare.com/els/cve/CVE-2022-1735" impact="important" public="20220517">CVE-2022-1735</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="vim is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789206875001"/>
        <criterion comment="vim-athena is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789206875002"/>
        <criterion comment="vim-common is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789206875003"/>
        <criterion comment="vim-doc is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789206875004"/>
        <criterion comment="vim-gtk is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789206875005"/>
        <criterion comment="vim-gtk3 is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789206875006"/>
        <criterion comment="vim-gui-common is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789206875007"/>
        <criterion comment="vim-nox is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789206875008"/>
        <criterion comment="vim-runtime is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789206875009"/>
        <criterion comment="vim-tiny is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789206875010"/>
        <criterion comment="xxd is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789206875011"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789289969" version="1">
      <metadata>
        <title>Fix of 5 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789289969" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789289969" source="CLSA"/>
        <reference ref_id="CVE-2026-6276" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-6276" source="CVE"/>
        <reference ref_id="CVE-2026-8927" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-8927" source="CVE"/>
        <reference ref_id="CVE-2026-8932" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-8932" source="CVE"/>
        <reference ref_id="CVE-2026-8286" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-8286" source="CVE"/>
        <reference ref_id="CVE-2026-5773" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-5773" source="CVE"/>
        <description>* SECURITY UPDATE: wrong reuse of SMB connection
     - debian/patches/CVE-2026-5773.patch: disable connection reuse for SMB
       and SMBS by closing the connection in smb_connect() in lib/smb.c.
     - CVE-2026-5773
   * SECURITY UPDATE: stale custom cookie host causes cookie leak
     - debian/patches/CVE-2026-6276.patch: clear the remembered custom
       Host: name at the start of every request in lib/http.c.
     - CVE-2026-6276
   * SECURITY UPDATE: wrong STARTTLS connection reuse
     - debian/patches/CVE-2026-8286.patch: require a matching SSL
       configuration when reusing a connection for a transfer that may
       upgrade to TLS in lib/url.c.
     - CVE-2026-8286
   * SECURITY UPDATE: env-set cross-proxy Digest auth state leak
     - debian/patches/CVE-2026-8927.patch: flush the proxy Digest state
       when the proxy read from the environment changes in lib/url.c,
       lib/urldata.h.
     - CVE-2026-8927
   * SECURITY UPDATE: incomplete mTLS config in connection reuse and TLS
     session cache
     - debian/patches/CVE-2026-8932.patch: include the client private key
       options in the primary SSL config so connection reuse and the TLS
       session cache compare them in lib/url.c, lib/urldata.h,
       lib/vtls/vtls.c.
     - CVE-2026-8932</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-13"/>
          <updated date="2026-09-13"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-319" href="https://cve.tuxcare.com/els/cve/CVE-2026-6276" impact="important" public="20260513">CVE-2026-6276</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" cwe="CWE-294" href="https://cve.tuxcare.com/els/cve/CVE-2026-8927" impact="important" public="20260703">CVE-2026-8927</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://cve.tuxcare.com/els/cve/CVE-2026-8932" impact="important" public="20260703">CVE-2026-8932</cve>
          <cve cvss3="8.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" cwe="CWE-295" href="https://cve.tuxcare.com/els/cve/CVE-2026-8286" impact="important" public="20260703">CVE-2026-8286</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" cwe="CWE-918" href="https://cve.tuxcare.com/els/cve/CVE-2026-5773" impact="important" public="20260513">CVE-2026-5773</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="curl is earlier than 0:7.74.0-1.3+deb11u16+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789289969001"/>
        <criterion comment="libcurl3-gnutls is earlier than 0:7.74.0-1.3+deb11u16+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789289969002"/>
        <criterion comment="libcurl3-nss is earlier than 0:7.74.0-1.3+deb11u16+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789289969003"/>
        <criterion comment="libcurl4 is earlier than 0:7.74.0-1.3+deb11u16+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789289969004"/>
        <criterion comment="libcurl4-doc is earlier than 0:7.74.0-1.3+deb11u16+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789289969005"/>
        <criterion comment="libcurl4-gnutls-dev is earlier than 0:7.74.0-1.3+deb11u16+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789289969006"/>
        <criterion comment="libcurl4-nss-dev is earlier than 0:7.74.0-1.3+deb11u16+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789289969007"/>
        <criterion comment="libcurl4-openssl-dev is earlier than 0:7.74.0-1.3+deb11u16+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789289969008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789290988" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2024-52005</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789290988" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789290988" source="CLSA"/>
        <reference ref_id="CVE-2024-52005" ref_url="https://cve.tuxcare.com/els/cve/CVE-2024-52005" source="CVE"/>
        <description>* SECURITY UPDATE: ANSI escape sequence injection via the sideband
     channel, allowing a malicious remote to corrupt terminal state, hide
     information, or insert characters into the terminal input buffer
     during clone, fetch and push (CWE-150)
     - debian/patches/CVE-2024-52005.patch: add strbuf_add_sanitized() in
       sideband.c and route the two remote-controlled sideband writes
       through it, replacing control characters with the conventional
       ^&lt;letter&gt; notation (^[ for ESC, ^A for 0x01, ^? for DEL) while
       letting tab and newline through.  Also carries upstream's
       t5409-colorize-remote-messages.sh regression test.
     - CVE-2024-52005
   * debian/rules: skip the git-svn test suite on armel only.  Subversion's
     directory I/O goes through APR, and Debian's armel libapr1 links the
     non-LFS readdir(), so dirent.d_ino is 32 bit there; when the source
     tree lives on a filesystem handing out inode numbers &gt;= 2^32 every
     git-svn test aborts with "svn: E000075: Can't read directory ...:
     Value too large for defined data type".  This is a limitation of the
     build environment, not a defect in git -- Debian's own armel buildd
     runs the same tests successfully.  All other architectures continue
     to run the git-svn suite in full.</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-13"/>
          <updated date="2026-09-13"/>
          <cve cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-116" href="https://cve.tuxcare.com/els/cve/CVE-2024-52005" impact="important" public="20250115">CVE-2024-52005</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="git is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789290988001"/>
        <criterion comment="git-all is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789290988002"/>
        <criterion comment="git-cvs is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789290988003"/>
        <criterion comment="git-daemon-run is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789290988004"/>
        <criterion comment="git-daemon-sysvinit is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789290988005"/>
        <criterion comment="git-doc is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789290988006"/>
        <criterion comment="git-el is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789290988007"/>
        <criterion comment="git-email is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789290988008"/>
        <criterion comment="git-gui is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789290988009"/>
        <criterion comment="git-man is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789290988010"/>
        <criterion comment="git-mediawiki is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789290988011"/>
        <criterion comment="git-svn is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789290988012"/>
        <criterion comment="gitk is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789290988013"/>
        <criterion comment="gitweb is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789290988014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789291176" version="1">
      <metadata>
        <title>Fix of 7 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789291176" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789291176" source="CLSA"/>
        <reference ref_id="CVE-2026-58010" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-58010" source="CVE"/>
        <reference ref_id="CVE-2026-58012" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-58012" source="CVE"/>
        <reference ref_id="CVE-2025-13601" ref_url="https://cve.tuxcare.com/els/cve/CVE-2025-13601" source="CVE"/>
        <reference ref_id="CVE-2026-58013" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-58013" source="CVE"/>
        <reference ref_id="CVE-2026-58011" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-58011" source="CVE"/>
        <reference ref_id="CVE-2026-58015" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-58015" source="CVE"/>
        <reference ref_id="CVE-2026-58014" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-58014" source="CVE"/>
        <description>* SECURITY UPDATE: Integer overflow into heap buffer overflow when escaping
     a URI string
     - debian/patches/gconvert-Error-out-if-g_escape_uri_string-would-overflow.patch:
       add this patch to debian/patches/series. The file already shipped in
       2.66.8-1+deb11u7, and that upload's changelog announces the CVE as
       fixed, but the patch was never added to the series and so was never
       applied: it is the only orphan in the 97-entry quilt stack, while every
       other CVE patch from the same entry (CVE-2025-14087, CVE-2025-4373,
       CVE-2025-7039) is listed. The shipped library therefore still counts
       unacceptable characters in a gint in g_escape_uri_string() in
       glib/gconvert.c, so g_malloc() is called with
       p - string + unacceptable * 2 + 1 after the multiplication has wrapped
       to INT_MIN. Confirmed against the stock Debian 11 libglib2.0-0
       2.66.8-1+deb11u8: g_filename_to_uri() on a path of 2^30 escapable
       characters aborts in gmem.c with "failed to allocate
       18446744072635809794 bytes", i.e. the negative sum widened to gsize.
       The patch is the vendor's own file and is added verbatim, unmodified.
     - CVE-2025-13601
   * SECURITY UPDATE: Off-by-one over-read in the GVariant tuple deserialiser
     - debian/patches/CVE-2026-58010.patch: correct the padding bounds test in
       gvs_tuple_is_normal() in glib/gvariant-serialiser.c from
       offset &gt; value.size to offset &gt;= value.size, which allowed a one-byte
       read past the end of the serialised data
     - CVE-2026-58010
   * SECURITY UPDATE: Missing range validation in g_date_time_add_full()
     - debian/patches/CVE-2026-58011.patch: reject results outside
       0001-01-01..9999-12-31 in glib/gdatetime.c instead of leaving the
       "XXX validate" placeholder, preventing a two-byte over-read when the
       computed day count falls outside the representable range
     - CVE-2026-58011
   * SECURITY UPDATE: Buffer over-read in g_regex_replace() in raw mode
     - debian/patches/CVE-2026-58012.patch: handle case-changing substitutions
       byte-wise rather than as UTF-8 in glib/gregex.c when the pattern was
       compiled with G_REGEX_RAW, where the subject is not required to be
       valid UTF-8
     - CVE-2026-58012
   * SECURITY UPDATE: memcmp() past the end of the buffer in GIOChannel
     - debian/patches/CVE-2026-58013.patch: bound the line-terminator
       comparison in glib/giochannel.c by the remaining buffer length, which
       was over-read when a custom terminator is longer than the data left
     - CVE-2026-58013
   * SECURITY UPDATE: One-byte heap under-read in GKeyFile
     - debian/patches/CVE-2026-58014.patch: guard the trailing-separator test
       in g_key_file_get_locale_string_list() in glib/gkeyfile.c with len &gt; 0,
       which indexed value[-1] for an empty value
     - CVE-2026-58014
   * SECURITY UPDATE: Path traversal via the D-Bus SHA-1 cookie context
     - debian/patches/CVE-2026-58015.patch: validate the server-supplied
       cookie context in gio/gdbusauthmechanismsha1.c against the D-Bus
       specification before using it as a keyring filename, so a malicious
       peer cannot direct the client to hash arbitrary files
     - CVE-2026-58015</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-13"/>
          <updated date="2026-09-13"/>
          <cve cvss3="8.2/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H" cwe="CWE-126" href="https://cve.tuxcare.com/els/cve/CVE-2026-58010" impact="important" public="20260630">CVE-2026-58010</cve>
          <cve cvss3="8.2/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H" cwe="CWE-126" href="https://cve.tuxcare.com/els/cve/CVE-2026-58012" impact="important" public="20260630">CVE-2026-58012</cve>
          <cve cvss3="7.7/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" cwe="CWE-190" href="https://cve.tuxcare.com/els/cve/CVE-2025-13601" impact="important" public="20251126">CVE-2025-13601</cve>
          <cve cvss3="8.2/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H" cwe="CWE-126" href="https://cve.tuxcare.com/els/cve/CVE-2026-58013" impact="important" public="20260630">CVE-2026-58013</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-125" href="https://cve.tuxcare.com/els/cve/CVE-2026-58011" impact="important" public="20260630">CVE-2026-58011</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" cwe="CWE-22" href="https://cve.tuxcare.com/els/cve/CVE-2026-58015" impact="important" public="20260630">CVE-2026-58015</cve>
          <cve cvss3="8.6/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" cwe="CWE-193" href="https://cve.tuxcare.com/els/cve/CVE-2026-58014" impact="important" public="20260630">CVE-2026-58014</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="libglib2.0-0 is earlier than 0:2.66.8-1+deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789291176001"/>
        <criterion comment="libglib2.0-bin is earlier than 0:2.66.8-1+deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789291176002"/>
        <criterion comment="libglib2.0-data is earlier than 0:2.66.8-1+deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789291176003"/>
        <criterion comment="libglib2.0-dev is earlier than 0:2.66.8-1+deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789291176004"/>
        <criterion comment="libglib2.0-dev-bin is earlier than 0:2.66.8-1+deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789291176005"/>
        <criterion comment="libglib2.0-doc is earlier than 0:2.66.8-1+deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789291176006"/>
        <criterion comment="libglib2.0-tests is earlier than 0:2.66.8-1+deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789291176007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789291359" version="1">
      <metadata>
        <title>Fix of 7 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789291359" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789291359" source="CLSA"/>
        <reference ref_id="CVE-2026-20214" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-20214" source="CVE"/>
        <reference ref_id="CVE-2026-20244" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-20244" source="CVE"/>
        <reference ref_id="CVE-2026-20243" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-20243" source="CVE"/>
        <reference ref_id="CVE-2026-20213" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-20213" source="CVE"/>
        <reference ref_id="CVE-2026-20217" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-20217" source="CVE"/>
        <reference ref_id="CVE-2026-20216" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-20216" source="CVE"/>
        <reference ref_id="CVE-2026-20215" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-20215" source="CVE"/>
        <description>* SECURITY UPDATE: heap buffer overflow via an integer overflow in the PE
     rebuilder
     - debian/patches/CVE-2026-20213.patch: sum rebuilt section sizes in a
       64-bit temporary and reject packed section totals or allocations that
       exceed CLI_MAX_ALLOCATION in libclamav/rebuildpe.c.
     - CVE-2026-20213
   * SECURITY UPDATE: out-of-bounds write via a section loop underflow in the
     FSG unpacker
     - debian/patches/CVE-2026-20214.patch: iterate the section loop with
       t &lt; sectcnt instead of t &lt;= sectcnt - 1, which underflows when sectcnt
       is zero, in libclamav/pe.c.
     - CVE-2026-20214
   * SECURITY UPDATE: heap buffer overflow via a 7z substream count overflow
     - debian/patches/CVE-2026-20215.patch: reject archives whose total
       unpack-stream count would overflow UInt32 before it is accumulated in
       libclamav/7z/7zIn.c.
     - CVE-2026-20215
   * SECURITY UPDATE: denial of service via unenforced extraction limits in
     the InstallShield parser
     - debian/patches/CVE-2026-20216.patch: apply cli_checklimits() to header
       parsing and to cab extraction output, and guard the output size
       accumulator against overflow, in libclamav/ishield.c.
     - CVE-2026-20216
   * SECURITY UPDATE: invalid free via incorrect cleanup bitmap tracking in
     the PESpin unpacker
     - debian/patches/CVE-2026-20217.patch: shift the bitmap that the cleanup
       loop tests, not the unrelated bitman variable, in libclamav/spin.c.
     - CVE-2026-20217
   * SECURITY UPDATE: denial of service via size handling errors in the ALZ
     parser
     - debian/patches/CVE-2026-20243.patch: harden ALZ size arithmetic,
       extract stored, bzip2 and deflate members under scan budgets, use
       bounded flate2 reads and drop the inflate dependency, in
       libclamav_rust/src/{alz,scanners,util,sys}.rs, libclamav_rust/Cargo.toml,
       libclamav_rust/build.rs, libclamav/libclamav.map and Cargo.lock.
     - CVE-2026-20243
   * SECURITY UPDATE: out-of-bounds read via integer overflow in the DMG mish
     size checks on 32-bit platforms
     - debian/patches/CVE-2026-20244.patch: compute the expected mish block
       length in a 64-bit integer, keep the XML range check in subtraction
       form and avoid overflow in the base64 buffer size, in libclamav/dmg.c.
     - CVE-2026-20244</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-13"/>
          <updated date="2026-09-13"/>
          <cve cwe="CWE-120" href="https://cve.tuxcare.com/els/cve/CVE-2026-20214" impact="unknown" public="20260701">CVE-2026-20214</cve>
          <cve cwe="CWE-120" href="https://cve.tuxcare.com/els/cve/CVE-2026-20244" impact="unknown" public="20260701">CVE-2026-20244</cve>
          <cve cwe="CWE-120" href="https://cve.tuxcare.com/els/cve/CVE-2026-20243" impact="unknown" public="20260701">CVE-2026-20243</cve>
          <cve cwe="CWE-120" href="https://cve.tuxcare.com/els/cve/CVE-2026-20213" impact="unknown" public="20260701">CVE-2026-20213</cve>
          <cve cwe="CWE-120" href="https://cve.tuxcare.com/els/cve/CVE-2026-20217" impact="unknown" public="20260701">CVE-2026-20217</cve>
          <cve cwe="CWE-770" href="https://cve.tuxcare.com/els/cve/CVE-2026-20216" impact="unknown" public="20260701">CVE-2026-20216</cve>
          <cve cwe="CWE-120" href="https://cve.tuxcare.com/els/cve/CVE-2026-20215" impact="unknown" public="20260701">CVE-2026-20215</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="clamav is earlier than 0:1.4.3+dfsg-1~deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789291359001"/>
        <criterion comment="clamav-base is earlier than 0:1.4.3+dfsg-1~deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789291359002"/>
        <criterion comment="clamav-daemon is earlier than 0:1.4.3+dfsg-1~deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789291359003"/>
        <criterion comment="clamav-doc is earlier than 0:1.4.3+dfsg-1~deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789291359004"/>
        <criterion comment="clamav-docs is earlier than 0:1.4.3+dfsg-1~deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789291359005"/>
        <criterion comment="clamav-freshclam is earlier than 0:1.4.3+dfsg-1~deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789291359006"/>
        <criterion comment="clamav-milter is earlier than 0:1.4.3+dfsg-1~deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789291359007"/>
        <criterion comment="clamav-testfiles is earlier than 0:1.4.3+dfsg-1~deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789291359008"/>
        <criterion comment="clamdscan is earlier than 0:1.4.3+dfsg-1~deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789291359009"/>
        <criterion comment="libclamav-dev is earlier than 0:1.4.3+dfsg-1~deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789291359010"/>
        <criterion comment="libclamav12 is earlier than 0:1.4.3+dfsg-1~deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789291359011"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789374596" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-59999, CVE-2026-60000, CVE-2026-73282</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789374596" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789374596" source="CLSA"/>
        <reference ref_id="CVE-2026-59999" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-59999" source="CVE"/>
        <reference ref_id="CVE-2026-73282" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-73282" source="CVE"/>
        <reference ref_id="CVE-2026-60000" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-60000" source="CVE"/>
        <description>* SECURITY UPDATE: use-after-free in the ssh client when a remote forwarding
     is added over the multiplexing socket
     - debian/patches/CVE-2026-73282.patch: register a heap-allocated index
       instead of a pointer into options.remote_forwards[] as the pending
       remote-forward confirmation context in ssh.c, and re-resolve the array
       element in ssh_confirm_remote_forward().
     - CVE-2026-73282</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-14"/>
          <updated date="2026-09-14"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-348" href="https://cve.tuxcare.com/els/cve/CVE-2026-59999" impact="important" public="20260708">CVE-2026-59999</cve>
          <cve cwe="CWE-416" href="https://cve.tuxcare.com/els/cve/CVE-2026-73282" impact="unknown" public="20260811">CVE-2026-73282</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-770" href="https://cve.tuxcare.com/els/cve/CVE-2026-60000" impact="important" public="20260708">CVE-2026-60000</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="openssh-client is earlier than 1:8.4p1-5+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789374596001"/>
        <criterion comment="openssh-server is earlier than 1:8.4p1-5+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789374596002"/>
        <criterion comment="openssh-sftp-server is earlier than 1:8.4p1-5+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789374596003"/>
        <criterion comment="openssh-tests is earlier than 1:8.4p1-5+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789374596004"/>
        <criterion comment="ssh is earlier than 1:8.4p1-5+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789374596005"/>
        <criterion comment="ssh-askpass-gnome is earlier than 1:8.4p1-5+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789374596006"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789375226" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-21311</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789375226" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789375226" source="CLSA"/>
        <reference ref_id="CVE-2025-21311" ref_url="https://cve.tuxcare.com/els/cve/CVE-2025-21311" source="CVE"/>
        <description>* SECURITY UPDATE: Remove the unmaintained ntlm_smb_lm_auth NTLM helper
     - debian/patches/CVE-2025-21311.patch: drop src/auth/ntlm/SMB_LM and its
       build wiring from configure.ac, configure, src/auth/ntlm/Makefile.am,
       src/auth/ntlm/Makefile.in and src/auth/ntlm/helpers.m4
     - debian/rules: drop SMB_LM from --enable-auth-ntlm, so
       /usr/lib/squid/ntlm_smb_lm_auth is no longer built or shipped and NTLM
       authentication must use an externally provided helper such as Samba
       ntlm_auth
     - CVE-2025-21311</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-14"/>
          <updated date="2026-09-14"/>
          <cve cwe="CWE-303" href="https://cve.tuxcare.com/els/cve/CVE-2025-21311" impact="unknown" public="20250114">CVE-2025-21311</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="squid is earlier than 0:4.13-10+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375226001"/>
        <criterion comment="squid-cgi is earlier than 0:4.13-10+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375226002"/>
        <criterion comment="squid-common is earlier than 0:4.13-10+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375226003"/>
        <criterion comment="squid-openssl is earlier than 0:4.13-10+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375226004"/>
        <criterion comment="squid-purge is earlier than 0:4.13-10+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375226005"/>
        <criterion comment="squidclient is earlier than 0:4.13-10+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375226006"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789375441" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-58224</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789375441" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789375441" source="CLSA"/>
        <reference ref_id="CVE-2026-58224" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-58224" source="CVE"/>
        <description>* SECURITY UPDATE: Out of bounds access and DoS in CTDB protocol handling
     - debian/patches/CVE-2026-58224.patch: validate protocol field lengths,
       bound array allocations and secure the sock_daemon socket
     - CVE-2026-58224</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-14"/>
          <updated date="2026-09-14"/>
          <cve cvss3="8.6/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-353" href="https://cve.tuxcare.com/els/cve/CVE-2026-58224" impact="important" public="20260814">CVE-2026-58224</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="ctdb is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375441001"/>
        <criterion comment="libnss-winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375441002"/>
        <criterion comment="libpam-winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375441003"/>
        <criterion comment="libsmbclient is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375441004"/>
        <criterion comment="libsmbclient-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375441005"/>
        <criterion comment="libwbclient-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375441006"/>
        <criterion comment="libwbclient0 is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375441007"/>
        <criterion comment="python3-samba is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375441008"/>
        <criterion comment="registry-tools is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375441009"/>
        <criterion comment="samba is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375441010"/>
        <criterion comment="samba-common is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375441011"/>
        <criterion comment="samba-common-bin is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375441012"/>
        <criterion comment="samba-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375441013"/>
        <criterion comment="samba-dsdb-modules is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375441014"/>
        <criterion comment="samba-libs is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375441015"/>
        <criterion comment="samba-testsuite is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375441016"/>
        <criterion comment="samba-vfs-modules is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375441017"/>
        <criterion comment="smbclient is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375441018"/>
        <criterion comment="winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789375441019"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789375664" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2022-3715</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789375664" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789375664" source="CLSA"/>
        <reference ref_id="CVE-2022-3715" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-3715" source="CVE"/>
        <description>* SECURITY UPDATE: out-of-bounds read in parameter transformation
     - debian/patches/CVE-2022-3715.patch: reject an empty transformation
       operator in parameter_brace_transform before valid_parameter_transform
       reads past the end of the operator string in subst.c
     - CVE-2022-3715</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-14"/>
          <updated date="2026-09-14"/>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-119" href="https://cve.tuxcare.com/els/cve/CVE-2022-3715" impact="important" public="20230105">CVE-2022-3715</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="bash is earlier than 0:5.1-2+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789375664001"/>
        <criterion comment="bash-builtins is earlier than 0:5.1-2+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789375664002"/>
        <criterion comment="bash-doc is earlier than 0:5.1-2+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789375664003"/>
        <criterion comment="bash-static is earlier than 0:5.1-2+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789375664004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789375817" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2018-13410</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789375817" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789375817" source="CLSA"/>
        <reference ref_id="CVE-2018-13410" ref_url="https://cve.tuxcare.com/els/cve/CVE-2018-13410" source="CVE"/>
        <description>* SECURITY UPDATE: Heap buffer overflow in the unzip test command builder
     - debian/patches/CVE-2018-13410.patch: allocate one more byte for the
       command string built in check_zipfile() in zip.c, so that the quotes,
       separator and terminating NUL added around the archive name when -TT
       is used cannot write past the end of the buffer
     - CVE-2018-13410</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-14"/>
          <updated date="2026-09-14"/>
          <cve cvss2="7.5/AV:N/AC:L/Au:N/C:P/I:P/A:P" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els/cve/CVE-2018-13410" impact="critical" public="20180706">CVE-2018-13410</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="zip is earlier than 0:3.0-12+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789375817001"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789042546" version="1">
      <metadata>
        <title>Fix of 7 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789042546" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789042546" source="CLSA"/>
        <reference ref_id="CVE-2026-56444" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-56444" source="CVE"/>
        <reference ref_id="CVE-2026-40622" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-40622" source="CVE"/>
        <reference ref_id="CVE-2026-33278" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-33278" source="CVE"/>
        <reference ref_id="CVE-2026-50252" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-50252" source="CVE"/>
        <reference ref_id="CVE-2026-42960" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-42960" source="CVE"/>
        <reference ref_id="CVE-2026-42959" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-42959" source="CVE"/>
        <reference ref_id="CVE-2026-41292" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-41292" source="CVE"/>
        <description>* SECURITY UPDATE: Possible remote code execution during DNSSEC validation
     - debian/patches/CVE-2026-33278.patch: Possible remote code execution during DNSSEC validation
     - CVE-2026-33278
   * SECURITY UPDATE: Ghost domain name variant
     - debian/patches/CVE-2026-40622.patch: Ghost domain name variant
     - CVE-2026-40622
   * SECURITY UPDATE: Parsing a long list of incoming EDNS options degrades performance
     - debian/patches/CVE-2026-41292.patch: Parsing a long list of incoming EDNS options degrades performance
     - CVE-2026-41292
   * SECURITY UPDATE: Crash during DNSSEC validation of malicious content
     - debian/patches/CVE-2026-42959.patch: Crash during DNSSEC validation of malicious content
     - CVE-2026-42959
   * SECURITY UPDATE: Possible cache poisoning attack while following delegation
     - debian/patches/CVE-2026-42960.patch: Possible cache poisoning attack while following delegation
     - CVE-2026-42960
   * SECURITY UPDATE: Degradation of resolution service when discard-timeout and serve-expired-client-timeout are combined
     - debian/patches/CVE-2026-56444.patch: Degradation of resolution service when discard-timeout and serve-expired-client-timeout are combined
     - CVE-2026-56444</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-10"/>
          <updated date="2026-09-10"/>
          <cve cwe="CWE-772" href="https://cve.tuxcare.com/els/cve/CVE-2026-56444" impact="unknown" public="20260722">CVE-2026-56444</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-346" href="https://cve.tuxcare.com/els/cve/CVE-2026-40622" impact="important" public="20260520">CVE-2026-40622</cve>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els/cve/CVE-2026-33278" impact="critical" public="20260520">CVE-2026-33278</cve>
          <cve cvss3="9.3/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H" cwe="CWE-349" href="https://cve.tuxcare.com/els/cve/CVE-2026-50252" impact="critical" public="20260722">CVE-2026-50252</cve>
          <cve cvss3="10.0/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H" cwe="CWE-349" href="https://cve.tuxcare.com/els/cve/CVE-2026-42960" impact="critical" public="20260520">CVE-2026-42960</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-824" href="https://cve.tuxcare.com/els/cve/CVE-2026-42959" impact="important" public="20260520">CVE-2026-42959</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-407" href="https://cve.tuxcare.com/els/cve/CVE-2026-41292" impact="important" public="20260520">CVE-2026-41292</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="libunbound-dev is earlier than 0:1.13.1-1+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789042546001"/>
        <criterion comment="libunbound8 is earlier than 0:1.13.1-1+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789042546002"/>
        <criterion comment="python3-unbound is earlier than 0:1.13.1-1+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789042546003"/>
        <criterion comment="unbound is earlier than 0:1.13.1-1+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789042546004"/>
        <criterion comment="unbound-anchor is earlier than 0:1.13.1-1+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789042546005"/>
        <criterion comment="unbound-host is earlier than 0:1.13.1-1+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789042546006"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789388743" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-81934</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789388743" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789388743" source="CLSA"/>
        <reference ref_id="CVE-2026-81934" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-81934" source="CVE"/>
        <description>* SECURITY UPDATE: Use-after-free in TLS pending-data processing
     - debian/patches/CVE-2026-81934.patch: drain the TLS pending list from
       its head and detach each node before running its event handler in
       src/tls.c, so a handler that closes another pending connection cannot
       leave the iterator holding a freed node
     - CVE-2026-81934</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-14"/>
          <updated date="2026-09-14"/>
          <cve cwe="CWE-416" href="https://cve.tuxcare.com/els/cve/CVE-2026-81934" impact="unknown" public="20260827">CVE-2026-81934</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="redis is earlier than 5:6.0.16-1+deb11u9+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789388743001"/>
        <criterion comment="redis-sentinel is earlier than 5:6.0.16-1+deb11u9+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789388743002"/>
        <criterion comment="redis-server is earlier than 5:6.0.16-1+deb11u9+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789388743003"/>
        <criterion comment="redis-tools is earlier than 5:6.0.16-1+deb11u9+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789388743004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789390312" version="1">
      <metadata>
        <title>Fix of 5 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789390312" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789390312" source="CLSA"/>
        <reference ref_id="CVE-2026-40469" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-40469" source="CVE"/>
        <reference ref_id="CVE-2026-40467" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-40467" source="CVE"/>
        <reference ref_id="CVE-2026-40468" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-40468" source="CVE"/>
        <reference ref_id="CVE-2026-40553" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-40553" source="CVE"/>
        <reference ref_id="CVE-2023-4156" ref_url="https://cve.tuxcare.com/els/cve/CVE-2023-4156" source="CVE"/>
        <description>* SECURITY UPDATE: out-of-bounds read via a positional field width or
     precision in printf/sprintf
     - debian/patches/CVE-2023-4156.patch: reject a negative positional index
       in format_tree() in builtin.c. The digit run of a `%*N$' specifier is
       accumulated into an int, so a sufficiently long N wraps it negative;
       the existing guard tested only val &gt;= num_args, letting the negative
       value reach the_args[val] and read before the start of the argument
       array
     - CVE-2023-4156
   * SECURITY UPDATE: use-after-free in getline from a two-way pipe
     - debian/patches/CVE-2026-40467.patch: stop do_getline_redir() in io.c
       from releasing redir_exp immediately after redirect(), since the
       two-way-pipe error path still reads redir_exp-&gt;stptr/stlen through
       is_non_fatal_redirect(). The DEREF is moved to each control-flow path
       after the node's last use
     - CVE-2026-40467
   * SECURITY UPDATE: heap buffer overflow in sub()/gsub() on 32-bit
     architectures
     - debian/patches/CVE-2026-40468.patch: widen the sofar accumulator in
       do_sub() in builtin.c from int to size_t so the running offset into the
       replacement buffer cannot overflow while the buffer itself is sized
       with size_t arithmetic. The upstream commit's second hunk, widening i
       to int64_t in parse_escape() in node.c, is carried verbatim for
       fidelity; it is inert here, as that function's octal and hex loops are
       bounded at 0777 and 0xFF and it returns int
     - CVE-2026-40468
   * SECURITY UPDATE: integer overflow in the sub()/gsub() replacement size
     computation on 32-bit architectures
     - debian/patches/CVE-2026-40469.patch: compute the ampersand expansion in
       do_sub() in builtin.c as a uint64_t and fatal out with "replacement
       expansion too large" when the result would exceed SIZE_MAX, instead of
       wrapping and under-allocating the destination buffer
     - CVE-2026-40469
   * SECURITY UPDATE: stack buffer overflow in the readdir extension
     - debian/patches/CVE-2026-40553.patch: build the path in ftype() in
       extension/readdir.c with a bounded snprintf() and reject the entry when
       the result would be truncated, replacing the unbounded strcpy()/strcat()
       pair that overflowed fname[] for a sufficiently long directory or entry
       name
     - CVE-2026-40553</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-14"/>
          <updated date="2026-09-14"/>
          <cve cvss3="9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" cwe="CWE-190" href="https://cve.tuxcare.com/els/cve/CVE-2026-40469" impact="critical" public="20260713">CVE-2026-40469</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els/cve/CVE-2026-40467" impact="important" public="20260713">CVE-2026-40467</cve>
          <cve cvss3="9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" cwe="CWE-190" href="https://cve.tuxcare.com/els/cve/CVE-2026-40468" impact="critical" public="20260713">CVE-2026-40468</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-121" href="https://cve.tuxcare.com/els/cve/CVE-2026-40553" impact="important" public="20260713">CVE-2026-40553</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" cwe="CWE-125" href="https://cve.tuxcare.com/els/cve/CVE-2023-4156" impact="important" public="20230925">CVE-2023-4156</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="gawk is earlier than 1:5.1.0-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789390312001"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789391878" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2023-43655, CVE-2026-40176, CVE-2026-40261</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789391878" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789391878" source="CLSA"/>
        <reference ref_id="CVE-2023-43655" ref_url="https://cve.tuxcare.com/els/cve/CVE-2023-43655" source="CVE"/>
        <reference ref_id="CVE-2026-40261" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-40261" source="CVE"/>
        <reference ref_id="CVE-2026-40176" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-40176" source="CVE"/>
        <description>* Non-maintainer upload by the TuxCare ELS team.
   * CVE-2026-40261: Prevent a command injection vulnerability in
     Perforce::syncCodeBase(), which appended the source reference to the
     'p4 sync -f' command without escaping. Package metadata served by a
     malicious or compromised Composer repository could inject shell
     metacharacters, leading to command execution even when Perforce is not
     installed.
     - debian/patches/0019-CVE-2026-40261.patch
   * CVE-2026-40176: Prevent a command injection vulnerability in
     Perforce::generateP4Command(), which interpolated the Perforce
     connection parameters (user, client, port) into the 'p4' command line
     without escaping. A malicious composer.json declaring a Perforce VCS
     repository could inject shell metacharacters, leading to command
     execution even when Perforce is not installed. Also backport the
     prerequisite upstream fix for Perforce::connectClient(), which passed
     the client spec path through the shell redirection of the same command
     line with only spaces escaped.
     - debian/patches/0020-CVE-2026-40176.patch
   * CVE-2023-43655: Refuse to run on a non-CLI SAPI when
     register_argc_argv is enabled and the entry point is a phar, which
     allowed a composer.phar published to a web-accessible directory to be
     driven through the query string. This package installs bin/composer as
     a plain PHP script and ships no phar, so the guard is inert here; it is
     applied for parity with the upstream and Debian bookworm fixes.
     - debian/patches/0021-CVE-2023-43655.patch</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-14"/>
          <updated date="2026-09-14"/>
          <cve cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-74" href="https://cve.tuxcare.com/els/cve/CVE-2023-43655" impact="important" public="20230929">CVE-2023-43655</cve>
          <cve cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-20" href="https://cve.tuxcare.com/els/cve/CVE-2026-40261" impact="important" public="20260415">CVE-2026-40261</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-20" href="https://cve.tuxcare.com/els/cve/CVE-2026-40176" impact="important" public="20260415">CVE-2026-40176</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="composer is earlier than 0:2.0.9-2+deb11u4+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789391878001"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789392206" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-58471, CVE-2026-58472</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789392206" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789392206" source="CLSA"/>
        <reference ref_id="CVE-2026-58472" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-58472" source="CVE"/>
        <reference ref_id="CVE-2026-58471" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-58471" source="CVE"/>
        <description>* SECURITY UPDATE: Heap buffer overflow in remote filename charset
     conversion
     - debian/patches/CVE-2026-58471.patch: fix the E2BIG buffer-growth path of
       convert_fname() in src/url.c.  On each iconv() overflow it recomputed the
       buffer size from the ORIGINAL length (done = len; len = done + inlen * 2)
       while resetting the write pointer to converted_fname + done, so outlen
       described a window that started before the bytes iconv() had already
       written; a multi-pass conversion therefore wrote past the allocation.
       The fix derives both the write offset and the remaining space from the
       actual bytes consumed (used = s - converted_fname) and guarantees the
       realloc grows the buffer
     - CVE-2026-58471
   * SECURITY UPDATE: Integer overflow leading to heap buffer overflow in HTML
     attribute entity encoding
     - debian/patches/CVE-2026-58472.patch: change the size accumulator of
       html_quote_string() in src/convert.c from int to size_t and guard every
       addition with INT_ADD_OK().  The per-character increments were correct,
       but a sufficiently long input overflowed the signed int counter, so
       xmalloc() received an undersized (or negative) size and the second loop
       wrote the escaped string past the end of it
     - CVE-2026-58472</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-14"/>
          <updated date="2026-09-14"/>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H" cwe="CWE-190" href="https://cve.tuxcare.com/els/cve/CVE-2026-58472" impact="important" public="20260707">CVE-2026-58472</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H" cwe="CWE-122" href="https://cve.tuxcare.com/els/cve/CVE-2026-58471" impact="important" public="20260707">CVE-2026-58471</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="wget is earlier than 0:1.21-1+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789392206001"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789394882" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-72522, CVE-2026-76957</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789394882" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789394882" source="CLSA"/>
        <reference ref_id="CVE-2026-76957" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-76957" source="CVE"/>
        <reference ref_id="CVE-2026-72522" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72522" source="CVE"/>
        <description>* SECURITY UPDATE: Out-of-bounds read and resultant infinite loop
     because low surrogates were treated the same as high surrogates in
     the *_toUtf16 functions (libexpat before 2.8.3)
     - debian/patches/CVE-2026-72522.patch: mask the high byte of the
       trailing code unit with 0xFC instead of 0xF8 in the
       DEFINE_UTF16_TO_UTF16(E) macro in expat/lib/xmltok.c, so the guard
       that avoids splitting a surrogate pair across two conversion calls
       matches only genuine high surrogates (0xD800-0xDBFF) and no longer
       accepts low surrogates (0xDC00-0xDFFF).  On a buffer ending in a
       lone low surrogate the old test reported
       XML_CONVERT_INPUT_INCOMPLETE without consuming any input, so the
       caller retried while reading two bytes past the intended limit.
       One edit covers both little2_toUtf16 and big2_toUtf16.  Reachable
       in the libexpatw (-DXML_UNICODE) build, which is where xmlparse.c
       maps XmlConvert to XmlUtf16Convert.
     - CVE-2026-72522
   * SECURITY UPDATE: Use-after-free because handler call depth tracking
     was missing for custom encoding callbacks (libexpat before 2.8.4)
     - debian/patches/CVE-2026-76957.patch: route the application's
       unknown-encoding convert and release callbacks through the new
       callUnknownEncodingConvert() and callUnknownEncodingRelease()
       wrappers in expat/lib/xmlparse.c, storing the application callback
       in the new m_unknownEncodingConvert member and passing the parser
       itself as the encoding's user data.  handleUnknownEncoding
       previously handed both callbacks out unwrapped, so
       m_handlerCallDepth stayed at zero while they ran and the
       reentrancy guard that rejects XML_ParserFree, XML_GetBuffer and
       XML_ResumeParser from inside a handler did not fire for them.
     - CVE-2026-76957</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-14"/>
          <updated date="2026-09-14"/>
          <cve cvss3="9.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els/cve/CVE-2026-76957" impact="critical" public="20260820">CVE-2026-76957</cve>
          <cve cwe="CWE-125" href="https://cve.tuxcare.com/els/cve/CVE-2026-72522" impact="unknown" public="20260810">CVE-2026-72522</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="expat is earlier than 0:2.2.10-2+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789394882001"/>
        <criterion comment="libexpat1 is earlier than 0:2.2.10-2+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789394882002"/>
        <criterion comment="libexpat1-dev is earlier than 0:2.2.10-2+deb11u7+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789394882003"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789398674" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-69720</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789398674" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789398674" source="CLSA"/>
        <reference ref_id="CVE-2025-69720" ref_url="https://cve.tuxcare.com/els/cve/CVE-2025-69720" source="CVE"/>
        <description>* SECURITY UPDATE: stack-based buffer overflow in infocmp
     - debian/patches/CVE-2025-69720.patch: add a bounds check on strlen(cp)
       in analyze_string() in progs/infocmp.c and grow buf2 by one byte so
       a maliciously long SGR parameter list can no longer overflow the
       stack buffer.
     - CVE-2025-69720</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-14"/>
          <updated date="2026-09-14"/>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-121" href="https://cve.tuxcare.com/els/cve/CVE-2025-69720" impact="important" public="20260319">CVE-2025-69720</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="lib32ncurses-dev is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789398674001"/>
        <criterion comment="lib32ncurses6 is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789398674002"/>
        <criterion comment="lib32ncursesw6 is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789398674003"/>
        <criterion comment="lib32tinfo6 is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789398674004"/>
        <criterion comment="libncurses-dev is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789398674005"/>
        <criterion comment="libncurses5 is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789398674006"/>
        <criterion comment="libncurses5-dev is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789398674007"/>
        <criterion comment="libncurses6 is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789398674008"/>
        <criterion comment="libncursesw5 is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789398674009"/>
        <criterion comment="libncursesw5-dev is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789398674010"/>
        <criterion comment="libncursesw6 is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789398674011"/>
        <criterion comment="libtinfo-dev is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789398674012"/>
        <criterion comment="libtinfo5 is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789398674013"/>
        <criterion comment="libtinfo6 is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789398674014"/>
        <criterion comment="ncurses-base is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789398674015"/>
        <criterion comment="ncurses-bin is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789398674016"/>
        <criterion comment="ncurses-doc is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789398674017"/>
        <criterion comment="ncurses-examples is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789398674018"/>
        <criterion comment="ncurses-term is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789398674019"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789461431" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-65637, CVE-2026-68763</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789461431" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789461431" source="CLSA"/>
        <reference ref_id="CVE-2026-65637" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-65637" source="CVE"/>
        <reference ref_id="CVE-2026-68763" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-68763" source="CVE"/>
        <description>* SECURITY UPDATE: HTTP/2 requests without an authority bypassed strict
     SNI validation - the fix for CVE-2026-32990 required an authority only
     for CONNECT requests, so a request using any other method could omit it
     and evade the host check
     - debian/patches/CVE-2026-65637.patch: treat a missing serverName as a
       missing header for all non-CONNECT HTTP/2 requests in
       receivedEndOfHeaders()
     - CVE-2026-65637
   * SECURITY UPDATE: Denial of service via an allocation leak in the HTTP/2
     backlog - resetting a stream that was waiting on the connection window
     left its reservation counted in the backlog and its allocation
     unreturned, so repeated resets exhausted the connection window and
     stalled the connection
     - debian/patches/CVE-2026-68763.patch: remove a replaced stream from the
       backlog and return its unused allocation to the connection window,
       decrement backLogSize when allocating, and skip streams that can no
       longer write
     - CVE-2026-68763</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-15"/>
          <updated date="2026-09-15"/>
          <cve cwe="CWE-20" href="https://cve.tuxcare.com/els/cve/CVE-2026-65637" impact="unknown" public="20260825">CVE-2026-65637</cve>
          <cve cwe="CWE-400" href="https://cve.tuxcare.com/els/cve/CVE-2026-68763" impact="unknown" public="20260825">CVE-2026-68763</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="libtomcat9-embed-java is earlier than 0:9.0.118-0+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789461431001"/>
        <criterion comment="libtomcat9-java is earlier than 0:9.0.118-0+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789461431002"/>
        <criterion comment="tomcat9 is earlier than 0:9.0.118-0+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789461431003"/>
        <criterion comment="tomcat9-admin is earlier than 0:9.0.118-0+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789461431004"/>
        <criterion comment="tomcat9-common is earlier than 0:9.0.118-0+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789461431005"/>
        <criterion comment="tomcat9-docs is earlier than 0:9.0.118-0+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789461431006"/>
        <criterion comment="tomcat9-examples is earlier than 0:9.0.118-0+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789461431007"/>
        <criterion comment="tomcat9-user is earlier than 0:9.0.118-0+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789461431008"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789463064" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2022-0318</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789463064" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789463064" source="CLSA"/>
        <reference ref_id="CVE-2022-0318" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-0318" source="CVE"/>
        <description>* SECURITY UPDATE: Heap-based buffer overflow in block insert
     - debian/patches/CVE-2022-0318.patch: only use the multi-byte head
       offset to correct the offset in block_insert() in src/ops.c, adjust
       the expected block-insert output in src/testdir/test_utf8.vim, add
       test in src/testdir/test_visual.vim, add patch numbers in
       src/version.c; also clamp a negative space count in block_insert()
       in src/ops.c, as upstream 8.2.3073 does and as debian10els already
       carries (Debian #1023818)
     - CVE-2022-0318</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-15"/>
          <updated date="2026-09-15"/>
          <cve cvss2="7.5/AV:N/AC:L/Au:N/C:P/I:P/A:P" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-122" href="https://cve.tuxcare.com/els/cve/CVE-2022-0318" impact="critical" public="20220121">CVE-2022-0318</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="vim is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789463064001"/>
        <criterion comment="vim-athena is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789463064002"/>
        <criterion comment="vim-common is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789463064003"/>
        <criterion comment="vim-doc is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789463064004"/>
        <criterion comment="vim-gtk is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789463064005"/>
        <criterion comment="vim-gtk3 is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789463064006"/>
        <criterion comment="vim-gui-common is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789463064007"/>
        <criterion comment="vim-nox is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789463064008"/>
        <criterion comment="vim-runtime is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789463064009"/>
        <criterion comment="vim-tiny is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789463064010"/>
        <criterion comment="xxd is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789463064011"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789479755" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2021-42523</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789479755" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789479755" source="CLSA"/>
        <reference ref_id="CVE-2021-42523" ref_url="https://cve.tuxcare.com/els/cve/CVE-2021-42523" source="CVE"/>
        <description>* SECURITY UPDATE: Memory leak in the sqlite3_exec() error message on
     colord database open
     - debian/patches/CVE-2021-42523.patch: Pass NULL instead of an error
       message buffer to the properties_v2 schema check in
       cd_device_db_load() in src/cd-device-db.c and to the properties_pu
       schema check in cd_profile_db_load() in src/cd-profile-db.c, so
       SQLite no longer allocates an error message that neither function
       frees
     - CVE-2021-42523
   * Stop colord-test-private timing out on the 32-bit builders
     - debian/rules: pass --timeout-multiplier 10 to meson test; the suite
       only reached 9 of its 38 subtests inside meson's default 30s ceiling
       on armel, while amd64 completes it in 6s</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-15"/>
          <updated date="2026-09-15"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" cwe="CWE-200" href="https://cve.tuxcare.com/els/cve/CVE-2021-42523" impact="important" public="20220825">CVE-2021-42523</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="colord is earlier than 0:1.4.5-3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789479755001"/>
        <criterion comment="colord-data is earlier than 0:1.4.5-3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789479755002"/>
        <criterion comment="colord-tests is earlier than 0:1.4.5-3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789479755003"/>
        <criterion comment="gir1.2-colord-1.0 is earlier than 0:1.4.5-3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789479755004"/>
        <criterion comment="gir1.2-colorhug-1.0 is earlier than 0:1.4.5-3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789479755005"/>
        <criterion comment="libcolord-dev is earlier than 0:1.4.5-3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789479755006"/>
        <criterion comment="libcolord2 is earlier than 0:1.4.5-3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789479755007"/>
        <criterion comment="libcolorhug-dev is earlier than 0:1.4.5-3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789479755008"/>
        <criterion comment="libcolorhug2 is earlier than 0:1.4.5-3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789479755009"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789483920" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-25724</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789483920" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789483920" source="CLSA"/>
        <reference ref_id="CVE-2025-25724" ref_url="https://cve.tuxcare.com/els/cve/CVE-2025-25724" source="CVE"/>
        <description>* SECURITY UPDATE: Use of undefined buffer content in bsdtar verbose listing
     - debian/patches/CVE-2025-25724.patch: check the strftime return value and
       the localtime result in list_item_verbose in tar/util.c, printing
       "-- -- ----" instead of undefined buffer content
     - CVE-2025-25724</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-15"/>
          <updated date="2026-09-15"/>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-252" href="https://cve.tuxcare.com/els/cve/CVE-2025-25724" impact="important" public="20250302">CVE-2025-25724</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="libarchive-dev is earlier than 0:3.4.3-2+deb11u5+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789483920001"/>
        <criterion comment="libarchive-tools is earlier than 0:3.4.3-2+deb11u5+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789483920002"/>
        <criterion comment="libarchive13 is earlier than 0:3.4.3-2+deb11u5+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789483920003"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789486509" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2023-46045</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789486509" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789486509" source="CLSA"/>
        <reference ref_id="CVE-2023-46045" ref_url="https://cve.tuxcare.com/els/cve/CVE-2023-46045" source="CVE"/>
        <description>* SECURITY UPDATE: Out-of-bounds read via a malformed plugin config file
     - debian/patches/CVE-2023-46045.patch: detect an unknown plugin API in
       gvconfig_plugin_install_from_config() in lib/gvc/gvconfig.c and fail
       with an error instead of indexing the API array out of bounds
     - CVE-2023-46045</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-15"/>
          <updated date="2026-09-15"/>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-125" href="https://cve.tuxcare.com/els/cve/CVE-2023-46045" impact="important" public="20240202">CVE-2023-46045</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="graphviz is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486509001"/>
        <criterion comment="graphviz-doc is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486509002"/>
        <criterion comment="libcdt5 is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486509003"/>
        <criterion comment="libcgraph6 is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486509004"/>
        <criterion comment="libgraphviz-dev is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486509005"/>
        <criterion comment="libgv-guile is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486509006"/>
        <criterion comment="libgv-lua is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486509007"/>
        <criterion comment="libgv-perl is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486509008"/>
        <criterion comment="libgv-php7 is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486509009"/>
        <criterion comment="libgv-ruby is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486509010"/>
        <criterion comment="libgv-tcl is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486509011"/>
        <criterion comment="libgvc6 is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486509012"/>
        <criterion comment="libgvc6-plugins-gtk is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486509013"/>
        <criterion comment="libgvpr2 is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486509014"/>
        <criterion comment="liblab-gamut1 is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486509015"/>
        <criterion comment="libpathplan4 is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486509016"/>
        <criterion comment="libxdot4 is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486509017"/>
        <criterion comment="python3-gv is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486509018"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789486843" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2024-6239</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789486843" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789486843" source="CLSA"/>
        <reference ref_id="CVE-2024-6239" ref_url="https://cve.tuxcare.com/els/cve/CVE-2024-6239" source="CVE"/>
        <description>* SECURITY UPDATE: Crash in pdfinfo -dests on broken documents
     - debian/patches/CVE-2024-6239.patch: give the destination map ownership of
       its name strings and skip entries with a null name in utils/pdfinfo.cc
     - CVE-2024-6239</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-15"/>
          <updated date="2026-09-15"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-20" href="https://cve.tuxcare.com/els/cve/CVE-2024-6239" impact="important" public="20240621">CVE-2024-6239</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="gir1.2-poppler-0.18 is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486843001"/>
        <criterion comment="libpoppler-cpp-dev is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486843002"/>
        <criterion comment="libpoppler-cpp0v5 is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486843003"/>
        <criterion comment="libpoppler-dev is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486843004"/>
        <criterion comment="libpoppler-glib-dev is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486843005"/>
        <criterion comment="libpoppler-glib-doc is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486843006"/>
        <criterion comment="libpoppler-glib8 is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486843007"/>
        <criterion comment="libpoppler-private-dev is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486843008"/>
        <criterion comment="libpoppler-qt5-1 is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486843009"/>
        <criterion comment="libpoppler-qt5-dev is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486843010"/>
        <criterion comment="libpoppler102 is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486843011"/>
        <criterion comment="poppler-utils is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789486843012"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789552364" version="1">
      <metadata>
        <title>Fix of 7 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789552364" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789552364" source="CLSA"/>
        <reference ref_id="CVE-2026-57433" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-57433" source="CVE"/>
        <reference ref_id="CVE-2026-9538" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-9538" source="CVE"/>
        <reference ref_id="CVE-2026-48962" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-48962" source="CVE"/>
        <reference ref_id="CVE-2026-57432" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-57432" source="CVE"/>
        <reference ref_id="CVE-2023-31486" ref_url="https://cve.tuxcare.com/els/cve/CVE-2023-31486" source="CVE"/>
        <reference ref_id="CVE-2026-42496" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-42496" source="CVE"/>
        <reference ref_id="CVE-2026-13221" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-13221" source="CVE"/>
        <description>* SECURITY UPDATE: path traversal in Archive::Tar via unvalidated
     symlink and hardlink targets in the tar header
     - debian/patches/CVE-2026-42496.patch: reject absolute and
       escaping '..' link targets in Archive::Tar::_make_special_file()
       unless $Archive::Tar::INSECURE_EXTRACT_MODE is set, resolving the
       target through _symlinks_resolver() so links that stay inside the
       extraction directory keep working
     - CVE-2026-42496
   * SECURITY UPDATE: memory exhaustion in Archive::Tar via an
     attacker-controlled entry size field in the tar header
     - debian/patches/CVE-2026-9538.patch: cap the per-entry declared size
       in Archive::Tar::_read_tar() with $Archive::Tar::MAX_FILE_SIZE
       (default 1 GiB), refusing the entry before the read buffer is
       allocated
     - CVE-2026-9538
   * SECURITY UPDATE: arbitrary code execution in File::GlobMapper via an
     attacker-controlled output glob
     - debian/patches/CVE-2026-48962.patch: replace the eval STRING in
       File::GlobMapper::_getFiles() with literal substitution of the
       internal markers set up by _parseOutputGlob() in
       cpan/IO-Compress/lib/File/GlobMapper.pm
     - CVE-2026-48962
   * SECURITY UPDATE: integer overflow when computing a pack/unpack
     template structure size
     - debian/patches/CVE-2026-57432.patch: croak in S_measure_struct() in
       pp_pack.c when the computed structure size would overflow SSize_t,
       and document the new diagnostic in pod/perldiag.pod
     - CVE-2026-57432
   * SECURITY UPDATE: signed integer overflow when deserializing a crafted
     Storable SX_HOOK record
     - debian/patches/CVE-2026-57433.patch: reject a hook data item count
       of I32_MAX in retrieve_hook_common() in dist/Storable/Storable.xs
       before it is incremented and passed to av_extend()
     - CVE-2026-57433
   * SECURITY UPDATE: HTTP::Tiny did not verify TLS certificates by default
     - debian/patches/CVE-2023-31486.patch: default verify_SSL to 1 in
       cpan/HTTP-Tiny/lib/HTTP/Tiny.pm and add the
       PERL_HTTP_TINY_SSL_INSECURE_BY_DEFAULT escape hatch, matching
       HTTP::Tiny 0.083
     - CVE-2023-31486</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-16"/>
          <updated date="2026-09-16"/>
          <cve cwe="CWE-190" href="https://cve.tuxcare.com/els/cve/CVE-2026-57433" impact="unknown" public="20260713">CVE-2026-57433</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-789" href="https://cve.tuxcare.com/els/cve/CVE-2026-9538" impact="important" public="20260526">CVE-2026-9538</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-95" href="https://cve.tuxcare.com/els/cve/CVE-2026-48962" impact="important" public="20260527">CVE-2026-48962</cve>
          <cve cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-125" href="https://cve.tuxcare.com/els/cve/CVE-2026-57432" impact="important" public="20260713">CVE-2026-57432</cve>
          <cve cvss3="8.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-295" href="https://cve.tuxcare.com/els/cve/CVE-2023-31486" impact="important" public="20230429">CVE-2023-31486</cve>
          <cve cvss3="9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" cwe="CWE-59" href="https://cve.tuxcare.com/els/cve/CVE-2026-42496" impact="critical" public="20260526">CVE-2026-42496</cve>
          <cve cvss3="9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" cwe="CWE-190" href="https://cve.tuxcare.com/els/cve/CVE-2026-13221" impact="critical" public="20260713">CVE-2026-13221</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="libperl-dev is earlier than 0:5.32.1-4+deb11u5+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789552364001"/>
        <criterion comment="libperl5.32 is earlier than 0:5.32.1-4+deb11u5+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789552364002"/>
        <criterion comment="perl is earlier than 0:5.32.1-4+deb11u5+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789552364003"/>
        <criterion comment="perl-base is earlier than 0:5.32.1-4+deb11u5+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789552364004"/>
        <criterion comment="perl-debug is earlier than 0:5.32.1-4+deb11u5+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789552364005"/>
        <criterion comment="perl-doc is earlier than 0:5.32.1-4+deb11u5+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789552364006"/>
        <criterion comment="perl-modules-5.32 is earlier than 0:5.32.1-4+deb11u5+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789552364007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789566857" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2022-4055</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789566857" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789566857" source="CLSA"/>
        <reference ref_id="CVE-2022-4055" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-4055" source="CVE"/>
        <description>* SECURITY UPDATE: a mailto: URI could silently attach a local file when
     Thunderbird was the configured handler
     - debian/patches/CVE-2022-4055.patch: remove the Thunderbird special case
       (run_thunderbird() and its callers) from scripts/xdg-email.in, so
       mailto: URIs go to the desktop handler and no URI field is parsed;
       the --attach option is dropped with it
     - debian/patches/tests-xdg-email-thunderbird-passthrough.patch: rewrite the
       autotest case that asserted the removed Thunderbird path so it asserts
       the fixed behaviour instead
     - CVE-2022-4055: unquoted subject= and body= in run_thunderbird() let a
       mailto: URI append a -compose attachment= argument
     - CVE-2020-27748: the attach= field of a mailto: URI was passed straight
       through to -compose attachment=</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-16"/>
          <updated date="2026-09-16"/>
          <cve cvss3="7.4/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N" cwe="CWE-146" href="https://cve.tuxcare.com/els/cve/CVE-2022-4055" impact="important" public="20221119">CVE-2022-4055</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="xdg-utils is earlier than 0:1.1.3-4.1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789566857001"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789567019" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2023-35945</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789567019" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789567019" source="CLSA"/>
        <reference ref_id="CVE-2023-35945" ref_url="https://cve.tuxcare.com/els/cve/CVE-2023-35945" source="CVE"/>
        <description>* SECURITY UPDATE: Memory leak when a HEADERS or PUSH_PROMISE frame cannot be
     sent and the stream close callback fails fatally
     - debian/patches/CVE-2023-35945.patch: free the outbound item and reset the
       active outbound item before returning the fatal error from
       nghttp2_session_close_stream in lib/nghttp2_session.c, add regression test
       in tests/nghttp2_session_test.c
     - CVE-2023-35945</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-16"/>
          <updated date="2026-09-16"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els/cve/CVE-2023-35945" impact="important" public="20230713">CVE-2023-35945</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="libnghttp2-14 is earlier than 0:1.43.0-1+deb11u3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789567019001"/>
        <criterion comment="libnghttp2-dev is earlier than 0:1.43.0-1+deb11u3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789567019002"/>
        <criterion comment="libnghttp2-doc is earlier than 0:1.43.0-1+deb11u3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789567019003"/>
        <criterion comment="nghttp2 is earlier than 0:1.43.0-1+deb11u3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789567019004"/>
        <criterion comment="nghttp2-client is earlier than 0:1.43.0-1+deb11u3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789567019005"/>
        <criterion comment="nghttp2-proxy is earlier than 0:1.43.0-1+deb11u3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789567019006"/>
        <criterion comment="nghttp2-server is earlier than 0:1.43.0-1+deb11u3+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789567019007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789571397" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-86138, CVE-2026-86142, CVE-2026-86143, CVE-2026-86144</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789571397" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789571397" source="CLSA"/>
        <reference ref_id="CVE-2026-86138" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-86138" source="CVE"/>
        <reference ref_id="CVE-2026-86144" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-86144" source="CVE"/>
        <reference ref_id="CVE-2026-86142" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-86142" source="CVE"/>
        <reference ref_id="CVE-2026-86143" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-86143" source="CVE"/>
        <description>* SECURITY UPDATE: heap buffer overflow in the dictionary string pool via
     an oversized QName
     - debian/patches/CVE-2026-86138.patch: compute the pool growth in
       xmlDictAddQString() with size_t arithmetic and bail out when the
       requested size is not representable, so a prefix and name together
       exceeding 2^30 characters no longer wrap the
       "4 * (namelen + plen + 1)" product down to a few bytes and overflow
       the pool on the following copy
     - CVE-2026-86138
   * SECURITY UPDATE: heap buffer overflow when evaluating an oversized
     XPointer expression
     - debian/patches/CVE-2026-86142.patch: take the length of the remaining
       XPointer expression with strlen() and reject anything not
       representable as an int before sizing the buffer in
       xmlXPtrEvalXPtrPart().  xmlStrlen() counts in a plain int on this
       branch and wraps for inputs above 2 GiB, and the loop that copies the
       expression into the buffer performs no capacity check of its own
     - CVE-2026-86142
   * SECURITY UPDATE: negative length passed to output write callbacks
     - debian/patches/CVE-2026-86143.patch: reject buffer lengths above
       INT_MAX before narrowing them for the writecallback() argument, in
       both xmlOutputBufferWrite() and xmlOutputBufferWriteEscape() as well
       as xmlOutputBufferFlush().  Without this a buffer larger than 2 GiB
       reaches the callback as a negative int, which callbacks such as
       xmlFileWrite() convert straight into a huge size_t for fwrite()
     - CVE-2026-86143
   * SECURITY UPDATE: XInclude processing ignored the document parse flags,
     dropping XML_PARSE_NONET
     - debian/patches/CVE-2026-86144.patch: pass the document's own
       parseFlags through xmlXIncludeProcess() and xmlXIncludeProcessTree()
       instead of hardcoding 0, and apply them to the parser context that
       xmlXIncludeLoadTxt() builds for parse="text" includes, so a caller
       that parsed with XML_PARSE_NONET no longer has that restriction
       silently dropped when XInclude references are resolved, on either
       the parse="xml" or the parse="text" path, which allowed remote
       resources to be fetched
     - CVE-2026-86144</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-16"/>
          <updated date="2026-09-16"/>
          <cve cvss3="9.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-190" href="https://cve.tuxcare.com/els/cve/CVE-2026-86138" impact="critical" public="20260905">CVE-2026-86138</cve>
          <cve cvss3="8.7/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-669" href="https://cve.tuxcare.com/els/cve/CVE-2026-86144" impact="important" public="20260905">CVE-2026-86144</cve>
          <cve cvss3="9.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-122" href="https://cve.tuxcare.com/els/cve/CVE-2026-86142" impact="critical" public="20260905">CVE-2026-86142</cve>
          <cve cvss3="8.6/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" cwe="CWE-192" href="https://cve.tuxcare.com/els/cve/CVE-2026-86143" impact="important" public="20260905">CVE-2026-86143</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="libxml2 is earlier than 0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789571397001"/>
        <criterion comment="libxml2-dev is earlier than 0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789571397002"/>
        <criterion comment="libxml2-doc is earlier than 0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789571397003"/>
        <criterion comment="libxml2-utils is earlier than 0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789571397004"/>
        <criterion comment="python3-libxml2 is earlier than 0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789571397005"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789573030" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2023-25193</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789573030" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789573030" source="CLSA"/>
        <reference ref_id="CVE-2023-25193" ref_url="https://cve.tuxcare.com/els/cve/CVE-2023-25193" source="CVE"/>
        <description>* SECURITY UPDATE: Denial of service via quadratic mark attachment in GPOS
     - debian/patches/CVE-2023-25193.patch: memoize the last base glyph in
       MarkBasePos/MarkLigPos so backward search no longer rescans the buffer
     - CVE-2023-25193</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-16"/>
          <updated date="2026-09-16"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-770" href="https://cve.tuxcare.com/els/cve/CVE-2023-25193" impact="important" public="20230204">CVE-2023-25193</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="gir1.2-harfbuzz-0.0 is earlier than 0:2.7.4-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789573030001"/>
        <criterion comment="libharfbuzz-bin is earlier than 0:2.7.4-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789573030002"/>
        <criterion comment="libharfbuzz-dev is earlier than 0:2.7.4-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789573030003"/>
        <criterion comment="libharfbuzz-doc is earlier than 0:2.7.4-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789573030004"/>
        <criterion comment="libharfbuzz-gobject0 is earlier than 0:2.7.4-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789573030005"/>
        <criterion comment="libharfbuzz-icu0 is earlier than 0:2.7.4-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789573030006"/>
        <criterion comment="libharfbuzz0b is earlier than 0:2.7.4-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789573030007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789574775" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2023-30630</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789574775" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789574775" source="CLSA"/>
        <reference ref_id="CVE-2023-30630" ref_url="https://cve.tuxcare.com/els/cve/CVE-2023-30630" source="CVE"/>
        <description>* SECURITY UPDATE: --dump-bin could overwrite an arbitrary existing file
     - debian/patches/CVE-2023-30630.patch: write the dump file in a single
       pass and create it with O_EXCL so an existing file is never clobbered
     - CVE-2023-30630
   * Build on armel
     - debian/control: add armel to Architecture on dmidecode and
       dmidecode-udeb. The debian11-els platform builds amd64, arm64 and
       armel, and with armel absent from the list dh produced no binary
       artifacts there, so every build of this package failed that target
       with "dpkg-genbuildinfo: error: binary build with no binary artifacts
       found" - the pristine vendor import fails the same way
     - the omission is an artefact of Debian's opt-in architecture list, not
       a portability limit: armhf and arm64 were each added on request
       (#715139, #767965) and armel was simply never asked for. dmidecode has
       no inline assembly and no VFP dependency (its only float use is printf
       formatting of voltages, which soft-float handles), its arch-conditional
       code is confined to __ia64__, __aarch64__ and an x86-only entry-point
       fallback - none of which armel enters - and the primary path reads
       /sys/firmware/dmi/tables/smbios_entry_point, which is arch-neutral</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-16"/>
          <updated date="2026-09-16"/>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" href="https://cve.tuxcare.com/els/cve/CVE-2023-30630" impact="important" public="20230413">CVE-2023-30630</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="dmidecode is earlier than 0:3.3-2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789574775001"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789577104" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-43964</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789577104" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789577104" source="CLSA"/>
        <reference ref_id="CVE-2026-43964" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-43964" source="CVE"/>
        <description>* SECURITY UPDATE: Buffer over-read in dsn_split()
     - debian/patches/CVE-2026-43964.patch: do not advance past the end of an
       enhanced status code that is not followed by other text, in
       src/global/dsn_util.c
     - CVE-2026-43964</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-16"/>
          <updated date="2026-09-16"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-193" href="https://cve.tuxcare.com/els/cve/CVE-2026-43964" impact="important" public="20260504">CVE-2026-43964</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="postfix is earlier than 0:3.5.25-0+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789577104001"/>
        <criterion comment="postfix-cdb is earlier than 0:3.5.25-0+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789577104002"/>
        <criterion comment="postfix-doc is earlier than 0:3.5.25-0+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789577104003"/>
        <criterion comment="postfix-ldap is earlier than 0:3.5.25-0+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789577104004"/>
        <criterion comment="postfix-lmdb is earlier than 0:3.5.25-0+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789577104005"/>
        <criterion comment="postfix-mysql is earlier than 0:3.5.25-0+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789577104006"/>
        <criterion comment="postfix-pcre is earlier than 0:3.5.25-0+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789577104007"/>
        <criterion comment="postfix-pgsql is earlier than 0:3.5.25-0+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789577104008"/>
        <criterion comment="postfix-sqlite is earlier than 0:3.5.25-0+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789577104009"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789577411" version="1">
      <metadata>
        <title>Fix of 5 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789577411" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789577411" source="CLSA"/>
        <reference ref_id="CVE-2022-37967" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-37967" source="CVE"/>
        <reference ref_id="CVE-2022-42898" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-42898" source="CVE"/>
        <reference ref_id="CVE-2022-38023" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-38023" source="CVE"/>
        <reference ref_id="CVE-2022-37966" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-37966" source="CVE"/>
        <reference ref_id="CVE-2022-32743" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-32743" source="CVE"/>
        <description>* SECURITY UPDATE: integer overflows in Heimdal PAC parsing allow remote
     code execution on 32-bit platforms and denial of service elsewhere
     - debian/patches/CVE-2022-42898.patch: catch the overflows that result
       from adding PAC_INFO_BUFFER_SIZE when parsing a PAC, and add the
       64-bit store/retrieve helpers the checks need
     - CVE-2022-42898
   * SECURITY UPDATE: an AD DC accepts a PAC whose contents were tampered
     with, because the KDC does not verify a checksum over the whole ticket
     - debian/patches/CVE-2022-37967.patch: add the new PAC ticket checksum
       and verify it in the KDC and in the PAC validation paths
     - CVE-2022-37967
   * SECURITY UPDATE: an unprivileged user can write the dNSHostName
     attribute of a computer account without the Validated-DNS-Host-Name
     right
     - debian/patches/CVE-2022-32743.patch: validate dNSHostName and
       servicePrincipalName writes in the acl module and connect to samdb as
       the workstation account in the netlogon server
     - CVE-2022-32743
   * SECURITY UPDATE: the netlogon secure channel accepts weak RC4/HMAC-MD5
     crypto and unsealed traffic, allowing elevation of privilege
     - debian/patches/CVE-2022-38023.patch: default 'reject md5 clients' and
       'reject md5 servers' to yes, add 'server schannel require seal
       [:COMPUTERACCOUNT]' (default yes) and route every netr_LogonSamLogon*
       variant through the schannel check in both netlogon servers
     - CVE-2022-38023
   * SECURITY UPDATE: an AD DC can be forced to issue rc4-hmac Kerberos
     tickets and session keys even where stronger encryption is available
     - debian/patches/CVE-2022-37966.patch: announce PA-SUPPORTED-ETYPES,
       select session keys from the server's supported types and add the
       'kdc supported enctypes', 'kdc default domain supportedenctypes' and
       'kdc force enable rc4 weak session keys' options
     - debian/patches/CVE-2022-37966-domain-trust-modify.patch: add
       'samba-tool domain trust modify' so an existing RC4-only trust can be
       repaired
     - CVE-2022-37966</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-16"/>
          <updated date="2026-09-16"/>
          <cve cvss3="7.2/CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://cve.tuxcare.com/els/cve/CVE-2022-37967" impact="important" public="20221109">CVE-2022-37967</cve>
          <cve cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-190" href="https://cve.tuxcare.com/els/cve/CVE-2022-42898" impact="important" public="20221225">CVE-2022-42898</cve>
          <cve cvss3="8.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://cve.tuxcare.com/els/cve/CVE-2022-38023" impact="important" public="20221109">CVE-2022-38023</cve>
          <cve cvss3="8.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://cve.tuxcare.com/els/cve/CVE-2022-37966" impact="important" public="20221109">CVE-2022-37966</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-276" href="https://cve.tuxcare.com/els/cve/CVE-2022-32743" impact="important" public="20220901">CVE-2022-32743</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="ctdb is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789577411001"/>
        <criterion comment="libnss-winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789577411002"/>
        <criterion comment="libpam-winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789577411003"/>
        <criterion comment="libsmbclient is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789577411004"/>
        <criterion comment="libsmbclient-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789577411005"/>
        <criterion comment="libwbclient-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789577411006"/>
        <criterion comment="libwbclient0 is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789577411007"/>
        <criterion comment="python3-samba is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789577411008"/>
        <criterion comment="registry-tools is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789577411009"/>
        <criterion comment="samba is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789577411010"/>
        <criterion comment="samba-common is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789577411011"/>
        <criterion comment="samba-common-bin is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789577411012"/>
        <criterion comment="samba-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789577411013"/>
        <criterion comment="samba-dsdb-modules is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789577411014"/>
        <criterion comment="samba-libs is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789577411015"/>
        <criterion comment="samba-testsuite is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789577411016"/>
        <criterion comment="samba-vfs-modules is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789577411017"/>
        <criterion comment="smbclient is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789577411018"/>
        <criterion comment="winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789577411019"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789581984" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2019-20838</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789581984" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789581984" source="CLSA"/>
        <reference ref_id="CVE-2019-20838" ref_url="https://cve.tuxcare.com/els/cve/CVE-2019-20838" source="CVE"/>
        <description>* SECURITY UPDATE: Subject buffer overread in JIT
     - debian/patches/CVE-2019-20838.patch: skip the fixed-quantifier fast path
       for \R and \X in pcre_jit_compile.c
     - CVE-2019-20838
   * Stop RunGrepTest failing the armel build
     - debian/rules: run the rest of the test suite instead of RunGrepTest on
       armel, where pcregrep's directory recursion returns no entries so the
       six "-L -r" subtests print an empty file list; pre-existing, the init
       commit's own build fails identically, and the other five tests still
       gate the architecture</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-16"/>
          <updated date="2026-09-16"/>
          <cve cvss2="4.3/AV:N/AC:M/Au:N/C:N/I:N/A:P" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-125" href="https://cve.tuxcare.com/els/cve/CVE-2019-20838" impact="important" public="20200615">CVE-2019-20838</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="libpcre16-3 is earlier than 2:8.39-13+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789581984001"/>
        <criterion comment="libpcre3 is earlier than 2:8.39-13+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789581984002"/>
        <criterion comment="libpcre3-dev is earlier than 2:8.39-13+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789581984003"/>
        <criterion comment="libpcre32-3 is earlier than 2:8.39-13+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789581984004"/>
        <criterion comment="libpcrecpp0v5 is earlier than 2:8.39-13+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789581984005"/>
        <criterion comment="pcregrep is earlier than 2:8.39-13+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789581984006"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789582390" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2022-35737</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789582390" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789582390" source="CLSA"/>
        <reference ref_id="CVE-2022-35737" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-35737" source="CVE"/>
        <description>* SECURITY UPDATE: Array-bounds overflow in the printf() implementation
     when a string argument to %q, %Q or %w exceeds 2GB
     - debian/patches/CVE-2022-35737.patch: widen the i, j, k and n loop
       variables in sqlite3_str_vappendf() to i64 so the length computation
       no longer overflows a signed int
     - CVE-2022-35737</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-16"/>
          <updated date="2026-09-16"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-129" href="https://cve.tuxcare.com/els/cve/CVE-2022-35737" impact="important" public="20220803">CVE-2022-35737</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="lemon is earlier than 0:3.34.1-3+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789582390001"/>
        <criterion comment="libsqlite3-0 is earlier than 0:3.34.1-3+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789582390002"/>
        <criterion comment="libsqlite3-dev is earlier than 0:3.34.1-3+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789582390003"/>
        <criterion comment="libsqlite3-tcl is earlier than 0:3.34.1-3+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789582390004"/>
        <criterion comment="sqlite3 is earlier than 0:3.34.1-3+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789582390005"/>
        <criterion comment="sqlite3-doc is earlier than 0:3.34.1-3+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789582390006"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789635862" version="1">
      <metadata>
        <title>Fix of 8 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789635862" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789635862" source="CLSA"/>
        <reference ref_id="CVE-2026-53803" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-53803" source="CVE"/>
        <reference ref_id="CVE-2026-53783" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-53783" source="CVE"/>
        <reference ref_id="CVE-2026-53790" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-53790" source="CVE"/>
        <reference ref_id="CVE-2022-29154" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-29154" source="CVE"/>
        <reference ref_id="CVE-2026-53793" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-53793" source="CVE"/>
        <reference ref_id="CVE-2026-53802" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-53802" source="CVE"/>
        <reference ref_id="CVE-2026-70454" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-70454" source="CVE"/>
        <reference ref_id="CVE-2026-70464" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-70464" source="CVE"/>
        <description>* SECURITY UPDATE: remote arbitrary file write via an unrequested file list
     - debian/patches/CVE-2022-29154.patch: add the receiver-side admission
       check (and the argument-escaping rework it needs) so a malicious server
       cannot write files the client never asked for; taken from Red Hat's
       rsync-3.2.3 patch pair
     - the same patch adds upstream's two follow-ups to that rework: 1aef79e1,
       which stops safe_arg() leaving a trailing backslash unescaped for the
       remote shell, and 4ad3dbcf, which un-escapes daemon option args since no
       remote shell does it for a daemon
     - CVE-2022-29154
   * SECURITY UPDATE: rrsync restricted-directory escape
     - debian/patches/CVE-2026-53783.patch: replace the Perl rrsync with
       upstream's hardened Python implementation, which inode-pins the
       validated path, denies --copy-unsafe-links, refuses a symlinked
       --log-file and passes --drop-D; add the --drop-D option it requires.
       The shebang is normalised to /usr/bin/python3, keeping the convention
       debian/patches/perl_shebang.patch sets for the shipped scripts
     - CVE-2026-53783
   * SECURITY UPDATE: command and argument injection via unquoted values
     - debian/patches/CVE-2026-53790.patch: quote or refuse shell-active
       values in the RSYNC_CONNECT_PROG host substitution, the daemon
       exec-hook expansions, rsync-ssl hostspecs and remote-shell arguments
     - CVE-2026-53790
   * SECURITY UPDATE: chroot /./ inner-module escape
     - debian/patches/CVE-2026-53793.patch: engage the secure resolver for the
       generator basis stat, the module chdir and the receiver write path, and
       sanitize the peer-supplied basis name on the client too
     - CVE-2026-53793
   * SECURITY UPDATE: arbitrary file read via symlinked input files
     - debian/patches/CVE-2026-53802.patch: resolve --filter merge files,
       --files-from/--include-from/--exclude-from, the daemon secrets file and
       --password-file through a trusted-owner path walk
     - CVE-2026-53802
   * SECURITY UPDATE: arbitrary file write via symlinked output paths
     - debian/patches/CVE-2026-53803.patch: same path walk for --log-file,
       --write-batch/--read-batch and the daemon motd, lock, early-input and
       --config opens, plus an S_ISREG check on --read-batch
     - CVE-2026-53803
   * SECURITY UPDATE: unauthenticated TLS in rsync-ssl
     - debian/patches/CVE-2026-70454.patch: validate the helper hostname,
       require certificate verification and bind the certificate to the
       requested hostname in stunnel mode, and refuse the GnuTLS backend
       without a CA certificate; each of the three is opt-out through an
       environment variable, for deployments that cannot meet it -- see the
       patch header
     - CVE-2026-70454
   * SECURITY UPDATE: unbounded pre-transfer daemon handshake
     - debian/patches/CVE-2026-70464.patch: bound the greeting, authentication
       and argument reads with an absolute deadline so an unauthenticated peer
       cannot hold a max-connections slot open, and cap the argument count
     - CVE-2026-70464
   * debian/control: suggest python3-braceexpand, which the Python rrsync uses
     for brace expansion when present
   * debian/rsync.NEWS: document the rrsync interpreter change for anyone using
     the script in an authorized_keys forced command</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-17"/>
          <updated date="2026-09-17"/>
          <cve cwe="CWE-59" href="https://cve.tuxcare.com/els/cve/CVE-2026-53803" impact="unknown" public="20260813">CVE-2026-53803</cve>
          <cve cwe="CWE-59" href="https://cve.tuxcare.com/els/cve/CVE-2026-53783" impact="unknown" public="20260813">CVE-2026-53783</cve>
          <cve cwe="CWE-78" href="https://cve.tuxcare.com/els/cve/CVE-2026-53790" impact="unknown" public="20260813">CVE-2026-53790</cve>
          <cve cvss3="7.4/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H" cwe="CWE-20" href="https://cve.tuxcare.com/els/cve/CVE-2022-29154" impact="important" public="20220802">CVE-2022-29154</cve>
          <cve cwe="CWE-59" href="https://cve.tuxcare.com/els/cve/CVE-2026-53793" impact="unknown" public="20260813">CVE-2026-53793</cve>
          <cve cwe="CWE-61" href="https://cve.tuxcare.com/els/cve/CVE-2026-53802" impact="unknown" public="20260813">CVE-2026-53802</cve>
          <cve cwe="CWE-295" href="https://cve.tuxcare.com/els/cve/CVE-2026-70454" impact="unknown" public="20260813">CVE-2026-70454</cve>
          <cve cwe="CWE-770" href="https://cve.tuxcare.com/els/cve/CVE-2026-70464" impact="unknown" public="20260813">CVE-2026-70464</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="rsync is earlier than 0:3.2.3-4+deb11u4+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789635862001"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789639853" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-12932</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789639853" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789639853" source="CLSA"/>
        <reference ref_id="CVE-2026-12932" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-12932" source="CVE"/>
        <description>* SECURITY UPDATE: Fix metadata buffer leak in tls-crypt-v2 client key extraction
     - debian/patches/CVE-2026-12932.patch: make the tls-crypt-v2 metadata a
       local variable instead of a tls_wrap_ctx member and always free it on
       every exit path in tls_crypt_v2_extract_client_key
     - CVE-2026-12932</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-17"/>
          <updated date="2026-09-17"/>
          <cve cvss3="8.1/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" cwe="CWE-401" href="https://cve.tuxcare.com/els/cve/CVE-2026-12932" impact="important" public="20260730">CVE-2026-12932</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="openvpn is earlier than 0:2.5.1-3+deb11u4+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789639853001"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789639975" version="1">
      <metadata>
        <title>Fix of 20 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789639975" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789639975" source="CLSA"/>
        <reference ref_id="CVE-2022-2286" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-2286" source="CVE"/>
        <reference ref_id="CVE-2022-2343" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-2343" source="CVE"/>
        <reference ref_id="CVE-2026-73076" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-73076" source="CVE"/>
        <reference ref_id="CVE-2026-39881" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-39881" source="CVE"/>
        <reference ref_id="CVE-2022-3256" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-3256" source="CVE"/>
        <reference ref_id="CVE-2026-41411" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-41411" source="CVE"/>
        <reference ref_id="CVE-2026-57455" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-57455" source="CVE"/>
        <reference ref_id="CVE-2023-0049" ref_url="https://cve.tuxcare.com/els/cve/CVE-2023-0049" source="CVE"/>
        <reference ref_id="CVE-2026-52858" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-52858" source="CVE"/>
        <reference ref_id="CVE-2022-2126" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-2126" source="CVE"/>
        <reference ref_id="CVE-2022-3296" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-3296" source="CVE"/>
        <reference ref_id="CVE-2026-28417" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-28417" source="CVE"/>
        <reference ref_id="CVE-2022-2817" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-2817" source="CVE"/>
        <reference ref_id="CVE-2026-26269" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-26269" source="CVE"/>
        <reference ref_id="CVE-2022-1619" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-1619" source="CVE"/>
        <reference ref_id="CVE-2022-3520" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-3520" source="CVE"/>
        <reference ref_id="CVE-2022-2183" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-2183" source="CVE"/>
        <reference ref_id="CVE-2026-52859" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-52859" source="CVE"/>
        <reference ref_id="CVE-2022-2581" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-2581" source="CVE"/>
        <reference ref_id="CVE-2022-47024" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-47024" source="CVE"/>
        <description>* SECURITY UPDATE: with latin1 encoding CTRL-W might go before the start of the command line
     - debian/patches/CVE-2022-1619.patch: with latin1 encoding CTRL-W might go before the start of the command line
     - CVE-2022-1619
   * SECURITY UPDATE: using an invalid index when looking for spell suggestions
     - debian/patches/CVE-2022-2126.patch: using an invalid index when looking for spell suggestions
     - CVE-2022-2126
   * SECURITY UPDATE: reading beyond the end of the line with lisp indenting
     - debian/patches/CVE-2022-2183.patch: reading beyond the end of the line with lisp indenting
     - CVE-2022-2183
   * SECURITY UPDATE: reading past the end of a string with some completions
     - debian/patches/CVE-2022-2286.patch: reading past the end of a string with some completions
     - CVE-2022-2286
   * SECURITY UPDATE: reading past the end of a completion with a long line and
     'infercase' set
     - debian/patches/CVE-2022-2343.patch: reading past the end of a completion
       with a long line and 'infercase' set
     - CVE-2022-2343
   * SECURITY UPDATE: illegal memory access when a pattern starts with an illegal byte
     - debian/patches/CVE-2022-2581.patch: illegal memory access when a pattern starts with an illegal byte
     - CVE-2022-2581
   * SECURITY UPDATE: using freed memory with an error in an assert argument
     - debian/patches/CVE-2022-2817.patch: using freed memory with an error in an assert argument
     - CVE-2022-2817
   * SECURITY UPDATE: using freed memory when an autocommand changes a mark
     - debian/patches/CVE-2022-3256.patch: using freed memory when an autocommand changes a mark
     - CVE-2022-3256
   * SECURITY UPDATE: buffer underflow with an unexpected :finally
     - debian/patches/CVE-2022-3296.patch: buffer underflow with an unexpected :finally
     - CVE-2022-3296
   * SECURITY UPDATE: missing NULL check on the return value of XChangeGC()
     - debian/patches/CVE-2022-47024.patch: missing NULL check on the return value of XChangeGC()
     - CVE-2022-47024
   * SECURITY UPDATE: invalid memory access with a bad 'statusline' value
     - debian/patches/CVE-2023-0049.patch: invalid memory access with a bad 'statusline' value
     - CVE-2023-0049
   * SECURITY UPDATE: buffer overflow in netbeans special_keys() handling
     - debian/patches/CVE-2026-26269.patch: buffer overflow in netbeans special_keys() handling
     - CVE-2026-26269
   * SECURITY UPDATE: insufficient validation of hostname and port in netrw URIs allows command injection
     - debian/patches/CVE-2026-28417.patch: insufficient validation of hostname and port in netrw URIs allows command injection
     - CVE-2026-28417
   * SECURITY UPDATE: netbeans defineAnnoType and specialKeys pass unvalidated names into Ex commands, allowing command injection
     - debian/patches/CVE-2026-39881.patch: netbeans defineAnnoType and specialKeys pass unvalidated names into Ex commands, allowing command injection
     - CVE-2026-39881
   * SECURITY UPDATE: command injection via backticks in tag files
     - debian/patches/CVE-2026-41411.patch: command injection via backticks in tag files
     - CVE-2026-41411
   * SECURITY UPDATE: possible code execution with python3complete and pythoncomplete
     - debian/patches/CVE-2026-52858.patch: possible code execution with python3complete and pythoncomplete
     - CVE-2026-52858
   * SECURITY UPDATE: out-of-bounds read in update_snapshot() with a full combining-character cell
     - debian/patches/CVE-2026-52859.patch: out-of-bounds read in update_snapshot() with a full combining-character cell
     - CVE-2026-52859
   * SECURITY UPDATE: out-of-bounds write with soundfold()
     - debian/patches/CVE-2026-57455.patch: out-of-bounds write with soundfold()
     - CVE-2026-57455
   * SECURITY UPDATE: code execution via a crafted .VimballRecord file
     - debian/patches/CVE-2026-73076.patch: code execution via a crafted .VimballRecord file
     - CVE-2026-73076</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-17"/>
          <updated date="2026-09-17"/>
          <cve cvss2="6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-125" href="https://cve.tuxcare.com/els/cve/CVE-2022-2286" impact="important" public="20220702">CVE-2022-2286</cve>
          <cve cvss2="6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-122" href="https://cve.tuxcare.com/els/cve/CVE-2022-2343" impact="important" public="20220708">CVE-2022-2343</cve>
          <cve cwe="CWE-94" href="https://cve.tuxcare.com/els/cve/CVE-2026-73076" impact="unknown" public="20260811">CVE-2026-73076</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-94" href="https://cve.tuxcare.com/els/cve/CVE-2026-39881" impact="important" public="20260408">CVE-2026-39881</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els/cve/CVE-2022-3256" impact="important" public="20220922">CVE-2022-3256</cve>
          <cve cvss3="7.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-78" href="https://cve.tuxcare.com/els/cve/CVE-2026-41411" impact="important" public="20260424">CVE-2026-41411</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-787" href="https://cve.tuxcare.com/els/cve/CVE-2026-57455" impact="important" public="20260625">CVE-2026-57455</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-125" href="https://cve.tuxcare.com/els/cve/CVE-2023-0049" impact="important" public="20230104">CVE-2023-0049</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-94" href="https://cve.tuxcare.com/els/cve/CVE-2026-52858" impact="important" public="20260611">CVE-2026-52858</cve>
          <cve cvss2="6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-125" href="https://cve.tuxcare.com/els/cve/CVE-2022-2126" impact="important" public="20220619">CVE-2022-2126</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-121" href="https://cve.tuxcare.com/els/cve/CVE-2022-3296" impact="important" public="20220925">CVE-2022-3296</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-86" href="https://cve.tuxcare.com/els/cve/CVE-2026-28417" impact="important" public="20260227">CVE-2026-28417</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els/cve/CVE-2022-2817" impact="important" public="20220815">CVE-2022-2817</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-121" href="https://cve.tuxcare.com/els/cve/CVE-2026-26269" impact="important" public="20260213">CVE-2026-26269</cve>
          <cve cvss2="6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-122" href="https://cve.tuxcare.com/els/cve/CVE-2022-1619" impact="important" public="20220508">CVE-2022-1619</cve>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-122" href="https://cve.tuxcare.com/els/cve/CVE-2022-3520" impact="critical" public="20221202">CVE-2022-3520</cve>
          <cve cvss2="6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-125" href="https://cve.tuxcare.com/els/cve/CVE-2022-2183" impact="important" public="20220623">CVE-2022-2183</cve>
          <cve cvss3="8.2/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H" cwe="CWE-125" href="https://cve.tuxcare.com/els/cve/CVE-2026-52859" impact="important" public="20260611">CVE-2026-52859</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-125" href="https://cve.tuxcare.com/els/cve/CVE-2022-2581" impact="important" public="20220801">CVE-2022-2581</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-476" href="https://cve.tuxcare.com/els/cve/CVE-2022-47024" impact="important" public="20230120">CVE-2022-47024</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="vim is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els11" test_ref="oval:com.tuxcare.clsa:tst:1789639975001"/>
        <criterion comment="vim-athena is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els11" test_ref="oval:com.tuxcare.clsa:tst:1789639975002"/>
        <criterion comment="vim-common is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els11" test_ref="oval:com.tuxcare.clsa:tst:1789639975003"/>
        <criterion comment="vim-doc is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els11" test_ref="oval:com.tuxcare.clsa:tst:1789639975004"/>
        <criterion comment="vim-gtk is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els11" test_ref="oval:com.tuxcare.clsa:tst:1789639975005"/>
        <criterion comment="vim-gtk3 is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els11" test_ref="oval:com.tuxcare.clsa:tst:1789639975006"/>
        <criterion comment="vim-gui-common is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els11" test_ref="oval:com.tuxcare.clsa:tst:1789639975007"/>
        <criterion comment="vim-nox is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els11" test_ref="oval:com.tuxcare.clsa:tst:1789639975008"/>
        <criterion comment="vim-runtime is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els11" test_ref="oval:com.tuxcare.clsa:tst:1789639975009"/>
        <criterion comment="vim-tiny is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els11" test_ref="oval:com.tuxcare.clsa:tst:1789639975010"/>
        <criterion comment="xxd is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els11" test_ref="oval:com.tuxcare.clsa:tst:1789639975011"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789641466" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-54874</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789641466" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789641466" source="CLSA"/>
        <reference ref_id="CVE-2026-54874" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-54874" source="CVE"/>
        <description>* SECURITY UPDATE: avoid buffering the whole DTLS read buffer for a record
     arriving early for the next epoch (ssl/record/rec_layer_d1.c)
     - debian/patches/CVE-2026-54874.patch: dtls1_buffer_record() took over the
       entire live read buffer for every queued record and allocated a fresh
       one, pinning about 16.7 KB of heap per queued record however small the
       record actually was, across three queues capped at 100 entries each;
       copy only the record's own on-wire bytes into a right-sized allocation
       and restore them into the live read buffer on retrieval, in
       ssl/record/rec_layer_d1.c, ssl/record/record.h and
       ssl/record/ssl3_record.c
     - CVE-2026-54874
   * Stop 30-test_afalg.t failing the armel build
     - debian/rules: exclude that one test recipe on armel, where the builder's
       io_setup(2) is not implemented so the AF_ALG engine cannot be exercised;
       the engine is still built and shipped and every other architecture still
       runs the test</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-17"/>
          <updated date="2026-09-17"/>
          <cve cwe="CWE-405" href="https://cve.tuxcare.com/els/cve/CVE-2026-54874" impact="unknown" public="20260825">CVE-2026-54874</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="libssl-dev is earlier than 0:1.1.1w-0+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789641466001"/>
        <criterion comment="libssl-doc is earlier than 0:1.1.1w-0+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789641466002"/>
        <criterion comment="libssl1.1 is earlier than 0:1.1.1w-0+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789641466003"/>
        <criterion comment="openssl is earlier than 0:1.1.1w-0+deb11u8+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789641466004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789643272" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-19654</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789643272" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789643272" source="CLSA"/>
        <reference ref_id="CVE-2026-19654" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-19654" source="CVE"/>
        <description>* SECURITY UPDATE: Negative message length in imptcp regex framing
     - debian/patches/CVE-2026-19654.patch: accept a regex framing match only
       when it follows an existing line, and fix the oversize regression test
       helper invocations
     - CVE-2026-19654</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-17"/>
          <updated date="2026-09-17"/>
          <cve cwe="CWE-125" href="https://cve.tuxcare.com/els/cve/CVE-2026-19654" impact="unknown" public="20260812">CVE-2026-19654</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="rsyslog is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789643272001"/>
        <criterion comment="rsyslog-czmq is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789643272002"/>
        <criterion comment="rsyslog-elasticsearch is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789643272003"/>
        <criterion comment="rsyslog-gnutls is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789643272004"/>
        <criterion comment="rsyslog-gssapi is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789643272005"/>
        <criterion comment="rsyslog-hiredis is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789643272006"/>
        <criterion comment="rsyslog-kafka is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789643272007"/>
        <criterion comment="rsyslog-mongodb is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789643272008"/>
        <criterion comment="rsyslog-mysql is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789643272009"/>
        <criterion comment="rsyslog-openssl is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789643272010"/>
        <criterion comment="rsyslog-pgsql is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789643272011"/>
        <criterion comment="rsyslog-relp is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789643272012"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789661255" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-14933, CVE-2025-14934, CVE-2025-14935, CVE-2025-14936</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789661255" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789661255" source="CLSA"/>
        <reference ref_id="CVE-2025-14936" ref_url="https://cve.tuxcare.com/els/cve/CVE-2025-14936" source="CVE"/>
        <reference ref_id="CVE-2025-14933" ref_url="https://cve.tuxcare.com/els/cve/CVE-2025-14933" source="CVE"/>
        <reference ref_id="CVE-2025-14934" ref_url="https://cve.tuxcare.com/els/cve/CVE-2025-14934" source="CVE"/>
        <reference ref_id="CVE-2025-14935" ref_url="https://cve.tuxcare.com/els/cve/CVE-2025-14935" source="CVE"/>
        <description>* SECURITY UPDATE: integer overflow in new_x_NC_var() and unbounded ndims in
     v1h_get_NC_var() (CVE-2025-14933)
   * SECURITY UPDATE: stack buffer overflow in NC3_inq_var() (CVE-2025-14934)
   * SECURITY UPDATE: heap buffer overflow in NC3_inq_dim() (CVE-2025-14935)
   * SECURITY UPDATE: stack buffer overflow in NC3_inq_attname() (CVE-2025-14936)</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-17"/>
          <updated date="2026-09-17"/>
          <cve cwe="CWE-121" href="https://cve.tuxcare.com/els/cve/CVE-2025-14936" impact="unknown" public="20251223">CVE-2025-14936</cve>
          <cve cwe="CWE-190" href="https://cve.tuxcare.com/els/cve/CVE-2025-14933" impact="unknown" public="20251223">CVE-2025-14933</cve>
          <cve cwe="CWE-121" href="https://cve.tuxcare.com/els/cve/CVE-2025-14934" impact="unknown" public="20251223">CVE-2025-14934</cve>
          <cve cwe="CWE-122" href="https://cve.tuxcare.com/els/cve/CVE-2025-14935" impact="unknown" public="20251223">CVE-2025-14935</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="libnetcdf-dev is earlier than 1:4.7.4-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789661255001"/>
        <criterion comment="libnetcdf18 is earlier than 1:4.7.4-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789661255002"/>
        <criterion comment="netcdf-bin is earlier than 1:4.7.4-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789661255003"/>
        <criterion comment="netcdf-doc is earlier than 1:4.7.4-1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789661255004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789666971" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-86145</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789666971" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789666971" source="CLSA"/>
        <reference ref_id="CVE-2026-86145" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-86145" source="CVE"/>
        <description>* SECURITY UPDATE: out-of-bounds write in pcre2_dfa_match() because
     more_workspace() reused a cached recursive-DFA workspace block without
     checking it was large enough for the request, so a pattern using nested
     assertions followed by recursion under a small heap limit could overflow
     the heap allocation (PCRE2 before 10.48)
     - debian/patches/CVE-2026-86145.patch: reject a cached next block smaller
       than the requested size, and clamp a newly allocated block to the
       remaining heap allowance without overflowing the size computation, in
       more_workspace() in src/pcre2_dfa_match.c
     - CVE-2026-86145</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-17"/>
          <updated date="2026-09-17"/>
          <cve cwe="CWE-424" href="https://cve.tuxcare.com/els/cve/CVE-2026-86145" impact="unknown" public="20260905">CVE-2026-86145</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="libpcre2-16-0 is earlier than 0:10.36-2+deb11u1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789666971001"/>
        <criterion comment="libpcre2-32-0 is earlier than 0:10.36-2+deb11u1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789666971002"/>
        <criterion comment="libpcre2-8-0 is earlier than 0:10.36-2+deb11u1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789666971003"/>
        <criterion comment="libpcre2-dev is earlier than 0:10.36-2+deb11u1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789666971004"/>
        <criterion comment="libpcre2-posix2 is earlier than 0:10.36-2+deb11u1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789666971005"/>
        <criterion comment="pcre2-utils is earlier than 0:10.36-2+deb11u1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789666971006"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789671837" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-59885, CVE-2026-59886</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789671837" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789671837" source="CLSA"/>
        <reference ref_id="CVE-2026-59885" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-59885" source="CVE"/>
        <reference ref_id="CVE-2026-59886" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-59886" source="CVE"/>
        <description>* SECURITY UPDATE: Quadratic complexity in OBJECT IDENTIFIER decoding
     - debian/patches/CVE-2026-59885.patch: accumulate arcs in a list instead
       of repeated tuple concatenation in the BER decoder and encoder
     - CVE-2026-59885
   * SECURITY UPDATE: Uncontrolled resource consumption converting univ.Real
     - debian/patches/CVE-2026-59886.patch: use math.ldexp for base 2 and
       reject base-10 exponents above sys.float_info.max_10_exp in
       Real.__float__, instead of exact big-integer exponentiation
     - CVE-2026-59886</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-17"/>
          <updated date="2026-09-17"/>
          <cve cwe="CWE-400" href="https://cve.tuxcare.com/els/cve/CVE-2026-59885" impact="unknown" public="20260714">CVE-2026-59885</cve>
          <cve cwe="CWE-400" href="https://cve.tuxcare.com/els/cve/CVE-2026-59886" impact="unknown" public="20260714">CVE-2026-59886</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="pypy-pyasn1 is earlier than 0:0.4.8-1+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789671837001"/>
        <criterion comment="python-pyasn1-doc is earlier than 0:0.4.8-1+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789671837002"/>
        <criterion comment="python3-pyasn1 is earlier than 0:0.4.8-1+deb11u2+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789671837003"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789718965" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-8376</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789718965" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789718965" source="CLSA"/>
        <reference ref_id="CVE-2026-8376" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-8376" source="CVE"/>
        <description>* SECURITY UPDATE: Buffer overflow in Perl_study_chunk via regex with
     large repeat counts on multi-character strings
     - debian/patches/CVE-2026-8376.patch: guard the repeated fixed string
       buffer size against SSize_t overflow in regcomp.c
     - upstream's companion test cases are not carried: they assert "Regexp out
       of space", but 5.32.1 still has REG_INFTY == U16_MAX so the patterns are
       rejected earlier by the quantifier parser, and the cases are only skipped
       when ptrsize != 4 so they would run and fail on armel
     - CVE-2026-8376</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-18"/>
          <updated date="2026-09-18"/>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-680" href="https://cve.tuxcare.com/els/cve/CVE-2026-8376" impact="critical" public="20260526">CVE-2026-8376</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="libperl-dev is earlier than 0:5.32.1-4+deb11u5+tuxcare.els5" test_ref="oval:com.tuxcare.clsa:tst:1789718965001"/>
        <criterion comment="libperl5.32 is earlier than 0:5.32.1-4+deb11u5+tuxcare.els5" test_ref="oval:com.tuxcare.clsa:tst:1789718965002"/>
        <criterion comment="perl is earlier than 0:5.32.1-4+deb11u5+tuxcare.els5" test_ref="oval:com.tuxcare.clsa:tst:1789718965003"/>
        <criterion comment="perl-base is earlier than 0:5.32.1-4+deb11u5+tuxcare.els5" test_ref="oval:com.tuxcare.clsa:tst:1789718965004"/>
        <criterion comment="perl-debug is earlier than 0:5.32.1-4+deb11u5+tuxcare.els5" test_ref="oval:com.tuxcare.clsa:tst:1789718965005"/>
        <criterion comment="perl-doc is earlier than 0:5.32.1-4+deb11u5+tuxcare.els5" test_ref="oval:com.tuxcare.clsa:tst:1789718965006"/>
        <criterion comment="perl-modules-5.32 is earlier than 0:5.32.1-4+deb11u5+tuxcare.els5" test_ref="oval:com.tuxcare.clsa:tst:1789718965007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789719259" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-11972</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789719259" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789719259" source="CLSA"/>
        <reference ref_id="CVE-2026-11972" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-11972" source="CVE"/>
        <description>* SECURITY UPDATE: denial of service when seeking a tar stream
     - debian/patches/CVE-2026-11972.patch: break out of the block-read loop
       in _Stream.seek() in Lib/tarfile.py once read() returns no data, so a
       member header declaring a huge size no longer drives an unbounded read
       loop past end of stream
     - CVE-2026-11972</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-18"/>
          <updated date="2026-09-18"/>
          <cve cwe="CWE-252" href="https://cve.tuxcare.com/els/cve/CVE-2026-11972" impact="unknown" public="20260623">CVE-2026-11972</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="idle-python2.7 is earlier than 0:2.7.18-8+deb11u1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789719259001"/>
        <criterion comment="libpython2.7 is earlier than 0:2.7.18-8+deb11u1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789719259002"/>
        <criterion comment="libpython2.7-dev is earlier than 0:2.7.18-8+deb11u1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789719259003"/>
        <criterion comment="libpython2.7-minimal is earlier than 0:2.7.18-8+deb11u1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789719259004"/>
        <criterion comment="libpython2.7-stdlib is earlier than 0:2.7.18-8+deb11u1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789719259005"/>
        <criterion comment="libpython2.7-testsuite is earlier than 0:2.7.18-8+deb11u1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789719259006"/>
        <criterion comment="python2.7 is earlier than 0:2.7.18-8+deb11u1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789719259007"/>
        <criterion comment="python2.7-dev is earlier than 0:2.7.18-8+deb11u1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789719259008"/>
        <criterion comment="python2.7-doc is earlier than 0:2.7.18-8+deb11u1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789719259009"/>
        <criterion comment="python2.7-examples is earlier than 0:2.7.18-8+deb11u1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789719259010"/>
        <criterion comment="python2.7-minimal is earlier than 0:2.7.18-8+deb11u1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789719259011"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789730024" version="1">
      <metadata>
        <title>Fix of 7 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789730024" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789730024" source="CLSA"/>
        <reference ref_id="CVE-2026-0864" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-0864" source="CVE"/>
        <reference ref_id="CVE-2007-4559" ref_url="https://cve.tuxcare.com/els/cve/CVE-2007-4559" source="CVE"/>
        <reference ref_id="CVE-2026-3644" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-3644" source="CVE"/>
        <reference ref_id="CVE-2026-4519" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-4519" source="CVE"/>
        <reference ref_id="CVE-2026-4224" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-4224" source="CVE"/>
        <reference ref_id="CVE-2026-15308" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-15308" source="CVE"/>
        <reference ref_id="CVE-2022-45061" ref_url="https://cve.tuxcare.com/els/cve/CVE-2022-45061" source="CVE"/>
        <description>* Drop the (&lt;&lt; 1:6.0) version constraint on the libdb-dev build dependency
     in debian/control.in and debian/control, matching debian10els. Bullseye
     ships only libdb-dev 5.3.1+nmu1, so the constraint excludes nothing, and
     the builder's pbuilder-satisfydepends misreads the '&lt;&lt;' relation as a
     build-profile restriction and skips installing the package entirely.
   * SECURITY UPDATE: directory traversal when extracting tar archives
     - debian/patches/CVE-2007-4559.patch: add the PEP 706 extraction filter
       API to Lib/tarfile.py, providing the fully_trusted, tar and data
       filters, the FilterError exception hierarchy, the TarFile.
       extraction_filter attribute and the filter= argument to extract() and
       extractall(), so that callers can reject members that would escape the
       destination directory. Includes the upstream follow-ups gh-149486 and
       gh-155999, which validate the written link target and normalise a
       member name that leaves the destination and comes back. The filters
       remain opt-in and do not contain a member extracted at errorlevel=0
       or through makelink()'s hardlink fallback; see the patch header
     - CVE-2007-4559
   * SECURITY UPDATE: quadratic complexity in IDNA decoding
     - debian/patches/CVE-2022-45061.patch: replace the per-character
       'for c in RandAL: if c:' BIDI loop in nameprep() with a single
       'if any(RandAL):' test in Lib/encodings/idna.py, so the RandALCat
       checks run once instead of once per character, restoring linear
       behaviour
     - CVE-2022-45061
   * SECURITY UPDATE: control character injection via http cookies
     - debian/patches/CVE-2026-0672.patch: reject control characters in
       Morsel keys, values, coded values and reserved attributes in
       Lib/Cookie.py
     - CVE-2026-0672
   * SECURITY UPDATE: incomplete fix for the http cookie control character
     injection
     - debian/patches/CVE-2026-3644.patch: apply the same control character
       rejection to Morsel.update() and js_output() in Lib/Cookie.py, which
       the previous fix left unguarded
     - CVE-2026-3644
   * SECURITY UPDATE: configuration file injection via carriage returns in
     written option values
     - debian/patches/CVE-2026-0864.patch: normalise CR and CRLF, and not
       only LF, into '\n\t' continuation lines when writing option values in
       RawConfigParser.write() in Lib/ConfigParser.py, so that an
       attacker-controlled value can no longer inject additional sections,
       keys and values into the written file
     - CVE-2026-0864
   * SECURITY UPDATE: C stack overflow parsing deeply nested content models
     - debian/patches/CVE-2026-4224.patch: guard conv_content_model() in
       Modules/pyexpat.c with Py_EnterRecursiveCall(), so that a deeply
       nested element declaration raises RuntimeError instead of crashing
       the interpreter
     - CVE-2026-4224
   * SECURITY UPDATE: argument injection via leading dashes in browser URLs
     - debian/patches/CVE-2026-4519.patch: reject URLs beginning with a dash
       in BaseBrowser._check_url() in Lib/webbrowser.py, so that a URL can no
       longer be passed to the browser process as an option
     - CVE-2026-4519
   * SECURITY UPDATE: CPU denial-of-service in html.parser.HTMLParser via
     repeated unterminated markup declarations in incremental parsing
     - debian/patches/CVE-2026-15308.patch: accumulate incrementally fed data
       in a list and only join and parse it once enough has piled up, in
       Lib/HTMLParser.py
     - CVE-2026-15308</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-18"/>
          <updated date="2026-09-18"/>
          <cve cvss3="7.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-74" href="https://cve.tuxcare.com/els/cve/CVE-2026-0864" impact="important" public="20260623">CVE-2026-0864</cve>
          <cve cwe="CWE-22" href="https://cve.tuxcare.com/els/cve/CVE-2007-4559" impact="unknown" public="20070828">CVE-2007-4559</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els/cve/CVE-2026-3644" impact="important" public="20260316">CVE-2026-3644</cve>
          <cve cvss3="7.1/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els/cve/CVE-2026-4519" impact="important" public="20260320">CVE-2026-4519</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-674" href="https://cve.tuxcare.com/els/cve/CVE-2026-4224" impact="important" public="20260316">CVE-2026-4224</cve>
          <cve cvss3="8.7/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els/cve/CVE-2026-15308" impact="important" public="20260709">CVE-2026-15308</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-407" href="https://cve.tuxcare.com/els/cve/CVE-2022-45061" impact="important" public="20221109">CVE-2022-45061</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="idle-python2.7 is earlier than 0:2.7.18-8+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789730024001"/>
        <criterion comment="libpython2.7 is earlier than 0:2.7.18-8+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789730024002"/>
        <criterion comment="libpython2.7-dev is earlier than 0:2.7.18-8+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789730024003"/>
        <criterion comment="libpython2.7-minimal is earlier than 0:2.7.18-8+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789730024004"/>
        <criterion comment="libpython2.7-stdlib is earlier than 0:2.7.18-8+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789730024005"/>
        <criterion comment="libpython2.7-testsuite is earlier than 0:2.7.18-8+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789730024006"/>
        <criterion comment="python2.7 is earlier than 0:2.7.18-8+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789730024007"/>
        <criterion comment="python2.7-dev is earlier than 0:2.7.18-8+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789730024008"/>
        <criterion comment="python2.7-doc is earlier than 0:2.7.18-8+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789730024009"/>
        <criterion comment="python2.7-examples is earlier than 0:2.7.18-8+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789730024010"/>
        <criterion comment="python2.7-minimal is earlier than 0:2.7.18-8+deb11u1+tuxcare.els1" test_ref="oval:com.tuxcare.clsa:tst:1789730024011"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789728065" version="1">
      <metadata>
        <title>Fix of 12 CVEs</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789728065" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789728065" source="CLSA"/>
        <reference ref_id="CVE-2026-53791" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-53791" source="CVE"/>
        <reference ref_id="CVE-2026-53784" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-53784" source="CVE"/>
        <reference ref_id="CVE-2026-70463" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-70463" source="CVE"/>
        <reference ref_id="CVE-2026-70456" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-70456" source="CVE"/>
        <reference ref_id="CVE-2026-53786" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-53786" source="CVE"/>
        <reference ref_id="CVE-2026-53785" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-53785" source="CVE"/>
        <reference ref_id="CVE-2026-53794" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-53794" source="CVE"/>
        <reference ref_id="CVE-2026-53795" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-53795" source="CVE"/>
        <reference ref_id="CVE-2026-70453" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-70453" source="CVE"/>
        <reference ref_id="CVE-2026-70462" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-70462" source="CVE"/>
        <reference ref_id="CVE-2026-70458" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-70458" source="CVE"/>
        <reference ref_id="CVE-2026-70459" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-70459" source="CVE"/>
        <description>* SECURITY UPDATE: CPU exhaustion from a crafted chain of equal weak checksums
     - debian/patches/CVE-2026-70453.patch: bound the number of same-weak-checksum
       candidates hash_search() examines per file offset, so a degenerate chain
       cannot turn the inner loop into an O(file_size * chain_length) scan
     - CVE-2026-70453
   * SECURITY UPDATE: heap out-of-bounds write in read_args()
     - debian/patches/CVE-2026-70456.patch: reserve room for the trailing NULL
       before storing it, so a peer argument count landing exactly on the argv
       allocation cannot write one pointer past the end
     - CVE-2026-70456
   * SECURITY UPDATE: peer-supplied MSG_IO_TIMEOUT defeats the client's timeout
     - debian/patches/CVE-2026-70462.patch: reject a non-positive value, cap the
       peer's value at 24 hours, and make set_io_timeout() arithmetic
       overflow-safe so a large value cannot wrap allowed_lull negative
     - CVE-2026-70462
   * SECURITY UPDATE: authorization bypass in the "auth users" parser
     - debian/patches/CVE-2026-70463.patch: parse with conf_strtok so a leading
       comma splits on commas alone, and a deny or :ro rule naming a group whose
       name contains a space fires as written
     - CVE-2026-70463
   * SECURITY UPDATE: wild-pointer read in the per-connection daemon child
     - debian/patches/CVE-2026-70459.patch: reject a non-directory transfer-root
       entry, and require dir_flist to hold an entry before trusting parent_ndx 0
     - CVE-2026-70459
   * SECURITY UPDATE: out-of-bounds write from a peer-set FLAG_HLINKED
     - debian/patches/CVE-2026-70458.patch: gate FLAG_HLINKED on
       preserve_hard_links and exclude directories, so a peer cannot set it while
       -H is off and have HLINK_BUMP() displace F_SUM() past the extras
     - the same patch carries upstream aed77143, which closes a separate
       unassigned out-of-bounds read of that field: start_server() now sets
       sender_keeps_checksum for a daemon sender using -c with a %C log format,
       and hard_link_check() requires S_ISREG before the basis compare
     - CVE-2026-70458
   * SECURITY UPDATE: the per-allocation size cap could be switched off
     - debian/patches/CVE-2026-53794.patch: reject --max-alloc=0, which disabled
       the cap that is the defence behind CVE-2024-12084 and was forwarded on the
       wire; the rsync.1 text describing 0 as "no limit" is corrected with it
     - a value of 0 is now an error rather than "no limit"; see debian/rsync.NEWS
     - CVE-2026-53794
   * SECURITY UPDATE: implied-parent creation escapes the destination tree
     - debian/patches/CVE-2026-53785.patch: create each component of make_path()
       through the held-directory-fd primitive, so a planted parent symlink under
       --relative cannot place the new directories outside the tree
     - CVE-2026-53785
   * SECURITY UPDATE: source address spoofing via the PROXY protocol header
     - debian/patches/CVE-2026-53791.patch: add the "proxy protocol hosts" global
       and honour a forwarded address only when the direct socket peer matches it,
       so a client connecting directly cannot forge its address past hosts allow
     - "proxy protocol = true" with no "proxy protocol hosts" now refuses every
       connection and warns at startup, which is upstream's fail-closed default;
       see debian/rsync.NEWS
     - CVE-2026-53791
   * SECURITY UPDATE: client-supplied --filter merge file bypasses the module filter
     - debian/patches/CVE-2026-53786.patch: strip the module-dir prefix, when it is
       actually present, before checking the merge file against the daemon filter
       list, and treat a filtered file as absent rather than a fatal error
     - CVE-2026-53786
   * SECURITY UPDATE: absolute --temp-dir or --link-dest disables rename confinement
     - debian/patches/CVE-2026-53795.patch: confine each side of do_rename_at() and
       do_link_at() independently, so an absolute path on one side no longer drops
       the other side back to the unconfined call
     - CVE-2026-53795</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-18"/>
          <updated date="2026-09-18"/>
          <cve cwe="CWE-290" href="https://cve.tuxcare.com/els/cve/CVE-2026-53791" impact="unknown" public="20260813">CVE-2026-53791</cve>
          <cve cwe="CWE-59" href="https://cve.tuxcare.com/els/cve/CVE-2026-53784" impact="unknown" public="20260813">CVE-2026-53784</cve>
          <cve cwe="CWE-863" href="https://cve.tuxcare.com/els/cve/CVE-2026-70463" impact="unknown" public="20260813">CVE-2026-70463</cve>
          <cve cwe="CWE-787" href="https://cve.tuxcare.com/els/cve/CVE-2026-70456" impact="unknown" public="20260813">CVE-2026-70456</cve>
          <cve cwe="CWE-863" href="https://cve.tuxcare.com/els/cve/CVE-2026-53786" impact="unknown" public="20260813">CVE-2026-53786</cve>
          <cve cwe="CWE-59" href="https://cve.tuxcare.com/els/cve/CVE-2026-53785" impact="unknown" public="20260813">CVE-2026-53785</cve>
          <cve cwe="CWE-1284" href="https://cve.tuxcare.com/els/cve/CVE-2026-53794" impact="unknown" public="20260813">CVE-2026-53794</cve>
          <cve cwe="CWE-59" href="https://cve.tuxcare.com/els/cve/CVE-2026-53795" impact="unknown" public="20260813">CVE-2026-53795</cve>
          <cve cwe="CWE-407" href="https://cve.tuxcare.com/els/cve/CVE-2026-70453" impact="unknown" public="20260813">CVE-2026-70453</cve>
          <cve cwe="CWE-190" href="https://cve.tuxcare.com/els/cve/CVE-2026-70462" impact="unknown" public="20260813">CVE-2026-70462</cve>
          <cve cwe="CWE-787" href="https://cve.tuxcare.com/els/cve/CVE-2026-70458" impact="unknown" public="20260813">CVE-2026-70458</cve>
          <cve cwe="CWE-908" href="https://cve.tuxcare.com/els/cve/CVE-2026-70459" impact="unknown" public="20260813">CVE-2026-70459</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="rsync is earlier than 0:3.2.3-4+deb11u4+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789728065001"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789745566" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-89157</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789745566" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789745566" source="CLSA"/>
        <reference ref_id="CVE-2026-89157" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-89157" source="CVE"/>
        <description>* SECURITY UPDATE: Integer overflow in the allocation size computation of
     pcre2_pattern_convert() and pcre2_substring_get_bynumber() leading to an
     undersized buffer and an out-of-bounds heap write, because both sites
     multiplied the code-unit count by the code-unit BIT width rather than its
     byte width and never checked the product for wraparound; reachable with a
     large pattern or captured substring on 32-bit platforms
     - debian/patches/CVE-2026-89157.patch: size both allocations with
       CU2BYTES() and reject a code-unit count that would overflow
       sizeof(pcre2_memctl) + CU2BYTES(n + 1), in src/pcre2_convert.c and
       src/pcre2_substring.c
     - CVE-2026-89157</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-18"/>
          <updated date="2026-09-18"/>
          <cve cvss3="9.4/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H" cwe="CWE-190" href="https://cve.tuxcare.com/els/cve/CVE-2026-89157" impact="critical" public="20260911">CVE-2026-89157</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="libpcre2-16-0 is earlier than 0:10.36-2+deb11u1+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789745566001"/>
        <criterion comment="libpcre2-32-0 is earlier than 0:10.36-2+deb11u1+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789745566002"/>
        <criterion comment="libpcre2-8-0 is earlier than 0:10.36-2+deb11u1+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789745566003"/>
        <criterion comment="libpcre2-dev is earlier than 0:10.36-2+deb11u1+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789745566004"/>
        <criterion comment="libpcre2-posix2 is earlier than 0:10.36-2+deb11u1+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789745566005"/>
        <criterion comment="pcre2-utils is earlier than 0:10.36-2+deb11u1+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789745566006"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789748107" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-72693</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789748107" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789748107" source="CLSA"/>
        <reference ref_id="CVE-2026-72693" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-72693" source="CVE"/>
        <description>* Fix the armel build: enable large-file support
     - debian/rules: build with DEB_BUILD_MAINT_OPTIONS = future=+lfs, so
       kbdfile_find()'s directory search does not fail with EOVERFLOW on
       32-bit architectures; no change on 64-bit, no exported ABI change</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-18"/>
          <updated date="2026-09-18"/>
          <cve cwe="CWE-284" href="https://cve.tuxcare.com/els/cve/CVE-2026-72693" impact="unknown" public="20260811">CVE-2026-72693</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="kbd is earlier than 0:2.3.0-3+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789748107001"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789748401" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2025-14932</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789748401" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789748401" source="CLSA"/>
        <reference ref_id="CVE-2025-14932" ref_url="https://cve.tuxcare.com/els/cve/CVE-2025-14932" source="CVE"/>
        <description>* SECURITY UPDATE: stack buffer overflow in cdParseRelunits() and
     is_valid_time_unit()
     - debian/patches/CVE-2025-14932.patch: bound the sscanf conversions that
       parse the time units attribute to the destination buffer sizes
     - CVE-2025-14932</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-18"/>
          <updated date="2026-09-18"/>
          <cve cwe="CWE-121" href="https://cve.tuxcare.com/els/cve/CVE-2025-14932" impact="unknown" public="20251223">CVE-2025-14932</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="libnetcdf-dev is earlier than 1:4.7.4-1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789748401001"/>
        <criterion comment="libnetcdf18 is earlier than 1:4.7.4-1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789748401002"/>
        <criterion comment="netcdf-bin is earlier than 1:4.7.4-1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789748401003"/>
        <criterion comment="netcdf-doc is earlier than 1:4.7.4-1+tuxcare.els2" test_ref="oval:com.tuxcare.clsa:tst:1789748401004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789780826" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-16118</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789780826" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789780826" source="CLSA"/>
        <reference ref_id="CVE-2026-16118" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-16118" source="CVE"/>
        <description>* SECURITY UPDATE: Out-of-bounds write in the bundled xdgmime magic parser
     - debian/patches/CVE-2026-16118.patch: parenthesize (ptr + i) before the
       cast in _xdg_mime_magic_parse_magic_line() in gio/xdgmime/xdgmimemagic.c,
       so the little-endian byte swap writes at byte offsets instead of scaling
       by sizeof(type) and writing past the end of matchlet-&gt;value and
       matchlet-&gt;mask
     - CVE-2026-16118</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-19"/>
          <updated date="2026-09-19"/>
          <cve cwe="CWE-122" href="https://cve.tuxcare.com/els/cve/CVE-2026-16118" impact="unknown" public="20260717">CVE-2026-16118</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="libglib2.0-0 is earlier than 0:2.66.8-1+deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789780826001"/>
        <criterion comment="libglib2.0-bin is earlier than 0:2.66.8-1+deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789780826002"/>
        <criterion comment="libglib2.0-data is earlier than 0:2.66.8-1+deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789780826003"/>
        <criterion comment="libglib2.0-dev is earlier than 0:2.66.8-1+deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789780826004"/>
        <criterion comment="libglib2.0-dev-bin is earlier than 0:2.66.8-1+deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789780826005"/>
        <criterion comment="libglib2.0-doc is earlier than 0:2.66.8-1+deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789780826006"/>
        <criterion comment="libglib2.0-tests is earlier than 0:2.66.8-1+deb11u8+tuxcare.els3" test_ref="oval:com.tuxcare.clsa:tst:1789780826007"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789785440" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-89158</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789785440" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789785440" source="CLSA"/>
        <reference ref_id="CVE-2026-89158" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-89158" source="CVE"/>
        <description>* CVE-2026-89158: integer overflow in the compiled-pattern block size
     computation in pcre2_compile(), giving an undersized allocation and a
     heap out-of-bounds write; reachable on 32-bit platforms
     - debian/patches/CVE-2026-89158.patch</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-19"/>
          <updated date="2026-09-19"/>
          <cve cvss3="9.4/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L" cwe="CWE-190" href="https://cve.tuxcare.com/els/cve/CVE-2026-89158" impact="critical" public="20260911">CVE-2026-89158</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="libpcre2-16-0 is earlier than 0:10.36-2+deb11u1+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789785440001"/>
        <criterion comment="libpcre2-32-0 is earlier than 0:10.36-2+deb11u1+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789785440002"/>
        <criterion comment="libpcre2-8-0 is earlier than 0:10.36-2+deb11u1+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789785440003"/>
        <criterion comment="libpcre2-dev is earlier than 0:10.36-2+deb11u1+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789785440004"/>
        <criterion comment="libpcre2-posix2 is earlier than 0:10.36-2+deb11u1+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789785440005"/>
        <criterion comment="pcre2-utils is earlier than 0:10.36-2+deb11u1+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789785440006"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1789899030" version="1">
      <metadata>
        <title>Fix CVE(s): CVE-2026-6949</title>
        <affected family="unix">
          <platform>Debian 11</platform>
        </affected>
        <reference ref_id="CLSA-2026:1789899030" ref_url="https://cve.tuxcare.com/els/releases/CLSA-2026:1789899030" source="CLSA"/>
        <reference ref_id="CVE-2026-6949" ref_url="https://cve.tuxcare.com/els/cve/CVE-2026-6949" source="CVE"/>
        <description>* SECURITY UPDATE: out-of-bounds write in the internal DNS server via a
     TSIG-signed packet using DNS name compression
     - debian/patches/CVE-2026-6949.patch: record the start offset of each
       dns_res_rec while pulling it and use the last additional record's
       offset to truncate the buffer for TSIG verification, instead of
       subtracting a re-pushed TSIG record length that can exceed the packet
       and underflow packet_len into a huge memcpy() size
     - CVE-2026-6949</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-09-20"/>
          <updated date="2026-09-20"/>
          <cve cwe="CWE-787" href="https://cve.tuxcare.com/els/cve/CVE-2026-6949" impact="unknown">CVE-2026-6949</cve>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Debian 11 with ELS isn't installed" test_ref="oval:com.tuxcare.clsa:tst:1787918353001"/>
        <criterion comment="ctdb is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789899030001"/>
        <criterion comment="libnss-winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789899030002"/>
        <criterion comment="libpam-winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789899030003"/>
        <criterion comment="libsmbclient is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789899030004"/>
        <criterion comment="libsmbclient-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789899030005"/>
        <criterion comment="libwbclient-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789899030006"/>
        <criterion comment="libwbclient0 is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789899030007"/>
        <criterion comment="python3-samba is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789899030008"/>
        <criterion comment="registry-tools is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789899030009"/>
        <criterion comment="samba is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789899030010"/>
        <criterion comment="samba-common is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789899030011"/>
        <criterion comment="samba-common-bin is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789899030012"/>
        <criterion comment="samba-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789899030013"/>
        <criterion comment="samba-dsdb-modules is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789899030014"/>
        <criterion comment="samba-libs is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789899030015"/>
        <criterion comment="samba-testsuite is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789899030016"/>
        <criterion comment="samba-vfs-modules is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789899030017"/>
        <criterion comment="smbclient is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789899030018"/>
        <criterion comment="winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" test_ref="oval:com.tuxcare.clsa:tst:1789899030019"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <ind-def:textfilecontent54_test check="none satisfy" check_existence="none_exist" comment="Debian 11 with ELS isn't installed" id="oval:com.tuxcare.clsa:tst:1787918353001" version="1">
      <ind-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353001"/>
    </ind-def:textfilecontent54_test>
    <unix-def:uname_test check="none satisfy" comment="kernel earlier than linux-5.10.0-47-amd64 (or unknown) is currently running" id="oval:com.tuxcare.clsa:tst:1787918353002" version="1">
      <unix-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353002"/>
      <unix-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353002"/>
    </unix-def:uname_test>
    <red-def:dpkginfo_test check="at least one" comment="bpftool is earlier than 0:5.10.262-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1787918353003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="hyperv-daemons is earlier than 0:5.10.262-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1787918353004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libcpupower-dev is earlier than 0:5.10.262-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1787918353005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libcpupower1 is earlier than 0:5.10.262-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1787918353006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-compiler-gcc-10-x86 is earlier than 0:5.10.262-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1787918353007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-config-5.10 is earlier than 0:5.10.262-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1787918353008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-cpupower is earlier than 0:5.10.262-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1787918353009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-doc is earlier than 0:5.10.262-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1787918353010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353010"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353010"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-doc-5.10 is earlier than 0:5.10.262-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1787918353011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353010"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-headers-5.10.0-47-amd64 is earlier than 0:5.10.262-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1787918353012" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353012"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-headers-5.10.0-47-common is earlier than 0:5.10.262-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1787918353013" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353010"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-headers-amd64 is earlier than 0:5.10.262-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1787918353014" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353014"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-image-5.10.0-47-amd64-unsigned is earlier than 0:5.10.262-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1787918353015" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353015"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-image-amd64 is earlier than 0:5.10.262-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1787918353016" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353016"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-image-amd64-signed-template is earlier than 0:5.10.262-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1787918353017" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353017"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-kbuild-5.10 is earlier than 0:5.10.262-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1787918353018" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353018"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-libc-dev is earlier than 0:5.10.262-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1787918353019" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353019"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-perf is earlier than 0:5.10.262-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1787918353020" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353020"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-perf-5.10 is earlier than 0:5.10.262-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1787918353021" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353021"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-source is earlier than 0:5.10.262-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1787918353022" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353022"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353010"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-source-5.10 is earlier than 0:5.10.262-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1787918353023" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353023"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353010"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-support-5.10.0-47 is earlier than 0:5.10.262-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1787918353024" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353024"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1787918353010"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libxml2 is earlier than 0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788696775001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788696775001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788696775001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libxml2-dev is earlier than 0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788696775002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788696775002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788696775001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libxml2-doc is earlier than 0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788696775003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788696775003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788696775003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libxml2-utils is earlier than 0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788696775004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788696775004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788696775001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="python3-libxml2 is earlier than 0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788696775005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788696775005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788696775001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnginx-mod-http-auth-pam is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnginx-mod-http-cache-purge is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnginx-mod-http-dav-ext is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnginx-mod-http-echo is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnginx-mod-http-fancyindex is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnginx-mod-http-geoip is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnginx-mod-http-geoip2 is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnginx-mod-http-headers-more-filter is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnginx-mod-http-image-filter is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnginx-mod-http-lua is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858010"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnginx-mod-http-ndk is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnginx-mod-http-perl is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858012" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858012"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnginx-mod-http-subs-filter is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858013" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnginx-mod-http-uploadprogress is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858014" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858014"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnginx-mod-http-upstream-fair is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858015" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858015"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnginx-mod-http-xslt-filter is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858016" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858016"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnginx-mod-mail is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858017" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858017"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnginx-mod-nchan is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858018" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858018"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnginx-mod-rtmp is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858019" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858019"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnginx-mod-stream is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858020" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858020"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnginx-mod-stream-geoip is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858021" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858021"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnginx-mod-stream-geoip2 is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858022" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858022"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="nginx is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858023" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858023"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858023"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="nginx-common is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858024" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858024"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858023"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="nginx-core is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858025" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858025"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="nginx-doc is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858026" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858026"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858023"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="nginx-extras is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858027" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858027"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="nginx-full is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858028" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858028"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858023"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="nginx-light is earlier than 0:1.18.0-6.1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788699858029" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788699858029"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788699858001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="haproxy is earlier than 0:2.2.9-2+deb11u7+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788773292001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788773292001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788773292001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="haproxy-doc is earlier than 0:2.2.9-2+deb11u7+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788773292002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788773292002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788773292002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-haproxy is earlier than 0:2.2.9-2+deb11u7+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788773292003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788773292003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788773292002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="glibc-doc is earlier than 0:2.31-13+deb11u14+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788774752001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788774752001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788774752001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="glibc-source is earlier than 0:2.31-13+deb11u14+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788774752002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788774752002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788774752001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libc-bin is earlier than 0:2.31-13+deb11u14+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788774752003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788774752003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788774752003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libc-dev-bin is earlier than 0:2.31-13+deb11u14+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788774752004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788774752004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788774752003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libc-devtools is earlier than 0:2.31-13+deb11u14+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788774752005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788774752005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788774752003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libc-l10n is earlier than 0:2.31-13+deb11u14+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788774752006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788774752006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788774752001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libc6 is earlier than 0:2.31-13+deb11u14+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788774752007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788774752007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788774752003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libc6-dev is earlier than 0:2.31-13+deb11u14+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788774752008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788774752008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788774752003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libc6-dev-i386 is earlier than 0:2.31-13+deb11u14+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788774752009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788774752009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788774752009"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libc6-dev-x32 is earlier than 0:2.31-13+deb11u14+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788774752010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788774752010"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788774752009"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libc6-i386 is earlier than 0:2.31-13+deb11u14+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788774752011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788774752011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788774752009"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libc6-x32 is earlier than 0:2.31-13+deb11u14+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788774752012" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788774752012"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788774752009"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="locales is earlier than 0:2.31-13+deb11u14+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788774752013" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788774752013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788774752001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="locales-all is earlier than 0:2.31-13+deb11u14+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788774752014" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788774752014"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788774752003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="nscd is earlier than 0:2.31-13+deb11u14+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788774752015" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788774752015"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788774752003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="openvpn is earlier than 0:2.5.1-3+deb11u4+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788774936001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788774936001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788774936001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="krb5-admin-server is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="krb5-doc is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="krb5-gss-samples is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="krb5-k5tls is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="krb5-kdc is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="krb5-kdc-ldap is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="krb5-kpropd is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="krb5-locales is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="krb5-multidev is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="krb5-otp is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309010"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="krb5-pkinit is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="krb5-user is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309012" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309012"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libgssapi-krb5-2 is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309013" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libgssrpc4 is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309014" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309014"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libk5crypto3 is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309015" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309015"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libkadm5clnt-mit12 is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309016" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309016"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libkadm5srv-mit12 is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309017" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309017"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libkdb5-10 is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309018" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309018"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libkrad-dev is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309019" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309019"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libkrad0 is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309020" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309020"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libkrb5-3 is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309021" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309021"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libkrb5-dev is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309022" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309022"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libkrb5support0 is earlier than 0:1.18.3-6+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786309023" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786309023"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786309001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="sudo is earlier than 0:1.9.5p2-3+deb11u4+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786535001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786535001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786535001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="sudo-ldap is earlier than 0:1.9.5p2-3+deb11u4+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788786535002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788786535002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788786535001"/>
    </red-def:dpkginfo_test>
    <unix-def:uname_test check="none satisfy" comment="kernel earlier than linux-5.10.0-48-amd64 (or unknown) is currently running" id="oval:com.tuxcare.clsa:tst:1788803338001" version="1">
      <unix-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353002"/>
      <unix-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338001"/>
    </unix-def:uname_test>
    <red-def:dpkginfo_test check="at least one" comment="bpftool is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="hyperv-daemons is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libcpupower-dev is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libcpupower1 is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-compiler-gcc-10-arm is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788803338006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338006"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-compiler-gcc-10-x86 is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338007"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-config-5.10 is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-cpupower is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-doc is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353010"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338010"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-doc-5.10 is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338010"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-headers-5.10.0-48-amd64 is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338012" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788803338012"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338007"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-headers-5.10.0-48-arm64 is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338013" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788803338013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338013"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-headers-5.10.0-48-common is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338014" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788803338014"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338010"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-headers-5.10.0-48-marvell is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338015" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788803338015"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338006"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-headers-5.10.0-48-rpi is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338016" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788803338016"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338006"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-headers-amd64 is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338017" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353014"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338007"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-headers-arm64 is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338018" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788803338018"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338013"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-headers-marvell is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338019" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788803338019"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338006"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-headers-rpi is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338020" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788803338020"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338006"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-image-5.10.0-48-amd64-unsigned is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338021" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788803338021"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338007"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-image-5.10.0-48-arm64-unsigned is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338022" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788803338022"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338013"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-image-5.10.0-48-marvell is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338023" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788803338023"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338006"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-image-5.10.0-48-rpi is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338024" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788803338024"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338006"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-image-amd64 is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338025" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353016"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338007"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-image-amd64-signed-template is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338026" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353017"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338007"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-image-arm64 is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338027" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788803338027"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338013"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-image-arm64-signed-template is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338028" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788803338028"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338013"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-image-marvell is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338029" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788803338029"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338006"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-image-rpi is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338030" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788803338030"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338006"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-kbuild-5.10 is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338031" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353018"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-libc-dev is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338032" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353019"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-perf is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338033" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353020"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-perf-5.10 is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338034" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353021"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-source is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338035" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353022"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338010"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-source-5.10 is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338036" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1787918353023"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338010"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="linux-support-5.10.0-48 is earlier than 0:5.10.269-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788803338037" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788803338037"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788803338010"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libglib2.0-0 is earlier than 0:2.66.8-1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788819939001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788819939001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788819939001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libglib2.0-bin is earlier than 0:2.66.8-1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788819939002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788819939002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788819939001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libglib2.0-data is earlier than 0:2.66.8-1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788819939003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788819939003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788819939003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libglib2.0-dev is earlier than 0:2.66.8-1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788819939004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788819939004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788819939001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libglib2.0-dev-bin is earlier than 0:2.66.8-1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788819939005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788819939005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788819939001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libglib2.0-doc is earlier than 0:2.66.8-1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788819939006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788819939006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788819939003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libglib2.0-tests is earlier than 0:2.66.8-1+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788819939007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788819939007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788819939001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="squid is earlier than 0:4.13-10+deb11u7+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788884663001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788884663001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788884663001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="squid-cgi is earlier than 0:4.13-10+deb11u7+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788884663002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788884663002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788884663001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="squid-common is earlier than 0:4.13-10+deb11u7+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788884663003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788884663003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788884663003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="squid-openssl is earlier than 0:4.13-10+deb11u7+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788884663004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788884663004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788884663001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="squid-purge is earlier than 0:4.13-10+deb11u7+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788884663005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788884663005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788884663001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="squidclient is earlier than 0:4.13-10+deb11u7+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788884663006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788884663006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788884663001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="haproxy is earlier than 0:2.2.9-2+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1788856712001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788773292001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788856712001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="haproxy-doc is earlier than 0:2.2.9-2+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1788856712002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788773292002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788856712002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-haproxy is earlier than 0:2.2.9-2+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1788856712003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788773292003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788856712002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libssh2-1 is earlier than 0:1.9.0-2+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788943086001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788943086001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788943086001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libssh2-1-dev is earlier than 0:1.9.0-2+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788943086002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788943086002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788943086001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="ctdb is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788966943001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788966943001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnss-winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788966943002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788966943001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpam-winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788966943003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788966943001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libsmbclient is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788966943004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788966943001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libsmbclient-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788966943005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788966943001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libwbclient-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788966943006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788966943001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libwbclient0 is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788966943007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788966943001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="python3-samba is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788966943008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788966943001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="registry-tools is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788966943009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788966943001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788966943010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943010"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788966943001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-common is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788966943011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788966943011"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-common-bin is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788966943012" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943012"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788966943001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788966943013" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788966943001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-dsdb-modules is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788966943014" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943014"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788966943001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-libs is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788966943015" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943015"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788966943001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-testsuite is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788966943016" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943016"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788966943001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-vfs-modules is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788966943017" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943017"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788966943001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="smbclient is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788966943018" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943018"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788966943001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788966943019" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943019"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788966943001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="cups is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788967622001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788967622001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788967622001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="cups-bsd is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788967622002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788967622002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788967622001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="cups-client is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788967622003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788967622003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788967622001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="cups-common is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788967622004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788967622004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788967622004"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="cups-core-drivers is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788967622005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788967622005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788967622001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="cups-daemon is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788967622006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788967622006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788967622001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="cups-ipp-utils is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788967622007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788967622007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788967622001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="cups-ppdc is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788967622008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788967622008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788967622001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="cups-server-common is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788967622009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788967622009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788967622004"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libcups2 is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788967622010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788967622010"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788967622001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libcups2-dev is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788967622011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788967622011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788967622001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libcupsimage2 is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788967622012" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788967622012"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788967622001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libcupsimage2-dev is earlier than 0:2.3.3op2-3+deb11u10+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788967622013" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788967622013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788967622001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="expat is earlier than 0:2.2.10-2+deb11u7+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788968222001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788968222001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788968222001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libexpat1 is earlier than 0:2.2.10-2+deb11u7+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788968222002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788968222002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788968222001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libexpat1-dev is earlier than 0:2.2.10-2+deb11u7+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1788968222003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788968222003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1788968222001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="redis is earlier than 5:6.0.16-1+deb11u9+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789049274001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789049274001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789049274001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="redis-sentinel is earlier than 5:6.0.16-1+deb11u9+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789049274002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789049274002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789049274002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="redis-server is earlier than 5:6.0.16-1+deb11u9+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789049274003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789049274003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789049274002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="redis-tools is earlier than 5:6.0.16-1+deb11u9+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789049274004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789049274004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789049274002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="patch is earlier than 0:2.7.6-7+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789116242001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789116242001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789116242001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="exim4 is earlier than 0:4.94.2-7+deb11u6+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789142195001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789142195001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789142195001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="exim4-base is earlier than 0:4.94.2-7+deb11u6+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789142195002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789142195002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789142195002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="exim4-config is earlier than 0:4.94.2-7+deb11u6+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789142195003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789142195003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789142195001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="exim4-daemon-heavy is earlier than 0:4.94.2-7+deb11u6+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789142195004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789142195004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789142195002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="exim4-daemon-light is earlier than 0:4.94.2-7+deb11u6+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789142195005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789142195005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789142195002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="exim4-dev is earlier than 0:4.94.2-7+deb11u6+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789142195006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789142195006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789142195002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="eximon4 is earlier than 0:4.94.2-7+deb11u6+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789142195007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789142195007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789142195002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="busybox is earlier than 1:1.30.1-6+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789202428001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789202428001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789202428001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="busybox-static is earlier than 1:1.30.1-6+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789202428002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789202428002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789202428001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="busybox-syslogd is earlier than 1:1.30.1-6+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789202428003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789202428003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789202428003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="udhcpc is earlier than 1:1.30.1-6+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789202428004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789202428004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789202428001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="udhcpd is earlier than 1:1.30.1-6+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789202428005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789202428005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789202428001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="gzip is earlier than 0:1.10-4+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789205560001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789205560001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789205560001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="gzip-win32 is earlier than 0:1.10-4+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789205560002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789205560002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789205560002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libssh2-1 is earlier than 0:1.9.0-2+deb11u1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789205759001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788943086001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789205759001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libssh2-1-dev is earlier than 0:1.9.0-2+deb11u1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789205759002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788943086002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789205759001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789206875001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789206875001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-athena is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789206875002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789206875001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-common is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789206875003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789206875003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-doc is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789206875004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789206875003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-gtk is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789206875005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789206875003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-gtk3 is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789206875006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789206875001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-gui-common is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789206875007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789206875003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-nox is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789206875008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789206875001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-runtime is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789206875009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789206875003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-tiny is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789206875010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875010"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789206875001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="xxd is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789206875011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789206875001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="curl is earlier than 0:7.74.0-1.3+deb11u16+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789289969001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789289969001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789289969001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libcurl3-gnutls is earlier than 0:7.74.0-1.3+deb11u16+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789289969002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789289969002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789289969001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libcurl3-nss is earlier than 0:7.74.0-1.3+deb11u16+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789289969003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789289969003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789289969001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libcurl4 is earlier than 0:7.74.0-1.3+deb11u16+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789289969004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789289969004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789289969001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libcurl4-doc is earlier than 0:7.74.0-1.3+deb11u16+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789289969005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789289969005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789289969005"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libcurl4-gnutls-dev is earlier than 0:7.74.0-1.3+deb11u16+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789289969006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789289969006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789289969001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libcurl4-nss-dev is earlier than 0:7.74.0-1.3+deb11u16+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789289969007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789289969007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789289969001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libcurl4-openssl-dev is earlier than 0:7.74.0-1.3+deb11u16+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789289969008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789289969008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789289969001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="git is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789290988001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789290988001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789290988001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="git-all is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789290988002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789290988002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789290988002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="git-cvs is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789290988003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789290988003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789290988002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="git-daemon-run is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789290988004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789290988004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789290988002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="git-daemon-sysvinit is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789290988005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789290988005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789290988002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="git-doc is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789290988006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789290988006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789290988002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="git-el is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789290988007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789290988007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789290988002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="git-email is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789290988008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789290988008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789290988002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="git-gui is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789290988009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789290988009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789290988002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="git-man is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789290988010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789290988010"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789290988002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="git-mediawiki is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789290988011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789290988011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789290988002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="git-svn is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789290988012" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789290988012"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789290988002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="gitk is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789290988013" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789290988013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789290988002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="gitweb is earlier than 1:2.30.2-1+deb11u5+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789290988014" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789290988014"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789290988002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libglib2.0-0 is earlier than 0:2.66.8-1+deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789291176001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788819939001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789291176001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libglib2.0-bin is earlier than 0:2.66.8-1+deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789291176002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788819939002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789291176001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libglib2.0-data is earlier than 0:2.66.8-1+deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789291176003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788819939003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789291176003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libglib2.0-dev is earlier than 0:2.66.8-1+deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789291176004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788819939004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789291176001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libglib2.0-dev-bin is earlier than 0:2.66.8-1+deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789291176005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788819939005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789291176001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libglib2.0-doc is earlier than 0:2.66.8-1+deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789291176006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788819939006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789291176003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libglib2.0-tests is earlier than 0:2.66.8-1+deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789291176007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788819939007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789291176001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="clamav is earlier than 0:1.4.3+dfsg-1~deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789291359001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789291359001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789291359001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="clamav-base is earlier than 0:1.4.3+dfsg-1~deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789291359002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789291359002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789291359002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="clamav-daemon is earlier than 0:1.4.3+dfsg-1~deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789291359003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789291359003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789291359001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="clamav-doc is earlier than 0:1.4.3+dfsg-1~deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789291359004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789291359004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789291359002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="clamav-docs is earlier than 0:1.4.3+dfsg-1~deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789291359005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789291359005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789291359002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="clamav-freshclam is earlier than 0:1.4.3+dfsg-1~deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789291359006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789291359006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789291359001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="clamav-milter is earlier than 0:1.4.3+dfsg-1~deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789291359007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789291359007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789291359001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="clamav-testfiles is earlier than 0:1.4.3+dfsg-1~deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789291359008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789291359008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789291359002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="clamdscan is earlier than 0:1.4.3+dfsg-1~deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789291359009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789291359009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789291359001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libclamav-dev is earlier than 0:1.4.3+dfsg-1~deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789291359010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789291359010"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789291359001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libclamav12 is earlier than 0:1.4.3+dfsg-1~deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789291359011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789291359011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789291359001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="openssh-client is earlier than 1:8.4p1-5+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789374596001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789374596001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789374596001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="openssh-server is earlier than 1:8.4p1-5+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789374596002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789374596002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789374596001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="openssh-sftp-server is earlier than 1:8.4p1-5+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789374596003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789374596003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789374596001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="openssh-tests is earlier than 1:8.4p1-5+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789374596004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789374596004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789374596001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="ssh is earlier than 1:8.4p1-5+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789374596005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789374596005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789374596005"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="ssh-askpass-gnome is earlier than 1:8.4p1-5+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789374596006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789374596006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789374596001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="squid is earlier than 0:4.13-10+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375226001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788884663001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375226001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="squid-cgi is earlier than 0:4.13-10+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375226002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788884663002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375226001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="squid-common is earlier than 0:4.13-10+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375226003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788884663003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375226003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="squid-openssl is earlier than 0:4.13-10+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375226004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788884663004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375226001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="squid-purge is earlier than 0:4.13-10+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375226005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788884663005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375226001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="squidclient is earlier than 0:4.13-10+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375226006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788884663006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375226001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="ctdb is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375441001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375441001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnss-winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375441002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375441001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpam-winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375441003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375441001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libsmbclient is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375441004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375441001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libsmbclient-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375441005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375441001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libwbclient-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375441006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375441001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libwbclient0 is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375441007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375441001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="python3-samba is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375441008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375441001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="registry-tools is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375441009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375441001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375441010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943010"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375441001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-common is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375441011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375441011"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-common-bin is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375441012" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943012"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375441001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375441013" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375441001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-dsdb-modules is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375441014" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943014"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375441001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-libs is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375441015" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943015"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375441001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-testsuite is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375441016" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943016"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375441001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-vfs-modules is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375441017" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943017"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375441001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="smbclient is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375441018" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943018"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375441001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789375441019" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943019"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375441001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="bash is earlier than 0:5.1-2+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789375664001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789375664001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375664001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="bash-builtins is earlier than 0:5.1-2+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789375664002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789375664002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375664001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="bash-doc is earlier than 0:5.1-2+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789375664003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789375664003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375664003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="bash-static is earlier than 0:5.1-2+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789375664004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789375664004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375664001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="zip is earlier than 0:3.0-12+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789375817001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789375817001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789375817001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libunbound-dev is earlier than 0:1.13.1-1+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789042546001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789042546001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789042546001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libunbound8 is earlier than 0:1.13.1-1+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789042546002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789042546002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789042546001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="python3-unbound is earlier than 0:1.13.1-1+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789042546003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789042546003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789042546001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="unbound is earlier than 0:1.13.1-1+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789042546004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789042546004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789042546001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="unbound-anchor is earlier than 0:1.13.1-1+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789042546005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789042546005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789042546001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="unbound-host is earlier than 0:1.13.1-1+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789042546006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789042546006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789042546001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="redis is earlier than 5:6.0.16-1+deb11u9+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789388743001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789049274001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789388743001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="redis-sentinel is earlier than 5:6.0.16-1+deb11u9+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789388743002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789049274002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789388743002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="redis-server is earlier than 5:6.0.16-1+deb11u9+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789388743003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789049274003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789388743002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="redis-tools is earlier than 5:6.0.16-1+deb11u9+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789388743004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789049274004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789388743002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="gawk is earlier than 1:5.1.0-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789390312001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789390312001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789390312001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="composer is earlier than 0:2.0.9-2+deb11u4+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789391878001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789391878001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789391878001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="wget is earlier than 0:1.21-1+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789392206001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789392206001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789392206001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="expat is earlier than 0:2.2.10-2+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789394882001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788968222001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789394882001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libexpat1 is earlier than 0:2.2.10-2+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789394882002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788968222002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789394882001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libexpat1-dev is earlier than 0:2.2.10-2+deb11u7+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789394882003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788968222003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789394882001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="lib32ncurses-dev is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789398674001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789398674001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789398674001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="lib32ncurses6 is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789398674002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789398674002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789398674001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="lib32ncursesw6 is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789398674003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789398674003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789398674001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="lib32tinfo6 is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789398674004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789398674004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789398674001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libncurses-dev is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789398674005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789398674005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789398674005"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libncurses5 is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789398674006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789398674006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789398674005"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libncurses5-dev is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789398674007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789398674007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789398674005"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libncurses6 is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789398674008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789398674008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789398674005"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libncursesw5 is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789398674009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789398674009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789398674005"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libncursesw5-dev is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789398674010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789398674010"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789398674005"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libncursesw6 is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789398674011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789398674011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789398674005"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libtinfo-dev is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789398674012" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789398674012"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789398674005"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libtinfo5 is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789398674013" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789398674013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789398674005"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libtinfo6 is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789398674014" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789398674014"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789398674005"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="ncurses-base is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789398674015" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789398674015"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789398674015"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="ncurses-bin is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789398674016" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789398674016"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789398674005"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="ncurses-doc is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789398674017" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789398674017"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789398674015"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="ncurses-examples is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789398674018" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789398674018"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789398674005"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="ncurses-term is earlier than 0:6.2+20201114-2+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789398674019" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789398674019"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789398674015"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libtomcat9-embed-java is earlier than 0:9.0.118-0+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789461431001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789461431001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789461431001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libtomcat9-java is earlier than 0:9.0.118-0+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789461431002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789461431002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789461431001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="tomcat9 is earlier than 0:9.0.118-0+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789461431003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789461431003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789461431001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="tomcat9-admin is earlier than 0:9.0.118-0+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789461431004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789461431004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789461431001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="tomcat9-common is earlier than 0:9.0.118-0+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789461431005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789461431005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789461431001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="tomcat9-docs is earlier than 0:9.0.118-0+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789461431006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789461431006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789461431001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="tomcat9-examples is earlier than 0:9.0.118-0+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789461431007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789461431007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789461431001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="tomcat9-user is earlier than 0:9.0.118-0+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789461431008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789461431008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789461431001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789463064001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789463064001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-athena is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789463064002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789463064001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-common is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789463064003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789463064003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-doc is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789463064004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789463064003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-gtk is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789463064005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789463064003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-gtk3 is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789463064006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789463064001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-gui-common is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789463064007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789463064003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-nox is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789463064008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789463064001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-runtime is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789463064009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789463064003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-tiny is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789463064010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875010"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789463064001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="xxd is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789463064011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789463064001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="colord is earlier than 0:1.4.5-3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789479755001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789479755001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789479755001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="colord-data is earlier than 0:1.4.5-3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789479755002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789479755002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789479755002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="colord-tests is earlier than 0:1.4.5-3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789479755003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789479755003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789479755001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="gir1.2-colord-1.0 is earlier than 0:1.4.5-3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789479755004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789479755004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789479755001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="gir1.2-colorhug-1.0 is earlier than 0:1.4.5-3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789479755005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789479755005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789479755001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libcolord-dev is earlier than 0:1.4.5-3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789479755006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789479755006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789479755001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libcolord2 is earlier than 0:1.4.5-3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789479755007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789479755007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789479755001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libcolorhug-dev is earlier than 0:1.4.5-3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789479755008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789479755008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789479755001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libcolorhug2 is earlier than 0:1.4.5-3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789479755009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789479755009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789479755001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libarchive-dev is earlier than 0:3.4.3-2+deb11u5+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789483920001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789483920001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789483920001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libarchive-tools is earlier than 0:3.4.3-2+deb11u5+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789483920002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789483920002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789483920001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libarchive13 is earlier than 0:3.4.3-2+deb11u5+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789483920003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789483920003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789483920001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="graphviz is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486509001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486509001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486509001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="graphviz-doc is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486509002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486509002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486509002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libcdt5 is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486509003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486509003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486509001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libcgraph6 is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486509004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486509004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486509001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libgraphviz-dev is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486509005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486509005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486509001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libgv-guile is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486509006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486509006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486509001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libgv-lua is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486509007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486509007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486509001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libgv-perl is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486509008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486509008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486509001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libgv-php7 is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486509009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486509009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486509001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libgv-ruby is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486509010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486509010"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486509001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libgv-tcl is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486509011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486509011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486509001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libgvc6 is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486509012" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486509012"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486509001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libgvc6-plugins-gtk is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486509013" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486509013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486509001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libgvpr2 is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486509014" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486509014"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486509001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="liblab-gamut1 is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486509015" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486509015"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486509001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpathplan4 is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486509016" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486509016"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486509001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libxdot4 is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486509017" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486509017"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486509001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="python3-gv is earlier than 0:2.42.2-5+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486509018" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486509018"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486509001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="gir1.2-poppler-0.18 is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486843001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486843001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486843001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpoppler-cpp-dev is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486843002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486843002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486843001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpoppler-cpp0v5 is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486843003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486843003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486843001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpoppler-dev is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486843004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486843004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486843001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpoppler-glib-dev is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486843005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486843005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486843001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpoppler-glib-doc is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486843006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486843006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486843006"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpoppler-glib8 is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486843007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486843007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486843001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpoppler-private-dev is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486843008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486843008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486843001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpoppler-qt5-1 is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486843009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486843009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486843001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpoppler-qt5-dev is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486843010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486843010"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486843001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpoppler102 is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486843011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486843011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486843001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="poppler-utils is earlier than 0:20.09.0-3.1+deb11u3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789486843012" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789486843012"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789486843001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libperl-dev is earlier than 0:5.32.1-4+deb11u5+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789552364001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789552364001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789552364001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libperl5.32 is earlier than 0:5.32.1-4+deb11u5+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789552364002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789552364002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789552364001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="perl is earlier than 0:5.32.1-4+deb11u5+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789552364003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789552364003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789552364001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="perl-base is earlier than 0:5.32.1-4+deb11u5+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789552364004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789552364004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789552364001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="perl-debug is earlier than 0:5.32.1-4+deb11u5+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789552364005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789552364005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789552364001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="perl-doc is earlier than 0:5.32.1-4+deb11u5+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789552364006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789552364006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789552364006"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="perl-modules-5.32 is earlier than 0:5.32.1-4+deb11u5+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789552364007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789552364007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789552364006"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="xdg-utils is earlier than 0:1.1.3-4.1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789566857001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789566857001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789566857001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnghttp2-14 is earlier than 0:1.43.0-1+deb11u3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789567019001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789567019001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789567019001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnghttp2-dev is earlier than 0:1.43.0-1+deb11u3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789567019002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789567019002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789567019001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnghttp2-doc is earlier than 0:1.43.0-1+deb11u3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789567019003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789567019003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789567019003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="nghttp2 is earlier than 0:1.43.0-1+deb11u3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789567019004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789567019004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789567019003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="nghttp2-client is earlier than 0:1.43.0-1+deb11u3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789567019005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789567019005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789567019001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="nghttp2-proxy is earlier than 0:1.43.0-1+deb11u3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789567019006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789567019006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789567019001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="nghttp2-server is earlier than 0:1.43.0-1+deb11u3+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789567019007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789567019007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789567019001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libxml2 is earlier than 0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789571397001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788696775001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789571397001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libxml2-dev is earlier than 0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789571397002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788696775002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789571397001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libxml2-doc is earlier than 0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789571397003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788696775003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789571397003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libxml2-utils is earlier than 0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789571397004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788696775004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789571397001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="python3-libxml2 is earlier than 0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789571397005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788696775005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789571397001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="gir1.2-harfbuzz-0.0 is earlier than 0:2.7.4-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789573030001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789573030001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789573030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libharfbuzz-bin is earlier than 0:2.7.4-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789573030002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789573030002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789573030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libharfbuzz-dev is earlier than 0:2.7.4-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789573030003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789573030003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789573030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libharfbuzz-doc is earlier than 0:2.7.4-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789573030004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789573030004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789573030004"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libharfbuzz-gobject0 is earlier than 0:2.7.4-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789573030005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789573030005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789573030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libharfbuzz-icu0 is earlier than 0:2.7.4-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789573030006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789573030006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789573030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libharfbuzz0b is earlier than 0:2.7.4-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789573030007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789573030007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789573030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="dmidecode is earlier than 0:3.3-2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789574775001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789574775001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789574775001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="postfix is earlier than 0:3.5.25-0+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789577104001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789577104001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577104001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="postfix-cdb is earlier than 0:3.5.25-0+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789577104002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789577104002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577104001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="postfix-doc is earlier than 0:3.5.25-0+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789577104003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789577104003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577104003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="postfix-ldap is earlier than 0:3.5.25-0+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789577104004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789577104004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577104001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="postfix-lmdb is earlier than 0:3.5.25-0+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789577104005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789577104005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577104001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="postfix-mysql is earlier than 0:3.5.25-0+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789577104006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789577104006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577104001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="postfix-pcre is earlier than 0:3.5.25-0+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789577104007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789577104007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577104001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="postfix-pgsql is earlier than 0:3.5.25-0+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789577104008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789577104008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577104001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="postfix-sqlite is earlier than 0:3.5.25-0+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789577104009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789577104009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577104001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="ctdb is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789577411001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577411001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnss-winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789577411002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577411001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpam-winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789577411003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577411001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libsmbclient is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789577411004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577411001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libsmbclient-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789577411005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577411001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libwbclient-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789577411006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577411001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libwbclient0 is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789577411007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577411001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="python3-samba is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789577411008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577411001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="registry-tools is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789577411009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577411001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789577411010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943010"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577411001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-common is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789577411011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577411011"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-common-bin is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789577411012" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943012"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577411001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789577411013" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577411001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-dsdb-modules is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789577411014" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943014"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577411001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-libs is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789577411015" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943015"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577411001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-testsuite is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789577411016" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943016"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577411001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-vfs-modules is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789577411017" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943017"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577411001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="smbclient is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789577411018" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943018"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577411001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789577411019" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943019"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789577411001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpcre16-3 is earlier than 2:8.39-13+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789581984001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789581984001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789581984001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpcre3 is earlier than 2:8.39-13+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789581984002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789581984002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789581984001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpcre3-dev is earlier than 2:8.39-13+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789581984003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789581984003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789581984001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpcre32-3 is earlier than 2:8.39-13+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789581984004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789581984004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789581984001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpcrecpp0v5 is earlier than 2:8.39-13+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789581984005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789581984005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789581984001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="pcregrep is earlier than 2:8.39-13+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789581984006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789581984006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789581984001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="lemon is earlier than 0:3.34.1-3+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789582390001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789582390001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789582390001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libsqlite3-0 is earlier than 0:3.34.1-3+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789582390002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789582390002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789582390001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libsqlite3-dev is earlier than 0:3.34.1-3+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789582390003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789582390003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789582390001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libsqlite3-tcl is earlier than 0:3.34.1-3+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789582390004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789582390004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789582390001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="sqlite3 is earlier than 0:3.34.1-3+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789582390005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789582390005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789582390001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="sqlite3-doc is earlier than 0:3.34.1-3+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789582390006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789582390006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789582390006"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="rsync is earlier than 0:3.2.3-4+deb11u4+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789635862001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789635862001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789635862001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="openvpn is earlier than 0:2.5.1-3+deb11u4+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789639853001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788774936001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789639853001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els11" id="oval:com.tuxcare.clsa:tst:1789639975001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789639975001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-athena is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els11" id="oval:com.tuxcare.clsa:tst:1789639975002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789639975001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-common is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els11" id="oval:com.tuxcare.clsa:tst:1789639975003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789639975003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-doc is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els11" id="oval:com.tuxcare.clsa:tst:1789639975004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789639975003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-gtk is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els11" id="oval:com.tuxcare.clsa:tst:1789639975005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789639975003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-gtk3 is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els11" id="oval:com.tuxcare.clsa:tst:1789639975006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789639975001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-gui-common is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els11" id="oval:com.tuxcare.clsa:tst:1789639975007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789639975003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-nox is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els11" id="oval:com.tuxcare.clsa:tst:1789639975008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789639975001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-runtime is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els11" id="oval:com.tuxcare.clsa:tst:1789639975009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789639975003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="vim-tiny is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els11" id="oval:com.tuxcare.clsa:tst:1789639975010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875010"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789639975001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="xxd is earlier than 2:8.2.2434-3+deb11u3+tuxcare.els11" id="oval:com.tuxcare.clsa:tst:1789639975011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789206875011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789639975001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libssl-dev is earlier than 0:1.1.1w-0+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789641466001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789641466001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789641466001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libssl-doc is earlier than 0:1.1.1w-0+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789641466002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789641466002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789641466002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libssl1.1 is earlier than 0:1.1.1w-0+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789641466003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789641466003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789641466001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="openssl is earlier than 0:1.1.1w-0+deb11u8+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789641466004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789641466004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789641466001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="rsyslog is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789643272001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643272001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789643272001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="rsyslog-czmq is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789643272002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643272002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789643272001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="rsyslog-elasticsearch is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789643272003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643272003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789643272001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="rsyslog-gnutls is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789643272004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643272004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789643272001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="rsyslog-gssapi is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789643272005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643272005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789643272001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="rsyslog-hiredis is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789643272006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643272006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789643272001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="rsyslog-kafka is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789643272007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643272007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789643272001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="rsyslog-mongodb is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789643272008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643272008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789643272001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="rsyslog-mysql is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789643272009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643272009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789643272001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="rsyslog-openssl is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789643272010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643272010"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789643272001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="rsyslog-pgsql is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789643272011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643272011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789643272001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="rsyslog-relp is earlier than 0:8.2102.0-2+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789643272012" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789643272012"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789643272001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnetcdf-dev is earlier than 1:4.7.4-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789661255001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789661255001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789661255001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnetcdf18 is earlier than 1:4.7.4-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789661255002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789661255002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789661255001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="netcdf-bin is earlier than 1:4.7.4-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789661255003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789661255003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789661255001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="netcdf-doc is earlier than 1:4.7.4-1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789661255004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789661255004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789661255004"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpcre2-16-0 is earlier than 0:10.36-2+deb11u1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789666971001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789666971001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789666971001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpcre2-32-0 is earlier than 0:10.36-2+deb11u1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789666971002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789666971002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789666971001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpcre2-8-0 is earlier than 0:10.36-2+deb11u1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789666971003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789666971003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789666971001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpcre2-dev is earlier than 0:10.36-2+deb11u1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789666971004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789666971004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789666971001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpcre2-posix2 is earlier than 0:10.36-2+deb11u1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789666971005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789666971005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789666971001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="pcre2-utils is earlier than 0:10.36-2+deb11u1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789666971006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789666971006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789666971001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="pypy-pyasn1 is earlier than 0:0.4.8-1+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789671837001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789671837001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789671837001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="python-pyasn1-doc is earlier than 0:0.4.8-1+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789671837002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789671837002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789671837001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="python3-pyasn1 is earlier than 0:0.4.8-1+deb11u2+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789671837003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789671837003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789671837001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libperl-dev is earlier than 0:5.32.1-4+deb11u5+tuxcare.els5" id="oval:com.tuxcare.clsa:tst:1789718965001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789552364001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789718965001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libperl5.32 is earlier than 0:5.32.1-4+deb11u5+tuxcare.els5" id="oval:com.tuxcare.clsa:tst:1789718965002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789552364002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789718965001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="perl is earlier than 0:5.32.1-4+deb11u5+tuxcare.els5" id="oval:com.tuxcare.clsa:tst:1789718965003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789552364003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789718965001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="perl-base is earlier than 0:5.32.1-4+deb11u5+tuxcare.els5" id="oval:com.tuxcare.clsa:tst:1789718965004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789552364004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789718965001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="perl-debug is earlier than 0:5.32.1-4+deb11u5+tuxcare.els5" id="oval:com.tuxcare.clsa:tst:1789718965005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789552364005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789718965001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="perl-doc is earlier than 0:5.32.1-4+deb11u5+tuxcare.els5" id="oval:com.tuxcare.clsa:tst:1789718965006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789552364006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789718965006"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="perl-modules-5.32 is earlier than 0:5.32.1-4+deb11u5+tuxcare.els5" id="oval:com.tuxcare.clsa:tst:1789718965007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789552364007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789718965006"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="idle-python2.7 is earlier than 0:2.7.18-8+deb11u1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789719259001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789719259001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789719259001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpython2.7 is earlier than 0:2.7.18-8+deb11u1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789719259002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789719259002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789719259002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpython2.7-dev is earlier than 0:2.7.18-8+deb11u1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789719259003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789719259003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789719259002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpython2.7-minimal is earlier than 0:2.7.18-8+deb11u1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789719259004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789719259004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789719259002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpython2.7-stdlib is earlier than 0:2.7.18-8+deb11u1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789719259005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789719259005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789719259002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpython2.7-testsuite is earlier than 0:2.7.18-8+deb11u1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789719259006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789719259006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789719259001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="python2.7 is earlier than 0:2.7.18-8+deb11u1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789719259007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789719259007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789719259002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="python2.7-dev is earlier than 0:2.7.18-8+deb11u1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789719259008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789719259008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789719259002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="python2.7-doc is earlier than 0:2.7.18-8+deb11u1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789719259009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789719259009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789719259001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="python2.7-examples is earlier than 0:2.7.18-8+deb11u1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789719259010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789719259010"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789719259001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="python2.7-minimal is earlier than 0:2.7.18-8+deb11u1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789719259011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789719259011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789719259002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="idle-python2.7 is earlier than 0:2.7.18-8+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789730024001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789719259001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789730024001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpython2.7 is earlier than 0:2.7.18-8+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789730024002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789719259002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789730024002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpython2.7-dev is earlier than 0:2.7.18-8+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789730024003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789719259003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789730024002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpython2.7-minimal is earlier than 0:2.7.18-8+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789730024004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789719259004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789730024002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpython2.7-stdlib is earlier than 0:2.7.18-8+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789730024005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789719259005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789730024002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpython2.7-testsuite is earlier than 0:2.7.18-8+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789730024006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789719259006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789730024001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="python2.7 is earlier than 0:2.7.18-8+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789730024007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789719259007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789730024002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="python2.7-dev is earlier than 0:2.7.18-8+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789730024008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789719259008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789730024002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="python2.7-doc is earlier than 0:2.7.18-8+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789730024009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789719259009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789730024001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="python2.7-examples is earlier than 0:2.7.18-8+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789730024010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789719259010"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789730024001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="python2.7-minimal is earlier than 0:2.7.18-8+deb11u1+tuxcare.els1" id="oval:com.tuxcare.clsa:tst:1789730024011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789719259011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789730024002"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="rsync is earlier than 0:3.2.3-4+deb11u4+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789728065001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789635862001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789728065001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpcre2-16-0 is earlier than 0:10.36-2+deb11u1+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789745566001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789666971001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789745566001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpcre2-32-0 is earlier than 0:10.36-2+deb11u1+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789745566002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789666971002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789745566001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpcre2-8-0 is earlier than 0:10.36-2+deb11u1+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789745566003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789666971003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789745566001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpcre2-dev is earlier than 0:10.36-2+deb11u1+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789745566004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789666971004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789745566001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpcre2-posix2 is earlier than 0:10.36-2+deb11u1+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789745566005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789666971005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789745566001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="pcre2-utils is earlier than 0:10.36-2+deb11u1+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789745566006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789666971006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789745566001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="kbd is earlier than 0:2.3.0-3+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789748107001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789748107001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789748107001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnetcdf-dev is earlier than 1:4.7.4-1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789748401001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789661255001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789748401001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnetcdf18 is earlier than 1:4.7.4-1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789748401002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789661255002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789748401001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="netcdf-bin is earlier than 1:4.7.4-1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789748401003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789661255003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789748401001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="netcdf-doc is earlier than 1:4.7.4-1+tuxcare.els2" id="oval:com.tuxcare.clsa:tst:1789748401004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789661255004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789748401004"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libglib2.0-0 is earlier than 0:2.66.8-1+deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789780826001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788819939001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789780826001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libglib2.0-bin is earlier than 0:2.66.8-1+deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789780826002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788819939002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789780826001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libglib2.0-data is earlier than 0:2.66.8-1+deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789780826003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788819939003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789780826003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libglib2.0-dev is earlier than 0:2.66.8-1+deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789780826004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788819939004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789780826001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libglib2.0-dev-bin is earlier than 0:2.66.8-1+deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789780826005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788819939005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789780826001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libglib2.0-doc is earlier than 0:2.66.8-1+deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789780826006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788819939006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789780826003"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libglib2.0-tests is earlier than 0:2.66.8-1+deb11u8+tuxcare.els3" id="oval:com.tuxcare.clsa:tst:1789780826007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788819939007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789780826001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpcre2-16-0 is earlier than 0:10.36-2+deb11u1+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789785440001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789666971001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789785440001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpcre2-32-0 is earlier than 0:10.36-2+deb11u1+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789785440002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789666971002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789785440001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpcre2-8-0 is earlier than 0:10.36-2+deb11u1+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789785440003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789666971003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789785440001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpcre2-dev is earlier than 0:10.36-2+deb11u1+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789785440004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789666971004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789785440001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpcre2-posix2 is earlier than 0:10.36-2+deb11u1+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789785440005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789666971005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789785440001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="pcre2-utils is earlier than 0:10.36-2+deb11u1+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789785440006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1789666971006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789785440001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="ctdb is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789899030001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789899030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libnss-winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789899030002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943002"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789899030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libpam-winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789899030003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789899030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libsmbclient is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789899030004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943004"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789899030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libsmbclient-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789899030005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789899030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libwbclient-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789899030006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943006"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789899030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="libwbclient0 is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789899030007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789899030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="python3-samba is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789899030008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943008"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789899030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="registry-tools is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789899030009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789899030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789899030010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943010"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789899030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-common is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789899030011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789899030011"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-common-bin is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789899030012" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943012"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789899030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-dev is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789899030013" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789899030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-dsdb-modules is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789899030014" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943014"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789899030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-libs is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789899030015" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943015"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789899030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-testsuite is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789899030016" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943016"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789899030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="samba-vfs-modules is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789899030017" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943017"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789899030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="smbclient is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789899030018" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943018"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789899030001"/>
    </red-def:dpkginfo_test>
    <red-def:dpkginfo_test check="at least one" comment="winbind is earlier than 2:4.13.13+dfsg-1~deb11u8+tuxcare.els4" id="oval:com.tuxcare.clsa:tst:1789899030019" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1788966943019"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1789899030001"/>
    </red-def:dpkginfo_test>
  </tests>
  <objects>
    <ind-def:textfilecontent54_object id="oval:com.tuxcare.clsa:obj:1787918353001" version="1">
      <ind-def:filepath datatype="string">/etc/els-release</ind-def:filepath>
      <ind-def:pattern operation="pattern match">Debian 11 LTS \(ELS by TuxCare\)</ind-def:pattern>
      <ind-def:instance datatype="int">1</ind-def:instance>
    </ind-def:textfilecontent54_object>
    <unix-def:uname_object id="oval:com.tuxcare.clsa:obj:1787918353002" version="1"/>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1787918353003" version="1">
      <red-def:name>bpftool</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1787918353004" version="1">
      <red-def:name>hyperv-daemons</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1787918353005" version="1">
      <red-def:name>libcpupower-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1787918353006" version="1">
      <red-def:name>libcpupower1</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1787918353007" version="1">
      <red-def:name>linux-compiler-gcc-10-x86</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1787918353008" version="1">
      <red-def:name>linux-config-5.10</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1787918353009" version="1">
      <red-def:name>linux-cpupower</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1787918353010" version="1">
      <red-def:name>linux-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1787918353011" version="1">
      <red-def:name>linux-doc-5.10</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1787918353012" version="1">
      <red-def:name>linux-headers-5.10.0-47-amd64</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1787918353013" version="1">
      <red-def:name>linux-headers-5.10.0-47-common</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1787918353014" version="1">
      <red-def:name>linux-headers-amd64</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1787918353015" version="1">
      <red-def:name>linux-image-5.10.0-47-amd64-unsigned</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1787918353016" version="1">
      <red-def:name>linux-image-amd64</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1787918353017" version="1">
      <red-def:name>linux-image-amd64-signed-template</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1787918353018" version="1">
      <red-def:name>linux-kbuild-5.10</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1787918353019" version="1">
      <red-def:name>linux-libc-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1787918353020" version="1">
      <red-def:name>linux-perf</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1787918353021" version="1">
      <red-def:name>linux-perf-5.10</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1787918353022" version="1">
      <red-def:name>linux-source</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1787918353023" version="1">
      <red-def:name>linux-source-5.10</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1787918353024" version="1">
      <red-def:name>linux-support-5.10.0-47</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788696775001" version="1">
      <red-def:name>libxml2</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788696775002" version="1">
      <red-def:name>libxml2-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788696775003" version="1">
      <red-def:name>libxml2-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788696775004" version="1">
      <red-def:name>libxml2-utils</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788696775005" version="1">
      <red-def:name>python3-libxml2</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858001" version="1">
      <red-def:name>libnginx-mod-http-auth-pam</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858002" version="1">
      <red-def:name>libnginx-mod-http-cache-purge</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858003" version="1">
      <red-def:name>libnginx-mod-http-dav-ext</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858004" version="1">
      <red-def:name>libnginx-mod-http-echo</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858005" version="1">
      <red-def:name>libnginx-mod-http-fancyindex</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858006" version="1">
      <red-def:name>libnginx-mod-http-geoip</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858007" version="1">
      <red-def:name>libnginx-mod-http-geoip2</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858008" version="1">
      <red-def:name>libnginx-mod-http-headers-more-filter</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858009" version="1">
      <red-def:name>libnginx-mod-http-image-filter</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858010" version="1">
      <red-def:name>libnginx-mod-http-lua</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858011" version="1">
      <red-def:name>libnginx-mod-http-ndk</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858012" version="1">
      <red-def:name>libnginx-mod-http-perl</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858013" version="1">
      <red-def:name>libnginx-mod-http-subs-filter</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858014" version="1">
      <red-def:name>libnginx-mod-http-uploadprogress</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858015" version="1">
      <red-def:name>libnginx-mod-http-upstream-fair</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858016" version="1">
      <red-def:name>libnginx-mod-http-xslt-filter</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858017" version="1">
      <red-def:name>libnginx-mod-mail</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858018" version="1">
      <red-def:name>libnginx-mod-nchan</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858019" version="1">
      <red-def:name>libnginx-mod-rtmp</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858020" version="1">
      <red-def:name>libnginx-mod-stream</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858021" version="1">
      <red-def:name>libnginx-mod-stream-geoip</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858022" version="1">
      <red-def:name>libnginx-mod-stream-geoip2</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858023" version="1">
      <red-def:name>nginx</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858024" version="1">
      <red-def:name>nginx-common</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858025" version="1">
      <red-def:name>nginx-core</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858026" version="1">
      <red-def:name>nginx-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858027" version="1">
      <red-def:name>nginx-extras</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858028" version="1">
      <red-def:name>nginx-full</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788699858029" version="1">
      <red-def:name>nginx-light</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788773292001" version="1">
      <red-def:name>haproxy</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788773292002" version="1">
      <red-def:name>haproxy-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788773292003" version="1">
      <red-def:name>vim-haproxy</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788774752001" version="1">
      <red-def:name>glibc-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788774752002" version="1">
      <red-def:name>glibc-source</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788774752003" version="1">
      <red-def:name>libc-bin</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788774752004" version="1">
      <red-def:name>libc-dev-bin</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788774752005" version="1">
      <red-def:name>libc-devtools</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788774752006" version="1">
      <red-def:name>libc-l10n</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788774752007" version="1">
      <red-def:name>libc6</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788774752008" version="1">
      <red-def:name>libc6-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788774752009" version="1">
      <red-def:name>libc6-dev-i386</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788774752010" version="1">
      <red-def:name>libc6-dev-x32</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788774752011" version="1">
      <red-def:name>libc6-i386</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788774752012" version="1">
      <red-def:name>libc6-x32</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788774752013" version="1">
      <red-def:name>locales</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788774752014" version="1">
      <red-def:name>locales-all</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788774752015" version="1">
      <red-def:name>nscd</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788774936001" version="1">
      <red-def:name>openvpn</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309001" version="1">
      <red-def:name>krb5-admin-server</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309002" version="1">
      <red-def:name>krb5-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309003" version="1">
      <red-def:name>krb5-gss-samples</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309004" version="1">
      <red-def:name>krb5-k5tls</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309005" version="1">
      <red-def:name>krb5-kdc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309006" version="1">
      <red-def:name>krb5-kdc-ldap</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309007" version="1">
      <red-def:name>krb5-kpropd</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309008" version="1">
      <red-def:name>krb5-locales</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309009" version="1">
      <red-def:name>krb5-multidev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309010" version="1">
      <red-def:name>krb5-otp</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309011" version="1">
      <red-def:name>krb5-pkinit</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309012" version="1">
      <red-def:name>krb5-user</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309013" version="1">
      <red-def:name>libgssapi-krb5-2</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309014" version="1">
      <red-def:name>libgssrpc4</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309015" version="1">
      <red-def:name>libk5crypto3</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309016" version="1">
      <red-def:name>libkadm5clnt-mit12</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309017" version="1">
      <red-def:name>libkadm5srv-mit12</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309018" version="1">
      <red-def:name>libkdb5-10</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309019" version="1">
      <red-def:name>libkrad-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309020" version="1">
      <red-def:name>libkrad0</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309021" version="1">
      <red-def:name>libkrb5-3</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309022" version="1">
      <red-def:name>libkrb5-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786309023" version="1">
      <red-def:name>libkrb5support0</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786535001" version="1">
      <red-def:name>sudo</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788786535002" version="1">
      <red-def:name>sudo-ldap</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788803338006" version="1">
      <red-def:name>linux-compiler-gcc-10-arm</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788803338012" version="1">
      <red-def:name>linux-headers-5.10.0-48-amd64</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788803338013" version="1">
      <red-def:name>linux-headers-5.10.0-48-arm64</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788803338014" version="1">
      <red-def:name>linux-headers-5.10.0-48-common</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788803338015" version="1">
      <red-def:name>linux-headers-5.10.0-48-marvell</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788803338016" version="1">
      <red-def:name>linux-headers-5.10.0-48-rpi</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788803338018" version="1">
      <red-def:name>linux-headers-arm64</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788803338019" version="1">
      <red-def:name>linux-headers-marvell</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788803338020" version="1">
      <red-def:name>linux-headers-rpi</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788803338021" version="1">
      <red-def:name>linux-image-5.10.0-48-amd64-unsigned</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788803338022" version="1">
      <red-def:name>linux-image-5.10.0-48-arm64-unsigned</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788803338023" version="1">
      <red-def:name>linux-image-5.10.0-48-marvell</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788803338024" version="1">
      <red-def:name>linux-image-5.10.0-48-rpi</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788803338027" version="1">
      <red-def:name>linux-image-arm64</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788803338028" version="1">
      <red-def:name>linux-image-arm64-signed-template</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788803338029" version="1">
      <red-def:name>linux-image-marvell</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788803338030" version="1">
      <red-def:name>linux-image-rpi</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788803338037" version="1">
      <red-def:name>linux-support-5.10.0-48</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788819939001" version="1">
      <red-def:name>libglib2.0-0</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788819939002" version="1">
      <red-def:name>libglib2.0-bin</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788819939003" version="1">
      <red-def:name>libglib2.0-data</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788819939004" version="1">
      <red-def:name>libglib2.0-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788819939005" version="1">
      <red-def:name>libglib2.0-dev-bin</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788819939006" version="1">
      <red-def:name>libglib2.0-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788819939007" version="1">
      <red-def:name>libglib2.0-tests</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788884663001" version="1">
      <red-def:name>squid</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788884663002" version="1">
      <red-def:name>squid-cgi</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788884663003" version="1">
      <red-def:name>squid-common</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788884663004" version="1">
      <red-def:name>squid-openssl</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788884663005" version="1">
      <red-def:name>squid-purge</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788884663006" version="1">
      <red-def:name>squidclient</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788943086001" version="1">
      <red-def:name>libssh2-1</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788943086002" version="1">
      <red-def:name>libssh2-1-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788966943001" version="1">
      <red-def:name>ctdb</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788966943002" version="1">
      <red-def:name>libnss-winbind</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788966943003" version="1">
      <red-def:name>libpam-winbind</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788966943004" version="1">
      <red-def:name>libsmbclient</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788966943005" version="1">
      <red-def:name>libsmbclient-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788966943006" version="1">
      <red-def:name>libwbclient-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788966943007" version="1">
      <red-def:name>libwbclient0</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788966943008" version="1">
      <red-def:name>python3-samba</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788966943009" version="1">
      <red-def:name>registry-tools</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788966943010" version="1">
      <red-def:name>samba</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788966943011" version="1">
      <red-def:name>samba-common</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788966943012" version="1">
      <red-def:name>samba-common-bin</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788966943013" version="1">
      <red-def:name>samba-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788966943014" version="1">
      <red-def:name>samba-dsdb-modules</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788966943015" version="1">
      <red-def:name>samba-libs</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788966943016" version="1">
      <red-def:name>samba-testsuite</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788966943017" version="1">
      <red-def:name>samba-vfs-modules</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788966943018" version="1">
      <red-def:name>smbclient</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788966943019" version="1">
      <red-def:name>winbind</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788967622001" version="1">
      <red-def:name>cups</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788967622002" version="1">
      <red-def:name>cups-bsd</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788967622003" version="1">
      <red-def:name>cups-client</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788967622004" version="1">
      <red-def:name>cups-common</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788967622005" version="1">
      <red-def:name>cups-core-drivers</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788967622006" version="1">
      <red-def:name>cups-daemon</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788967622007" version="1">
      <red-def:name>cups-ipp-utils</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788967622008" version="1">
      <red-def:name>cups-ppdc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788967622009" version="1">
      <red-def:name>cups-server-common</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788967622010" version="1">
      <red-def:name>libcups2</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788967622011" version="1">
      <red-def:name>libcups2-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788967622012" version="1">
      <red-def:name>libcupsimage2</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788967622013" version="1">
      <red-def:name>libcupsimage2-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788968222001" version="1">
      <red-def:name>expat</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788968222002" version="1">
      <red-def:name>libexpat1</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1788968222003" version="1">
      <red-def:name>libexpat1-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789049274001" version="1">
      <red-def:name>redis</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789049274002" version="1">
      <red-def:name>redis-sentinel</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789049274003" version="1">
      <red-def:name>redis-server</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789049274004" version="1">
      <red-def:name>redis-tools</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789116242001" version="1">
      <red-def:name>patch</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789142195001" version="1">
      <red-def:name>exim4</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789142195002" version="1">
      <red-def:name>exim4-base</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789142195003" version="1">
      <red-def:name>exim4-config</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789142195004" version="1">
      <red-def:name>exim4-daemon-heavy</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789142195005" version="1">
      <red-def:name>exim4-daemon-light</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789142195006" version="1">
      <red-def:name>exim4-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789142195007" version="1">
      <red-def:name>eximon4</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789202428001" version="1">
      <red-def:name>busybox</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789202428002" version="1">
      <red-def:name>busybox-static</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789202428003" version="1">
      <red-def:name>busybox-syslogd</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789202428004" version="1">
      <red-def:name>udhcpc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789202428005" version="1">
      <red-def:name>udhcpd</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789205560001" version="1">
      <red-def:name>gzip</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789205560002" version="1">
      <red-def:name>gzip-win32</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789206875001" version="1">
      <red-def:name>vim</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789206875002" version="1">
      <red-def:name>vim-athena</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789206875003" version="1">
      <red-def:name>vim-common</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789206875004" version="1">
      <red-def:name>vim-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789206875005" version="1">
      <red-def:name>vim-gtk</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789206875006" version="1">
      <red-def:name>vim-gtk3</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789206875007" version="1">
      <red-def:name>vim-gui-common</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789206875008" version="1">
      <red-def:name>vim-nox</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789206875009" version="1">
      <red-def:name>vim-runtime</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789206875010" version="1">
      <red-def:name>vim-tiny</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789206875011" version="1">
      <red-def:name>xxd</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789289969001" version="1">
      <red-def:name>curl</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789289969002" version="1">
      <red-def:name>libcurl3-gnutls</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789289969003" version="1">
      <red-def:name>libcurl3-nss</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789289969004" version="1">
      <red-def:name>libcurl4</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789289969005" version="1">
      <red-def:name>libcurl4-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789289969006" version="1">
      <red-def:name>libcurl4-gnutls-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789289969007" version="1">
      <red-def:name>libcurl4-nss-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789289969008" version="1">
      <red-def:name>libcurl4-openssl-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789290988001" version="1">
      <red-def:name>git</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789290988002" version="1">
      <red-def:name>git-all</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789290988003" version="1">
      <red-def:name>git-cvs</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789290988004" version="1">
      <red-def:name>git-daemon-run</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789290988005" version="1">
      <red-def:name>git-daemon-sysvinit</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789290988006" version="1">
      <red-def:name>git-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789290988007" version="1">
      <red-def:name>git-el</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789290988008" version="1">
      <red-def:name>git-email</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789290988009" version="1">
      <red-def:name>git-gui</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789290988010" version="1">
      <red-def:name>git-man</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789290988011" version="1">
      <red-def:name>git-mediawiki</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789290988012" version="1">
      <red-def:name>git-svn</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789290988013" version="1">
      <red-def:name>gitk</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789290988014" version="1">
      <red-def:name>gitweb</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789291359001" version="1">
      <red-def:name>clamav</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789291359002" version="1">
      <red-def:name>clamav-base</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789291359003" version="1">
      <red-def:name>clamav-daemon</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789291359004" version="1">
      <red-def:name>clamav-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789291359005" version="1">
      <red-def:name>clamav-docs</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789291359006" version="1">
      <red-def:name>clamav-freshclam</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789291359007" version="1">
      <red-def:name>clamav-milter</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789291359008" version="1">
      <red-def:name>clamav-testfiles</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789291359009" version="1">
      <red-def:name>clamdscan</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789291359010" version="1">
      <red-def:name>libclamav-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789291359011" version="1">
      <red-def:name>libclamav12</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789374596001" version="1">
      <red-def:name>openssh-client</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789374596002" version="1">
      <red-def:name>openssh-server</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789374596003" version="1">
      <red-def:name>openssh-sftp-server</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789374596004" version="1">
      <red-def:name>openssh-tests</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789374596005" version="1">
      <red-def:name>ssh</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789374596006" version="1">
      <red-def:name>ssh-askpass-gnome</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789375664001" version="1">
      <red-def:name>bash</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789375664002" version="1">
      <red-def:name>bash-builtins</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789375664003" version="1">
      <red-def:name>bash-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789375664004" version="1">
      <red-def:name>bash-static</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789375817001" version="1">
      <red-def:name>zip</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789042546001" version="1">
      <red-def:name>libunbound-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789042546002" version="1">
      <red-def:name>libunbound8</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789042546003" version="1">
      <red-def:name>python3-unbound</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789042546004" version="1">
      <red-def:name>unbound</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789042546005" version="1">
      <red-def:name>unbound-anchor</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789042546006" version="1">
      <red-def:name>unbound-host</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789390312001" version="1">
      <red-def:name>gawk</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789391878001" version="1">
      <red-def:name>composer</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789392206001" version="1">
      <red-def:name>wget</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789398674001" version="1">
      <red-def:name>lib32ncurses-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789398674002" version="1">
      <red-def:name>lib32ncurses6</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789398674003" version="1">
      <red-def:name>lib32ncursesw6</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789398674004" version="1">
      <red-def:name>lib32tinfo6</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789398674005" version="1">
      <red-def:name>libncurses-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789398674006" version="1">
      <red-def:name>libncurses5</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789398674007" version="1">
      <red-def:name>libncurses5-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789398674008" version="1">
      <red-def:name>libncurses6</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789398674009" version="1">
      <red-def:name>libncursesw5</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789398674010" version="1">
      <red-def:name>libncursesw5-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789398674011" version="1">
      <red-def:name>libncursesw6</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789398674012" version="1">
      <red-def:name>libtinfo-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789398674013" version="1">
      <red-def:name>libtinfo5</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789398674014" version="1">
      <red-def:name>libtinfo6</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789398674015" version="1">
      <red-def:name>ncurses-base</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789398674016" version="1">
      <red-def:name>ncurses-bin</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789398674017" version="1">
      <red-def:name>ncurses-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789398674018" version="1">
      <red-def:name>ncurses-examples</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789398674019" version="1">
      <red-def:name>ncurses-term</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789461431001" version="1">
      <red-def:name>libtomcat9-embed-java</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789461431002" version="1">
      <red-def:name>libtomcat9-java</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789461431003" version="1">
      <red-def:name>tomcat9</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789461431004" version="1">
      <red-def:name>tomcat9-admin</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789461431005" version="1">
      <red-def:name>tomcat9-common</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789461431006" version="1">
      <red-def:name>tomcat9-docs</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789461431007" version="1">
      <red-def:name>tomcat9-examples</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789461431008" version="1">
      <red-def:name>tomcat9-user</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789479755001" version="1">
      <red-def:name>colord</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789479755002" version="1">
      <red-def:name>colord-data</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789479755003" version="1">
      <red-def:name>colord-tests</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789479755004" version="1">
      <red-def:name>gir1.2-colord-1.0</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789479755005" version="1">
      <red-def:name>gir1.2-colorhug-1.0</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789479755006" version="1">
      <red-def:name>libcolord-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789479755007" version="1">
      <red-def:name>libcolord2</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789479755008" version="1">
      <red-def:name>libcolorhug-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789479755009" version="1">
      <red-def:name>libcolorhug2</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789483920001" version="1">
      <red-def:name>libarchive-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789483920002" version="1">
      <red-def:name>libarchive-tools</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789483920003" version="1">
      <red-def:name>libarchive13</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486509001" version="1">
      <red-def:name>graphviz</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486509002" version="1">
      <red-def:name>graphviz-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486509003" version="1">
      <red-def:name>libcdt5</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486509004" version="1">
      <red-def:name>libcgraph6</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486509005" version="1">
      <red-def:name>libgraphviz-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486509006" version="1">
      <red-def:name>libgv-guile</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486509007" version="1">
      <red-def:name>libgv-lua</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486509008" version="1">
      <red-def:name>libgv-perl</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486509009" version="1">
      <red-def:name>libgv-php7</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486509010" version="1">
      <red-def:name>libgv-ruby</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486509011" version="1">
      <red-def:name>libgv-tcl</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486509012" version="1">
      <red-def:name>libgvc6</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486509013" version="1">
      <red-def:name>libgvc6-plugins-gtk</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486509014" version="1">
      <red-def:name>libgvpr2</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486509015" version="1">
      <red-def:name>liblab-gamut1</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486509016" version="1">
      <red-def:name>libpathplan4</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486509017" version="1">
      <red-def:name>libxdot4</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486509018" version="1">
      <red-def:name>python3-gv</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486843001" version="1">
      <red-def:name>gir1.2-poppler-0.18</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486843002" version="1">
      <red-def:name>libpoppler-cpp-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486843003" version="1">
      <red-def:name>libpoppler-cpp0v5</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486843004" version="1">
      <red-def:name>libpoppler-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486843005" version="1">
      <red-def:name>libpoppler-glib-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486843006" version="1">
      <red-def:name>libpoppler-glib-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486843007" version="1">
      <red-def:name>libpoppler-glib8</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486843008" version="1">
      <red-def:name>libpoppler-private-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486843009" version="1">
      <red-def:name>libpoppler-qt5-1</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486843010" version="1">
      <red-def:name>libpoppler-qt5-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486843011" version="1">
      <red-def:name>libpoppler102</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789486843012" version="1">
      <red-def:name>poppler-utils</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789552364001" version="1">
      <red-def:name>libperl-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789552364002" version="1">
      <red-def:name>libperl5.32</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789552364003" version="1">
      <red-def:name>perl</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789552364004" version="1">
      <red-def:name>perl-base</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789552364005" version="1">
      <red-def:name>perl-debug</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789552364006" version="1">
      <red-def:name>perl-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789552364007" version="1">
      <red-def:name>perl-modules-5.32</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789566857001" version="1">
      <red-def:name>xdg-utils</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789567019001" version="1">
      <red-def:name>libnghttp2-14</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789567019002" version="1">
      <red-def:name>libnghttp2-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789567019003" version="1">
      <red-def:name>libnghttp2-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789567019004" version="1">
      <red-def:name>nghttp2</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789567019005" version="1">
      <red-def:name>nghttp2-client</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789567019006" version="1">
      <red-def:name>nghttp2-proxy</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789567019007" version="1">
      <red-def:name>nghttp2-server</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789573030001" version="1">
      <red-def:name>gir1.2-harfbuzz-0.0</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789573030002" version="1">
      <red-def:name>libharfbuzz-bin</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789573030003" version="1">
      <red-def:name>libharfbuzz-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789573030004" version="1">
      <red-def:name>libharfbuzz-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789573030005" version="1">
      <red-def:name>libharfbuzz-gobject0</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789573030006" version="1">
      <red-def:name>libharfbuzz-icu0</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789573030007" version="1">
      <red-def:name>libharfbuzz0b</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789574775001" version="1">
      <red-def:name>dmidecode</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789577104001" version="1">
      <red-def:name>postfix</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789577104002" version="1">
      <red-def:name>postfix-cdb</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789577104003" version="1">
      <red-def:name>postfix-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789577104004" version="1">
      <red-def:name>postfix-ldap</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789577104005" version="1">
      <red-def:name>postfix-lmdb</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789577104006" version="1">
      <red-def:name>postfix-mysql</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789577104007" version="1">
      <red-def:name>postfix-pcre</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789577104008" version="1">
      <red-def:name>postfix-pgsql</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789577104009" version="1">
      <red-def:name>postfix-sqlite</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789581984001" version="1">
      <red-def:name>libpcre16-3</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789581984002" version="1">
      <red-def:name>libpcre3</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789581984003" version="1">
      <red-def:name>libpcre3-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789581984004" version="1">
      <red-def:name>libpcre32-3</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789581984005" version="1">
      <red-def:name>libpcrecpp0v5</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789581984006" version="1">
      <red-def:name>pcregrep</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789582390001" version="1">
      <red-def:name>lemon</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789582390002" version="1">
      <red-def:name>libsqlite3-0</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789582390003" version="1">
      <red-def:name>libsqlite3-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789582390004" version="1">
      <red-def:name>libsqlite3-tcl</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789582390005" version="1">
      <red-def:name>sqlite3</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789582390006" version="1">
      <red-def:name>sqlite3-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789635862001" version="1">
      <red-def:name>rsync</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789641466001" version="1">
      <red-def:name>libssl-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789641466002" version="1">
      <red-def:name>libssl-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789641466003" version="1">
      <red-def:name>libssl1.1</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789641466004" version="1">
      <red-def:name>openssl</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789643272001" version="1">
      <red-def:name>rsyslog</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789643272002" version="1">
      <red-def:name>rsyslog-czmq</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789643272003" version="1">
      <red-def:name>rsyslog-elasticsearch</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789643272004" version="1">
      <red-def:name>rsyslog-gnutls</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789643272005" version="1">
      <red-def:name>rsyslog-gssapi</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789643272006" version="1">
      <red-def:name>rsyslog-hiredis</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789643272007" version="1">
      <red-def:name>rsyslog-kafka</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789643272008" version="1">
      <red-def:name>rsyslog-mongodb</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789643272009" version="1">
      <red-def:name>rsyslog-mysql</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789643272010" version="1">
      <red-def:name>rsyslog-openssl</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789643272011" version="1">
      <red-def:name>rsyslog-pgsql</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789643272012" version="1">
      <red-def:name>rsyslog-relp</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789661255001" version="1">
      <red-def:name>libnetcdf-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789661255002" version="1">
      <red-def:name>libnetcdf18</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789661255003" version="1">
      <red-def:name>netcdf-bin</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789661255004" version="1">
      <red-def:name>netcdf-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789666971001" version="1">
      <red-def:name>libpcre2-16-0</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789666971002" version="1">
      <red-def:name>libpcre2-32-0</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789666971003" version="1">
      <red-def:name>libpcre2-8-0</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789666971004" version="1">
      <red-def:name>libpcre2-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789666971005" version="1">
      <red-def:name>libpcre2-posix2</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789666971006" version="1">
      <red-def:name>pcre2-utils</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789671837001" version="1">
      <red-def:name>pypy-pyasn1</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789671837002" version="1">
      <red-def:name>python-pyasn1-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789671837003" version="1">
      <red-def:name>python3-pyasn1</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789719259001" version="1">
      <red-def:name>idle-python2.7</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789719259002" version="1">
      <red-def:name>libpython2.7</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789719259003" version="1">
      <red-def:name>libpython2.7-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789719259004" version="1">
      <red-def:name>libpython2.7-minimal</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789719259005" version="1">
      <red-def:name>libpython2.7-stdlib</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789719259006" version="1">
      <red-def:name>libpython2.7-testsuite</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789719259007" version="1">
      <red-def:name>python2.7</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789719259008" version="1">
      <red-def:name>python2.7-dev</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789719259009" version="1">
      <red-def:name>python2.7-doc</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789719259010" version="1">
      <red-def:name>python2.7-examples</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789719259011" version="1">
      <red-def:name>python2.7-minimal</red-def:name>
    </red-def:dpkginfo_object>
    <red-def:dpkginfo_object id="oval:com.tuxcare.clsa:obj:1789748107001" version="1">
      <red-def:name>kbd</red-def:name>
    </red-def:dpkginfo_object>
  </objects>
  <states>
    <unix-def:uname_state id="oval:com.tuxcare.clsa:ste:1787918353002" version="1">
      <unix-def:os_release operation="pattern match">(^5\.10\.0\-(?:\d{3,}|[5-9]\d|4[7-9])(?:\-tuxcare\.els\d+)?\-\w*$)</unix-def:os_release>
    </unix-def:uname_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1787918353003" version="1">
      <red-def:arch datatype="string" operation="equals">amd64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:5.10.262-1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1787918353010" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:5.10.262-1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788696775001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788696775003" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788699858001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:1.18.0-6.1+deb11u8+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788699858023" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:1.18.0-6.1+deb11u8+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788773292001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.2.9-2+deb11u7+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788773292002" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:2.2.9-2+deb11u7+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788774752001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:2.31-13+deb11u14+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788774752003" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.31-13+deb11u14+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788774752009" version="1">
      <red-def:arch datatype="string" operation="equals">amd64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.31-13+deb11u14+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788774936001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.5.1-3+deb11u4+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788786309001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:1.18.3-6+deb11u8+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788786309002" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:1.18.3-6+deb11u8+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788786535001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:1.9.5p2-3+deb11u4+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <unix-def:uname_state id="oval:com.tuxcare.clsa:ste:1788803338001" version="1">
      <unix-def:os_release operation="pattern match">(^5\.10\.0\-(?:\d{3,}|[5-9]\d|4[8-9])(?:\-tuxcare\.els\d+)?\-\w*$)</unix-def:os_release>
    </unix-def:uname_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788803338002" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:5.10.269-1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788803338003" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:5.10.269-1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788803338006" version="1">
      <red-def:arch datatype="string" operation="equals">armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:5.10.269-1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788803338007" version="1">
      <red-def:arch datatype="string" operation="equals">amd64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:5.10.269-1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788803338010" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:5.10.269-1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788803338013" version="1">
      <red-def:arch datatype="string" operation="equals">arm64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:5.10.269-1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788819939001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.66.8-1+deb11u8+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788819939003" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:2.66.8-1+deb11u8+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788884663001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:4.13-10+deb11u7+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788884663003" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:4.13-10+deb11u7+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788856712001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.2.9-2+deb11u7+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788856712002" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:2.2.9-2+deb11u7+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788943086001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:1.9.0-2+deb11u1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788966943001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">2:4.13.13+dfsg-1~deb11u8+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788966943011" version="1">
      <red-def:evr datatype="evr_string" operation="less than">2:4.13.13+dfsg-1~deb11u8+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788967622001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.3.3op2-3+deb11u10+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788967622004" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:2.3.3op2-3+deb11u10+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1788968222001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.2.10-2+deb11u7+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789049274001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">5:6.0.16-1+deb11u9+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789049274002" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">5:6.0.16-1+deb11u9+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789116242001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.6-7+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789142195001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:4.94.2-7+deb11u6+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789142195002" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:4.94.2-7+deb11u6+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789202428001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">1:1.30.1-6+deb11u1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789202428003" version="1">
      <red-def:evr datatype="evr_string" operation="less than">1:1.30.1-6+deb11u1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789205560001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:1.10-4+deb11u1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789205560002" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:1.10-4+deb11u1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789205759001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:1.9.0-2+deb11u1+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789206875001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">2:8.2.2434-3+deb11u3+tuxcare.els3</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789206875003" version="1">
      <red-def:evr datatype="evr_string" operation="less than">2:8.2.2434-3+deb11u3+tuxcare.els3</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789289969001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:7.74.0-1.3+deb11u16+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789289969005" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:7.74.0-1.3+deb11u16+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789290988001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">1:2.30.2-1+deb11u5+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789290988002" version="1">
      <red-def:evr datatype="evr_string" operation="less than">1:2.30.2-1+deb11u5+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789291176001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.66.8-1+deb11u8+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789291176003" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:2.66.8-1+deb11u8+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789291359001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:1.4.3+dfsg-1~deb11u1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789291359002" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:1.4.3+dfsg-1~deb11u1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789374596001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">1:8.4p1-5+deb11u7+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789374596005" version="1">
      <red-def:evr datatype="evr_string" operation="less than">1:8.4p1-5+deb11u7+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789375226001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:4.13-10+deb11u7+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789375226003" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:4.13-10+deb11u7+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789375441001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">2:4.13.13+dfsg-1~deb11u8+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789375441011" version="1">
      <red-def:evr datatype="evr_string" operation="less than">2:4.13.13+dfsg-1~deb11u8+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789375664001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:5.1-2+deb11u1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789375664003" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:5.1-2+deb11u1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789375817001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.0-12+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789042546001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:1.13.1-1+deb11u7+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789388743001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">5:6.0.16-1+deb11u9+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789388743002" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">5:6.0.16-1+deb11u9+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789390312001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">1:5.1.0-1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789391878001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:2.0.9-2+deb11u4+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789392206001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:1.21-1+deb11u2+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789394882001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.2.10-2+deb11u7+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789398674001" version="1">
      <red-def:arch datatype="string" operation="equals">amd64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:6.2+20201114-2+deb11u2+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789398674005" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:6.2+20201114-2+deb11u2+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789398674015" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:6.2+20201114-2+deb11u2+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789461431001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:9.0.118-0+deb11u1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789463064001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">2:8.2.2434-3+deb11u3+tuxcare.els4</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789463064003" version="1">
      <red-def:evr datatype="evr_string" operation="less than">2:8.2.2434-3+deb11u3+tuxcare.els4</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789479755001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:1.4.5-3+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789479755002" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:1.4.5-3+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789483920001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.4.3-2+deb11u5+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789486509001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.42.2-5+deb11u1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789486509002" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:2.42.2-5+deb11u1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789486843001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:20.09.0-3.1+deb11u3+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789486843006" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:20.09.0-3.1+deb11u3+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789552364001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:5.32.1-4+deb11u5+tuxcare.els4</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789552364006" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:5.32.1-4+deb11u5+tuxcare.els4</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789566857001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:1.1.3-4.1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789567019001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:1.43.0-1+deb11u3+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789567019003" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:1.43.0-1+deb11u3+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789571397001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789571397003" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:2.9.10+dfsg-6.7+deb11u10+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789573030001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.4-1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789573030004" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.4-1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789574775001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.3-2+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789577104001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.5.25-0+deb11u1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789577104003" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:3.5.25-0+deb11u1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789577411001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">2:4.13.13+dfsg-1~deb11u8+tuxcare.els3</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789577411011" version="1">
      <red-def:evr datatype="evr_string" operation="less than">2:4.13.13+dfsg-1~deb11u8+tuxcare.els3</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789581984001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">2:8.39-13+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789582390001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.34.1-3+deb11u1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789582390006" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:3.34.1-3+deb11u1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789635862001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.2.3-4+deb11u4+tuxcare.els3</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789639853001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.5.1-3+deb11u4+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789639975001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">2:8.2.2434-3+deb11u3+tuxcare.els11</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789639975003" version="1">
      <red-def:evr datatype="evr_string" operation="less than">2:8.2.2434-3+deb11u3+tuxcare.els11</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789641466001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:1.1.1w-0+deb11u8+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789641466002" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:1.1.1w-0+deb11u8+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789643272001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:8.2102.0-2+deb11u1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789661255001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">1:4.7.4-1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789661255004" version="1">
      <red-def:evr datatype="evr_string" operation="less than">1:4.7.4-1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789666971001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:10.36-2+deb11u1+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789671837001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:0.4.8-1+deb11u2+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789718965001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:5.32.1-4+deb11u5+tuxcare.els5</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789718965006" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:5.32.1-4+deb11u5+tuxcare.els5</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789719259001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-8+deb11u1+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789719259002" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-8+deb11u1+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789730024001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-8+deb11u1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789730024002" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-8+deb11u1+tuxcare.els1</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789728065001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.2.3-4+deb11u4+tuxcare.els4</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789745566001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:10.36-2+deb11u1+tuxcare.els3</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789748107001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.3.0-3+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789748401001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">1:4.7.4-1+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789748401004" version="1">
      <red-def:evr datatype="evr_string" operation="less than">1:4.7.4-1+tuxcare.els2</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789780826001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.66.8-1+deb11u8+tuxcare.els3</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789780826003" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:2.66.8-1+deb11u8+tuxcare.els3</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789785440001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:10.36-2+deb11u1+tuxcare.els4</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789899030001" version="1">
      <red-def:arch datatype="string" operation="pattern match">amd64|arm64|armel</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">2:4.13.13+dfsg-1~deb11u8+tuxcare.els4</red-def:evr>
    </red-def:dpkginfo_state>
    <red-def:dpkginfo_state id="oval:com.tuxcare.clsa:ste:1789899030011" version="1">
      <red-def:evr datatype="evr_string" operation="less than">2:4.13.13+dfsg-1~deb11u8+tuxcare.els4</red-def:evr>
    </red-def:dpkginfo_state>
  </states>
</oval_definitions>
