golang-1.24 (1.24.4-1) unstable; urgency=medium . * Team upload * New upstream version 1.24.1 + CVE-2025-4673: net/http: sensitive headers not cleared on cross-origin redirect (Closes: #1107364) + CVE-2025-0913: os: inconsistent handling of O_CREATE|O_EXCL on Unix and Windows + CVE 2025-22874: crypto/x509: usage of ExtKeyUsageAny disables policy validation (Closes: #1107364) + CVE-2025-22873: os: Root permits access to parent directory (Closes: #1104816) * d/patches: Removed patch 0003 as it's already applied upstream now