freecad (0.20.2+dfsg1-4+deb11u1) bullseye-security; urgency=high

  As part of the fix for CVE-2026-34789, The legacy Python 'pickle'
  fallback mechanism has been completely removed from the file loading
  pipeline to eliminate an arbitrary code execution vulnerability, which
  means very old FreeCAD (.FCStd) files, created in version 0.12 or
  earlier that rely on pickled object properties will no longer load.
  
  As a workaround, trusted legacy files can be opened in an older,
  intermediate version of FreeCAD and re-saved to migrate their data
  structure:set to the modern format.

 -- Tobias Frost <tobi@debian.org>  Sat, 03 Oct 2026 11:01:09 +0200
