CVE-2023-32668 (https://tug.org/pipermail/tex-live/2023-May/049188.html): LuaTeX before 1.17.0 enables the socket library by default. There is also CVE-2023-32700, which is remote code execution fixed in luatex-1.17.0, though I'm not certain how that maps to our versioning.
commit 96fe8d6e52f342b6764536aca58ddd563df3e278 (HEAD -> master, origin/master, origin/HEAD) Author: Sam James <sam@gentoo.org> Date: Fri May 19 06:01:11 2023 +0100 app-text/texlive-core: patch CVE-2023-32700 This does not fix CVE-2023-32668 which changes behaviour so must be handled in a new version (>= 2023). Bug: https://bugs.gentoo.org/836779 Bug: https://bugs.gentoo.org/906712 Signed-off-by: Sam James <sam@gentoo.org>
CVE-2023-32668 will need us to bump to TL-2023.