-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 06 Dec 2025 11:15:39 +0100 Source: libpng1.6 Binary: libpng-dev libpng-tools libpng-tools-dbgsym libpng16-16 libpng16-16-dbgsym libpng16-16-udeb Architecture: arm64 Version: 1.6.39-2+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-conova-04) Changed-By: Tobias Frost Description: libpng-dev - PNG library - development (version 1.6) libpng-tools - PNG library - tools (version 1.6) libpng16-16 - PNG library - runtime (version 1.6) libpng16-16-udeb - PNG library - minimal runtime library (version 1.6) (udeb) Closes: 1121216 1121217 1121218 1121219 1121877 Changes: libpng1.6 (1.6.39-2+deb12u1) bookworm-security; urgency=high . * Security upload targeting boowkorm. * Backport fixes for: - CVE-2025-64505 - Heap buffer over-read (Closes: #1121219) - CVE-2025-64506 - Heap buffer over-read (Closes: #1121218) - CVE-2025-64720 - Heap buffer overflow (Closes: #1121217) - CVE-2025-65018 - Heap buffer overflow (Closes: #1121216) - CVE-2025-66293 - Out-of-bounds read (Closes: #1121877) * Set gbp.conf for bookworm and enable salsa CI Checksums-Sha1: e7142a9d022d9c4e2bf521f2c2e5eda1d440ec31 354956 libpng-dev_1.6.39-2+deb12u1_arm64.deb 70fa7d4dd2cb32b8253e09a71910c1aaf920d6f0 49420 libpng-tools-dbgsym_1.6.39-2+deb12u1_arm64.deb 8916ff120748e927e39d741860b5227c14181ceb 126312 libpng-tools_1.6.39-2+deb12u1_arm64.deb 7dcaadd635d5187f8ab53afff9b2df976ebe9176 7531 libpng1.6_1.6.39-2+deb12u1_arm64-buildd.buildinfo 7764b9134b769ac42500164db5247baa1dea71de 256376 libpng16-16-dbgsym_1.6.39-2+deb12u1_arm64.deb f2af19442c84a2df0a1ab2dfc67929478b9b47dc 87420 libpng16-16-udeb_1.6.39-2+deb12u1_arm64.udeb 4228fe8b5ec9814910465e306127cb5d2f7b9bd3 269800 libpng16-16_1.6.39-2+deb12u1_arm64.deb Checksums-Sha256: 4cebe07e83121783ed0ee89656c7032ef8d34363c279e73c51564b105da00585 354956 libpng-dev_1.6.39-2+deb12u1_arm64.deb c21e2a756f8868afa81ce7eac7ac5ce90d9afbfc0c45e6a1d82be93deee543dd 49420 libpng-tools-dbgsym_1.6.39-2+deb12u1_arm64.deb 695aa811657ec0fef5e31da240bcda05c4830fd938460abdebfba2900ebbc774 126312 libpng-tools_1.6.39-2+deb12u1_arm64.deb b90a549a0549aa61e739e44b6259c4499c2cf3eba63835925785f4583e51dfea 7531 libpng1.6_1.6.39-2+deb12u1_arm64-buildd.buildinfo 976f1faf9760b62a8b23c6e3b49a160ff7e34cf2504ef60b3934ee3485546baf 256376 libpng16-16-dbgsym_1.6.39-2+deb12u1_arm64.deb de3b7cfe9e65b40431515ad7e921f627cc15d27fa5abfd4478763a6ece62f0d0 87420 libpng16-16-udeb_1.6.39-2+deb12u1_arm64.udeb 7ec030b4f2911be67fdd05f44d6571d3fb48dbc7498675dd385aa70aeed0a252 269800 libpng16-16_1.6.39-2+deb12u1_arm64.deb Files: b294a08b7b1372b4d594c07ae1a0251b 354956 libdevel optional libpng-dev_1.6.39-2+deb12u1_arm64.deb a4ab3064507d070ffef2e63c36df5ea3 49420 debug optional libpng-tools-dbgsym_1.6.39-2+deb12u1_arm64.deb a6cc27770337f6a97a90c3a7f914adc9 126312 libdevel optional libpng-tools_1.6.39-2+deb12u1_arm64.deb 75f7e225267bf6e8fe269fda7a529f25 7531 libs optional libpng1.6_1.6.39-2+deb12u1_arm64-buildd.buildinfo da3912b9e80cec8ca2bdb53bfaf3637d 256376 debug optional libpng16-16-dbgsym_1.6.39-2+deb12u1_arm64.deb 7ee9d1612d637f11e1d24931f6b2725e 87420 debian-installer optional libpng16-16-udeb_1.6.39-2+deb12u1_arm64.udeb 7e81013437be44456a7f2d0706744d2b 269800 libs optional libpng16-16_1.6.39-2+deb12u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYxmcRLDHP0tCCM0oScpU3dYulLgFAmk0RssACgkQScpU3dYu lLg6Hw/8DW/RY5FhEliUxPKxQXVY+xz80idpoiBfG+rpa9QHst1G3FLDyyxRILnp xNu/OKnJ4OaIXJp9aJZwjrV2u0+5Hb/Pr7b2F/0lGZ4W1i5ck5HXo7cFzLsG0Wkh hjgDuu06vKqdMbLVCKqii5NVO0QtwTmF922jjEpMpFuFxIWXQ/MkzW9AlOqeO2Rw SJ1hXUsQpepM0La6v2tQLATE6Ci5lREHJSvngDhRu1f2n9oYqSzHubuilnv0HV0n tiiXw6H95chovWEO3Me/xvL1780VVHpCLV1VdAId9NFASiusdAh4v41m2BEhzex0 sAgzikY9nZXDaPLKeDIN7w2Jyazu0Zne+QDVGl7ZJZtWNOTWPZagqimaUi5mNwwH chIoKFfQSfiJgRUIsJSwZQcbdRP7V/C5kgcPnHbIS56i6sgag+fait3fMA58A/T7 ZOSxth2lb4GXfrkWwzjX8wzH6MFIhAXw8Dpj21CJhucej/XzqAqnZXk+Bxl5XfSp oK/4zYmpS+75x83dpVuruayVUSi/rUoNi0n0TAILqBSAM4R9JO66GxuKhQIPIM9l cH/WIVCwbai32mUDeHBwhacjZPMGI9hdmCndZJnyLgilYZdzPl+lYXUbfVU3MMeY OTSR26qiUmucM7ozyMzdfr8pshROGt1QAQ2+puGBkcMrjCFQPOY= =7WAO -----END PGP SIGNATURE-----