-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 06 Dec 2025 11:15:39 +0100 Source: libpng1.6 Binary: libpng-dev libpng-tools libpng-tools-dbgsym libpng16-16 libpng16-16-dbgsym libpng16-16-udeb Architecture: armhf Version: 1.6.39-2+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-conova-04) Changed-By: Tobias Frost Description: libpng-dev - PNG library - development (version 1.6) libpng-tools - PNG library - tools (version 1.6) libpng16-16 - PNG library - runtime (version 1.6) libpng16-16-udeb - PNG library - minimal runtime library (version 1.6) (udeb) Closes: 1121216 1121217 1121218 1121219 1121877 Changes: libpng1.6 (1.6.39-2+deb12u1) bookworm-security; urgency=high . * Security upload targeting boowkorm. * Backport fixes for: - CVE-2025-64505 - Heap buffer over-read (Closes: #1121219) - CVE-2025-64506 - Heap buffer over-read (Closes: #1121218) - CVE-2025-64720 - Heap buffer overflow (Closes: #1121217) - CVE-2025-65018 - Heap buffer overflow (Closes: #1121216) - CVE-2025-66293 - Out-of-bounds read (Closes: #1121877) * Set gbp.conf for bookworm and enable salsa CI Checksums-Sha1: ca355018dd2652ec29e76601a205befadbb57d6b 343420 libpng-dev_1.6.39-2+deb12u1_armhf.deb b7105bfe428fb581f1acea6e102552f2a6757e01 48112 libpng-tools-dbgsym_1.6.39-2+deb12u1_armhf.deb 1266bbee6d5e47ccdb9baa9eb271868d182ba9e8 124592 libpng-tools_1.6.39-2+deb12u1_armhf.deb e24d71de1b32ce89036c6ab7d1a78fcd14f56d57 7375 libpng1.6_1.6.39-2+deb12u1_armhf-buildd.buildinfo c696b3486d31ff469655b7c46ebf09d7c566d773 246808 libpng16-16-dbgsym_1.6.39-2+deb12u1_armhf.deb 229c2cb2732375838f2330afe931d56ec1ec4379 76476 libpng16-16-udeb_1.6.39-2+deb12u1_armhf.udeb a8934916bd21862c1d2829cbde018c20ded0c70d 260024 libpng16-16_1.6.39-2+deb12u1_armhf.deb Checksums-Sha256: 17913d5f2066a2bc32c43bc6e498f330897c923a9f886c639b662b9caa7c43eb 343420 libpng-dev_1.6.39-2+deb12u1_armhf.deb 4a3bb467510f0a136c1573de2ab0e6ec32780c075f5e95c9ca540fe8e66ca95f 48112 libpng-tools-dbgsym_1.6.39-2+deb12u1_armhf.deb 99bfeb979f7d0f506840e0ba7b542fdffca7d091aaf20851acdd9ea670679279 124592 libpng-tools_1.6.39-2+deb12u1_armhf.deb 20c3ca14acf528e8aee2bbfc8970c1f7410b8eaabb37d5462892774f682c9317 7375 libpng1.6_1.6.39-2+deb12u1_armhf-buildd.buildinfo 01024f141ae875946ae3b82065b9307f062e2ec3f1492c930c1eb5dcbc5f1325 246808 libpng16-16-dbgsym_1.6.39-2+deb12u1_armhf.deb 1dd85618a5834c06b78ab927de0cafcd1fe38bfa9031e7ceeba0044cf9f1bf99 76476 libpng16-16-udeb_1.6.39-2+deb12u1_armhf.udeb 756c7b2ca239cd5f96e27b713f71b560a5b1f529c30da24d72e29f2744c0d65a 260024 libpng16-16_1.6.39-2+deb12u1_armhf.deb Files: 91c43b3af1859f5fc6e8ea5616c55f07 343420 libdevel optional libpng-dev_1.6.39-2+deb12u1_armhf.deb 852b145db65d39ef729c5875b2ab0fa4 48112 debug optional libpng-tools-dbgsym_1.6.39-2+deb12u1_armhf.deb c50a485012ea3473db61de9b3bd56f20 124592 libdevel optional libpng-tools_1.6.39-2+deb12u1_armhf.deb b6a98891f4bc0a1b8ff3573842e46ca4 7375 libs optional libpng1.6_1.6.39-2+deb12u1_armhf-buildd.buildinfo 899daca34d95b6e42448546bb98b9e81 246808 debug optional libpng16-16-dbgsym_1.6.39-2+deb12u1_armhf.deb caec9d854ec108d87e41d48be56c3f5c 76476 debian-installer optional libpng16-16-udeb_1.6.39-2+deb12u1_armhf.udeb e8f7c080a52cdebd37533cad00bd7719 260024 libs optional libpng16-16_1.6.39-2+deb12u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYxmcRLDHP0tCCM0oScpU3dYulLgFAmk0R6IACgkQScpU3dYu lLjwgw/+IP0yV3wtuehsm4T4pH860f+/z1k788IZgTfFhv4WTJyQmyLNUNaQ8z/8 DWBmJz008AIGZoHKYcYKBEUVmKFeq9RCTy/fzDz7YYOU3A6A7z/vVRTvpiPLghVj TfOLMf6EWlVHz3I3HJmadaE90chuqJJLTNT+G6fXmb7bzfg/KlBeg8kevFnIeak0 fmnN2R2wdhLmzKTjy+kAcG/DztVnBVeiirB48hCssDjpYiw2XC+Ke/Y7ouCX+uM/ 4X3trHtqq3GN3tr8ROlUcpJQj8AxBKu6c4Bvse14sQCZgV70Dbj4W8Qeyc6vbVHT D5DsOZS7iwO5PhYsQEenYa2crIryB2uhGp1L8mjGhXwlvd8kIF6zjgtwbTYtN+nE FHICQ8cYcroIPTTL2JGqjJr5sbrdLBQiMtifGpQ3x2KuHQwUzm7o+1qha6IKlzJn aaZ+bG1bhxepNAWUbSQpnHQHSldImaDhDJWZo+t5RKxECj8Fn7+ng6GJ/rUEugPz h198CpQSOejNSFcNpjsVuq3lgl4pgmDAfNyn6AwZD3NZzEh1LLKPDdSrn0wwpZaU Cr7IwBGIsxJIFw/qnONPm3mYmqOJqfbgin8uYfHNmSUYsedYRAasPmmG+6a9BN/H RLpFU+g85mmhp2vj6uaCzmWX2ZRXChp6t3DyAtbvrW5amLru1vc= =1gF6 -----END PGP SIGNATURE-----