-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 08 May 2026 14:30:14 +0200 Source: libpng1.6 Binary: libpng-dev libpng-tools libpng-tools-dbgsym libpng16-16 libpng16-16-dbgsym libpng16-16-udeb Architecture: armhf Version: 1.6.39-2+deb12u5 Distribution: bookworm-security Urgency: high Maintainer: armhf Build Daemon (arm-ubc-01) Changed-By: Tobias Frost Description: libpng-dev - PNG library - development (version 1.6) libpng-tools - PNG library - tools (version 1.6) libpng16-16 - PNG library - runtime (version 1.6) libpng16-16-udeb - PNG library - minimal runtime library (version 1.6) (udeb) Closes: 1133051 Changes: libpng1.6 (1.6.39-2+deb12u5) bookworm-security; urgency=high . * Security upload targeting bookworm. * CVE-2026-34757 - Use after free. (Closes: #1133051) * Cherry-pick upstream regression fix for previously fixed CVE 2026-33416. Checksums-Sha1: 927e7145163fbfe0373a1548c2f405127a5d0335 344028 libpng-dev_1.6.39-2+deb12u5_armhf.deb 20f7c440fd3b16b0d997360719e10c0efbcca1c9 48124 libpng-tools-dbgsym_1.6.39-2+deb12u5_armhf.deb 7c523fe9c2600b999db216941bbe762a945e83ac 124864 libpng-tools_1.6.39-2+deb12u5_armhf.deb ed8a42cc8a98134ae348ed8a05f085fa192927aa 7395 libpng1.6_1.6.39-2+deb12u5_armhf-buildd.buildinfo beb89b8eee0e59752262b08cd80ae9dd11d3f132 248416 libpng16-16-dbgsym_1.6.39-2+deb12u5_armhf.deb 4c4df011fd03e0323951b35717e2136c59bc5480 76828 libpng16-16-udeb_1.6.39-2+deb12u5_armhf.udeb 7312cf5ac923cc37aa9eb0612dba7ae1ad99cfae 260480 libpng16-16_1.6.39-2+deb12u5_armhf.deb Checksums-Sha256: b5d8b45681688c8763c6e03fee8f142eb336bb4f68d680a9c25a8a8197658a64 344028 libpng-dev_1.6.39-2+deb12u5_armhf.deb 4f68e8c873ef452b8d2442677d35ee587f54f8ba4f8fb2f72536bf33217ef3ac 48124 libpng-tools-dbgsym_1.6.39-2+deb12u5_armhf.deb 7c27b34b0d9a2632a2430cb8f94badc7b0e698e83478e22a5220c22346b1be0f 124864 libpng-tools_1.6.39-2+deb12u5_armhf.deb ee390fbc862f51e5c1f9ed18d56b340927b57d596e1d8db90fe00176322502e5 7395 libpng1.6_1.6.39-2+deb12u5_armhf-buildd.buildinfo 020d04d22de3f836ae0d90b6e586db36f53caa287b8c958bac08ff77fe928c1c 248416 libpng16-16-dbgsym_1.6.39-2+deb12u5_armhf.deb 0a48c6e192695b2e98ab75ac79bb1972ff4a0e95ac0556ffadbb9a2cfa56c631 76828 libpng16-16-udeb_1.6.39-2+deb12u5_armhf.udeb e2e799490846d595337f9fff15f2c9cda4d5574f234b9e1f8a5e0197462e93e4 260480 libpng16-16_1.6.39-2+deb12u5_armhf.deb Files: 20fc14907eca4561e4f2e61b78e37e22 344028 libdevel optional libpng-dev_1.6.39-2+deb12u5_armhf.deb 982db131675765200fa735f4f7a5bac8 48124 debug optional libpng-tools-dbgsym_1.6.39-2+deb12u5_armhf.deb 3b97af81e2a542b7c587951b62f01187 124864 libdevel optional libpng-tools_1.6.39-2+deb12u5_armhf.deb 69c951cb7b2fdbdbce1bb7456457a468 7395 libs optional libpng1.6_1.6.39-2+deb12u5_armhf-buildd.buildinfo 7362b2b79401d66b163a6f4f96f5cf58 248416 debug optional libpng16-16-dbgsym_1.6.39-2+deb12u5_armhf.deb b1396f876751398b0b53ad2261fb1aa2 76828 debian-installer optional libpng16-16-udeb_1.6.39-2+deb12u5_armhf.udeb 962d734cd0fdfedb10b8f75a64e006df 260480 libs optional libpng16-16_1.6.39-2+deb12u5_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE0Ha//LlsGOpbQ/H4xqCFmsOWgoYFAmn+DzQACgkQxqCFmsOW goavFBAAsDCxdBaR15iOIxumWrnU6qksAnQWaTAX/MT6XsLpeWElrUnL8kHnG5e9 biIFS4Hc+Zz1PpLkjulsThDlbjTdHMWuzuZj8TTZE6SqRMlH+fy5DklzZ2JDbCRy +7K+jVJ5+CNheHtHGUzo4HM6KRjAjyYVgeLgr/238GZ+xspgPIlxPEK6H5no7ouK ElyByG4rFphHhkEi7TCrA+gU8hrjDkxPF8Xts3DQOBGqRfr2e82rssGkfEQruIuZ 0OUlVOdbXMAajUq4LbrwkETWdJja3YyJX8HseQFDPFPYRcmIl04E2EcDbkg3pJQn 6eZhKsjH7BkZJ+tHs7I+QLpz1W/qjfcA/XDbk50tc3Oous5FxGiMPTMl32ibtXBG bIuSms12Vqcqj/E8tGKNPc1clIyFqsONnvqRlNHN2MqE92/J2YhRi/C0b/tsJsQ+ wNSgdgHns8spMTQXak/kg6R3XhLuScoBONcsdzMM6yLcuxMvqDvElFwt3ybZ6Fs1 vbgxC65LabLApE0pfttPhm3A2+ekrzz9ZsUooz/UN9lDV5kfYyxLGQaq/fk9riiI Qoxd0rARTCSuKRHdpAMrsELCcs+vFN4XGuMjibXNtngLLcJZGyu5NEBpSgT4OV9d gH4MFZvWRwksSrcXf2ReTMR+iO11r/MYhHrNx9LF0DrzK3qmVOM= =KHsX -----END PGP SIGNATURE-----