-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 01 Jan 2026 15:54:00 +0100 Source: gnupg2 Binary: dirmngr dirmngr-dbgsym gnupg-utils gnupg-utils-dbgsym gpg gpg-agent gpg-agent-dbgsym gpg-dbgsym gpg-wks-client gpg-wks-client-dbgsym gpg-wks-server gpg-wks-server-dbgsym gpgconf gpgconf-dbgsym gpgsm gpgsm-dbgsym gpgv gpgv-dbgsym gpgv-static gpgv-static-dbgsym gpgv-udeb scdaemon scdaemon-dbgsym Architecture: s390x Version: 2.2.40-1.1+deb12u2 Distribution: bookworm Urgency: high Maintainer: s390x Build Daemon (zandonai) Changed-By: Daniel Kahn Gillmor Description: dirmngr - GNU privacy guard - network certificate management service gnupg-utils - GNU privacy guard - utility programs gpg - GNU Privacy Guard -- minimalist public key operations gpg-agent - GNU privacy guard - cryptographic agent gpg-wks-client - GNU privacy guard - Web Key Service client gpg-wks-server - GNU privacy guard - Web Key Service server gpgconf - GNU privacy guard - core configuration utilities gpgsm - GNU privacy guard - S/MIME version gpgv - GNU privacy guard - signature verification tool gpgv-static - minimal signature verification tool (static build) gpgv-udeb - minimal signature verification tool (udeb) scdaemon - GNU privacy guard - smart card support Closes: 1124221 Changes: gnupg2 (2.2.40-1.1+deb12u2) bookworm; urgency=high . * Address four issues from https://gpg.fail, including: + Fix CVE-2025-68973 (Closes: #1124221) + Avoid potential downgrade to SHA1 in 3rd party key signatures. + Error out on unverified output for non-detached signatures. + Do not use a default when asking for another output filename. * d/control: Point Vcs-Git to the correct branch Checksums-Sha1: 127b7988f2197f714cf480ebf75ce247ecf37d66 959176 dirmngr-dbgsym_2.2.40-1.1+deb12u2_s390x.deb d3e6ab7bed8ac1f446d7a6e87edf2358caae7bfb 768596 dirmngr_2.2.40-1.1+deb12u2_s390x.deb 5d2ed2ae4e9e8b76c960287888afeecd893b6096 1606956 gnupg-utils-dbgsym_2.2.40-1.1+deb12u2_s390x.deb bc820fa724652c2411d4093c6e3c9d8e7d5adf88 872800 gnupg-utils_2.2.40-1.1+deb12u2_s390x.deb 13b6558af1759132ff58bdd1c649be511a244fed 16799 gnupg2_2.2.40-1.1+deb12u2_s390x-buildd.buildinfo 752288c73076e419339c1445f4542b22e2e33a04 942076 gpg-agent-dbgsym_2.2.40-1.1+deb12u2_s390x.deb 42e52f97d46e20965f53f28f50c6848d7ee96e7d 671872 gpg-agent_2.2.40-1.1+deb12u2_s390x.deb b377c89922dac7ac2c803414c790db060111e869 1265832 gpg-dbgsym_2.2.40-1.1+deb12u2_s390x.deb c17365f59a581d416f6b2edeea7e7f28a034a40a 301004 gpg-wks-client-dbgsym_2.2.40-1.1+deb12u2_s390x.deb 04427184b3a76f9ad149ba098c3ba2fd47518922 533404 gpg-wks-client_2.2.40-1.1+deb12u2_s390x.deb e6582bbf6e1f61bd692ce56442840d14a40d1f76 275436 gpg-wks-server-dbgsym_2.2.40-1.1+deb12u2_s390x.deb a3c93ec1332a5d388ea0d9fa3ce23c62fea2b707 524848 gpg-wks-server_2.2.40-1.1+deb12u2_s390x.deb 72b0a7e1ba10f23a7adb0d7b756b93892cbcbd52 899544 gpg_2.2.40-1.1+deb12u2_s390x.deb 3cff06cce70065f2e401c3e12d08e62e84a3e54d 371900 gpgconf-dbgsym_2.2.40-1.1+deb12u2_s390x.deb a5db55eda6f0356214a2e1fef7dfd441f47fc403 556276 gpgconf_2.2.40-1.1+deb12u2_s390x.deb 81a41ebdd4cbe223bf8c580215e1e6fa84aadaf0 639504 gpgsm-dbgsym_2.2.40-1.1+deb12u2_s390x.deb 983d5c886c1853157ceb2f2c90531da48663f78e 649656 gpgsm_2.2.40-1.1+deb12u2_s390x.deb 62920f1a8f4773b253a5aab1c4a225ee29ac752e 608104 gpgv-dbgsym_2.2.40-1.1+deb12u2_s390x.deb 63fe9bdfb94fe3654a95d0121b3c9ec80866058a 653376 gpgv-static-dbgsym_2.2.40-1.1+deb12u2_s390x.deb 5fc603f395c380c05708969f0797fbc0472036e4 1325628 gpgv-static_2.2.40-1.1+deb12u2_s390x.deb 92e612b1b54b31cb6801486bbcfa3fc534e1d12d 180580 gpgv-udeb_2.2.40-1.1+deb12u2_s390x.udeb ec4caafa46b6cec0b80dabe77ce5243b0e1885fb 629800 gpgv_2.2.40-1.1+deb12u2_s390x.deb 70350f971f4d737e207761a8e92986f8ef9d9ae2 559472 scdaemon-dbgsym_2.2.40-1.1+deb12u2_s390x.deb 5902f61af364d2782997915a5e4b55fbd1349009 627424 scdaemon_2.2.40-1.1+deb12u2_s390x.deb Checksums-Sha256: 3ef22bab7de44a113bab639725990f218c61616d074c248527f6e1f76cef7860 959176 dirmngr-dbgsym_2.2.40-1.1+deb12u2_s390x.deb dfcb9587f533db9f578cae7a8c7b67ae9f66adec2826dbf790757b3036470e51 768596 dirmngr_2.2.40-1.1+deb12u2_s390x.deb 48e503622e66e99f735f0a47391d4aa14724abb52ca94ad85f5241b21d4b4603 1606956 gnupg-utils-dbgsym_2.2.40-1.1+deb12u2_s390x.deb 4f57716ca6c5f282f19cdf3a930d8b57b06685977a3a40f576969d2574a1fca2 872800 gnupg-utils_2.2.40-1.1+deb12u2_s390x.deb 256b672196463207e70078089456d1b38d8d724ded55e81f8f47a260ff466729 16799 gnupg2_2.2.40-1.1+deb12u2_s390x-buildd.buildinfo ecc367848581dbb0b7e43123c74fe92291dbbde453b441b39c81fcd0b6458aca 942076 gpg-agent-dbgsym_2.2.40-1.1+deb12u2_s390x.deb decc71b0a5ff30494c8d971ceec63e9479ea4fa4487bb9fcf1b6f4d3efa0dece 671872 gpg-agent_2.2.40-1.1+deb12u2_s390x.deb 8715366765152f07f0e0e6a4f338fd03f3c87475e7195c4bbc8c3ffb1f2ef831 1265832 gpg-dbgsym_2.2.40-1.1+deb12u2_s390x.deb 3e085a0e3438a656a6a522571fb8ee9ebbb5d01f0fb60ad1a2dd8b9773506974 301004 gpg-wks-client-dbgsym_2.2.40-1.1+deb12u2_s390x.deb 25d4fcce13affd23b6a67ea6035b04896c1f756f72630ce15cc0dc947b24a33d 533404 gpg-wks-client_2.2.40-1.1+deb12u2_s390x.deb bb3f3ac54981cacd37dbeef3740d9ebc707341fc30ee842d88a58da660125efb 275436 gpg-wks-server-dbgsym_2.2.40-1.1+deb12u2_s390x.deb e37df949f610da6de0ef1ce96b6cb9c504cec1a37b74bedafdf46af2a4cf21fb 524848 gpg-wks-server_2.2.40-1.1+deb12u2_s390x.deb 8cf1a64b10ec841d3be6aa59cf44ce7ebc73d2cec8a1c87b694cc7ca4884a00e 899544 gpg_2.2.40-1.1+deb12u2_s390x.deb 65517e79a5425ad40ba64a2ccc8edadb7b392125675c4091daa0e32010a87ee2 371900 gpgconf-dbgsym_2.2.40-1.1+deb12u2_s390x.deb 6b2ee3679c263d02fc66b0a238e4f6954015f4503f0088232605e332b0af0835 556276 gpgconf_2.2.40-1.1+deb12u2_s390x.deb 1f53dbe8af4c6db61b76c7c7ce5735fb845f4c01f62fdcf5ba6ece18f21abcd4 639504 gpgsm-dbgsym_2.2.40-1.1+deb12u2_s390x.deb f49c694fa0b9bc701b537ebc1314c68498d9c5d6cadd5c392fcaa7b0f2696191 649656 gpgsm_2.2.40-1.1+deb12u2_s390x.deb bc08c823a1dbf8ff5a753d838eac54907dea532749dc5825d72176573ee25ebb 608104 gpgv-dbgsym_2.2.40-1.1+deb12u2_s390x.deb 62b8a893b116bcd4446f15b4c69f0a42f5e5aa1417b9badb130f4a91870bc2c7 653376 gpgv-static-dbgsym_2.2.40-1.1+deb12u2_s390x.deb 23d1e9da60fa78256963a104c0c122815f51d472c2a4cc0f362f0e52a8d6a40c 1325628 gpgv-static_2.2.40-1.1+deb12u2_s390x.deb 0a5fc4888cef2bfc8472463c0da04ae3d020acda2c45a323796aa2471477e120 180580 gpgv-udeb_2.2.40-1.1+deb12u2_s390x.udeb 30781ec650e5a511ccf74dd4e4f99aff27760aa8688a8dd6cad31019d2eafc3d 629800 gpgv_2.2.40-1.1+deb12u2_s390x.deb e605b409ebab05b849260aabbde80e87e6b5375c884dab152a7000e609362979 559472 scdaemon-dbgsym_2.2.40-1.1+deb12u2_s390x.deb ff85dda59cc7586d9603ae39804cda432777d4ab1a8a4854ee3c5a2f90bd5f29 627424 scdaemon_2.2.40-1.1+deb12u2_s390x.deb Files: abf5ac601c51a31c0b8a3e8f889609b8 959176 debug optional dirmngr-dbgsym_2.2.40-1.1+deb12u2_s390x.deb 20efc48e817a05fd5eb1baec0aa7fde4 768596 utils optional dirmngr_2.2.40-1.1+deb12u2_s390x.deb b58061b4b272511a89e607319340e928 1606956 debug optional gnupg-utils-dbgsym_2.2.40-1.1+deb12u2_s390x.deb f661bc876a63139bef48814f767b19ac 872800 utils optional gnupg-utils_2.2.40-1.1+deb12u2_s390x.deb 92bfdb3f925c53d8525c434a7fd3e2c2 16799 utils optional gnupg2_2.2.40-1.1+deb12u2_s390x-buildd.buildinfo e410489e0f3593febee6703aa904e723 942076 debug optional gpg-agent-dbgsym_2.2.40-1.1+deb12u2_s390x.deb 19e8e7b0bce90fce537588c8aa4f92c4 671872 utils optional gpg-agent_2.2.40-1.1+deb12u2_s390x.deb 4acef0bd02d50fccfebe257343ad6eb1 1265832 debug optional gpg-dbgsym_2.2.40-1.1+deb12u2_s390x.deb 176f98a32873611b4c0ac1f50ae7fbf6 301004 debug optional gpg-wks-client-dbgsym_2.2.40-1.1+deb12u2_s390x.deb 704ee4a82b2a80514d2e24b9c006b2d6 533404 utils optional gpg-wks-client_2.2.40-1.1+deb12u2_s390x.deb ec9f4f017d581b2e38509ac6ec90243b 275436 debug optional gpg-wks-server-dbgsym_2.2.40-1.1+deb12u2_s390x.deb 34279bce6e1d4b6a06b32b7bd8c75b90 524848 utils optional gpg-wks-server_2.2.40-1.1+deb12u2_s390x.deb 27cc37b6f66124a4230ac8be654d9bbe 899544 utils optional gpg_2.2.40-1.1+deb12u2_s390x.deb 0ba69a16d8bc1b124ab0aa7c96d27666 371900 debug optional gpgconf-dbgsym_2.2.40-1.1+deb12u2_s390x.deb a721288cb5776a0e6ac8f8da461673b6 556276 utils optional gpgconf_2.2.40-1.1+deb12u2_s390x.deb f0d0c53157447089fc9a343026426904 639504 debug optional gpgsm-dbgsym_2.2.40-1.1+deb12u2_s390x.deb 9ef3e0d3afea78f17c87327071e3886b 649656 utils optional gpgsm_2.2.40-1.1+deb12u2_s390x.deb e613eeee66c1e7d212a8f9a4c467dc82 608104 debug optional gpgv-dbgsym_2.2.40-1.1+deb12u2_s390x.deb d68b07350e46a2ab9f342b62e46c8839 653376 debug optional gpgv-static-dbgsym_2.2.40-1.1+deb12u2_s390x.deb d38d2f26792c93673446abcf1a0a7149 1325628 utils optional gpgv-static_2.2.40-1.1+deb12u2_s390x.deb d68ed445ea180ce71c1ec3620da24f95 180580 debian-installer optional gpgv-udeb_2.2.40-1.1+deb12u2_s390x.udeb f23eb60bbbc2340b2aeaeb65b75ed363 629800 utils important gpgv_2.2.40-1.1+deb12u2_s390x.deb 79037bc9497ec36c72dda2842c8a4205 559472 debug optional scdaemon-dbgsym_2.2.40-1.1+deb12u2_s390x.deb 9b5cd8d3179e2129088dcb6e8db82ebd 627424 utils optional scdaemon_2.2.40-1.1+deb12u2_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEENly2ANlpa4eeqnluvVOPI7pYNpgFAmlYYZMACgkQvVOPI7pY NphofBAAu6S9ZNJBm2XOiR2vriPSA7YzP7TbMUzymPvS4No498zlEjVPtoe9xsVQ HruVGbEvJS5qcK/pC33U/WURuNUIpPW0kyB2N9VSa9fJDJjmqyTL/0EiV/LCHoeJ RkgXF755iiD6YU3Zmo3eFccjgVb3+hIF8ykkF1jEOls72NmNPX6yD02iSQkHmgCa pwCgrfGAkYfBsfmrlffFyoMcB1Y0xWiRFg/prgSvyFCsUFaTpo0SR9rwq3VpsSYk vCuZQn2PE6QAZd3JQRA+/N06ydxVQAWziWwnE1l02tfLGebnir43P410x7cuTQdt 8hjS20a63/GiX3u6AVjvO4aiJREASpn0szARvKCxRjHbaJK+yxJmyLHtut8XA9MB 6m7DvPWNLY657TxpljxvkNbsKX7kfU2VZxFholK6zpFxdiUuxaEgd/sSujt396xP i682EKGtPxp/PktnoaFZtHP1wBWJMlwqqNuu6/xtqNNJCisJnQDryoR5Yr504Yoc zHqlA5aZWaWx+z8oBxSJZj0H8n46EWGhd8WFihyorMyeQouk5XCGEHU3n+hgADuy /yG2sjnOH2bLxjJ6+EhhHgCUhZiXY7XiexpPnIDM/9+XeQpuzDL+Qof9b4jZM4s0 gYjJRGmHpcgA1rFylteE2wPOp0yqCO+8NsEQzBgcbEwY7Yglq/8= =ovfz -----END PGP SIGNATURE-----