-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 08 May 2026 14:19:08 +0200 Source: libpng1.6 Binary: libpng-dev libpng-tools libpng-tools-dbgsym libpng16-16-udeb libpng16-16t64 libpng16-16t64-dbgsym Architecture: amd64 Version: 1.6.48-1+deb13u5 Distribution: trixie-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Tobias Frost Description: libpng-dev - PNG library - development (version 1.6) libpng-tools - PNG library - tools (version 1.6) libpng16-16-udeb - PNG library - minimal runtime library (version 1.6) (udeb) libpng16-16t64 - PNG library - runtime (version 1.6) Closes: 1133051 Changes: libpng1.6 (1.6.48-1+deb13u5) trixie-security; urgency=high . * Security upload targeting trixie. * CVE-2026-34757 - Use after free. (Closes: #1133051) * Cherry-pick upstream regression fix for previously fixed CVE 2026-33416. Checksums-Sha1: 5db64ea60be3c1b7957a68449c25c11a8da668be 367368 libpng-dev_1.6.48-1+deb13u5_amd64.deb 97ba0476c86e4e71624c0530ecba1ebc2e26231e 51532 libpng-tools-dbgsym_1.6.48-1+deb13u5_amd64.deb e9fe6a43a25d3c1bfe711c4fcef7d6f247b87179 130284 libpng-tools_1.6.48-1+deb13u5_amd64.deb aa8ab2ad27f16a10225ca4aac65d40c67ea4a5d0 8160 libpng1.6_1.6.48-1+deb13u5_amd64-buildd.buildinfo 0a5cbc6a26d957d1fb64ea4339dea6425f9014ee 95504 libpng16-16-udeb_1.6.48-1+deb13u5_amd64.udeb 22fa986b51889257b9717af2291a29694407a43d 262216 libpng16-16t64-dbgsym_1.6.48-1+deb13u5_amd64.deb 565c5c9c0d5279036bff64da652ac5f3e0f38885 283204 libpng16-16t64_1.6.48-1+deb13u5_amd64.deb Checksums-Sha256: 9027d5ace59ce266124c87054302805f49f9cb1ec4a6c8264a64596c7916fbff 367368 libpng-dev_1.6.48-1+deb13u5_amd64.deb 3ef844d9a0ab31e90bbb137920fcd1a58e42e10e5aa9afc6912bbfe92c131a0b 51532 libpng-tools-dbgsym_1.6.48-1+deb13u5_amd64.deb 793104609725c06b05bf3c8655a02d78da57f3ec92a36af3cd8d764647bc9868 130284 libpng-tools_1.6.48-1+deb13u5_amd64.deb 59ba66679703fc0909a8a4b52689bc06984bc789a290c724f35a57b36ec1596c 8160 libpng1.6_1.6.48-1+deb13u5_amd64-buildd.buildinfo c149203468086bc1a8a720d7b37434b10fa79187b33372ab5f768d5922bd5001 95504 libpng16-16-udeb_1.6.48-1+deb13u5_amd64.udeb cff8c9847c1c1183c50a1cabee17d7cfacce4948ec3a8e116f4217ff5ee87aca 262216 libpng16-16t64-dbgsym_1.6.48-1+deb13u5_amd64.deb 2465b4e9fa85cff54dc10a6da3e64074d8d9292c86e4a8f989b809d6b158e97e 283204 libpng16-16t64_1.6.48-1+deb13u5_amd64.deb Files: 5b92a1c9a5c98c398c219a94ff8ff26d 367368 libdevel optional libpng-dev_1.6.48-1+deb13u5_amd64.deb ebc231618bc204676b8da5bbb818dc75 51532 debug optional libpng-tools-dbgsym_1.6.48-1+deb13u5_amd64.deb 66e3c13f915496e9e60c075415c4094d 130284 libdevel optional libpng-tools_1.6.48-1+deb13u5_amd64.deb 6cf072fb49a354129c7f9d3af9e39fac 8160 libs optional libpng1.6_1.6.48-1+deb13u5_amd64-buildd.buildinfo 8a26828ca584a9745b5156beceb58c29 95504 debian-installer optional libpng16-16-udeb_1.6.48-1+deb13u5_amd64.udeb 98a07dbe829f1c9c72a90fa49e7b5568 262216 debug optional libpng16-16t64-dbgsym_1.6.48-1+deb13u5_amd64.deb 0cd2789cb2b8855e0a0798c0c5ffb213 283204 libs optional libpng16-16t64_1.6.48-1+deb13u5_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmtr4KUMaso2EQ6NrTwt/65ON6zcFAmn+D/gACgkQTwt/65ON 6ze1fA/+IDvXPypakwxHvzsF0fmPyRxhvGqyuDMdaQZolTxTtSq4jH18S18ftKq+ 1t2gb7gicLbGUuE38+qibdEN3z9rc0eVmH+kRcf7Poa7gz4BFWws+SfV6qHGnktf QRU3r/klhlOsULpbEyD2EBCM2IVjhAC05i2nOSCqKbmCsBskWgHu1RxZUj19g62Y tQDgd3yIa86lcVEBD5MHJkcTHRvA1ApE49EYMjq7RWDc29ystm1OSCPsmlHfv/Vv 0Jt9BVfJ8K3RpptxZ/3cV01xpHkKOU5vDqTjrKFvwKjutzjAVUnHe4Oz2Hr3igxf A+dDGXaRnKYgL75H9agJSyzuifO5b6ItAPnCI3hQkchcf6Ta/c7krxJFk1rfUboM 6SaU5vTwHlyoFYX58Op1S66VZFvpn56BRySZ0aJtEIuRuxvc+GW+qZClTcGRA0ay LEVYJcpL5cEoIbeo2Zwxqlv7XedKJmZURMzgy0kMNIGCHuBuJPrzn7yY0kia0TjT OC5L2fEPqfxp2u5OfI+V3Xte5esVXtVJeepQJaKdFVxOa0MMGWLVwh6FWT9JWZpZ t6ceTzBkTpn1xfmNPxpTiK/B9DvYsHKvLjlEWj4qhz9IwKxVCkpJulrzIaqliwVJ HtLGBqPeXYthat1T4+UmlXB+Fi+YZxPrzCl7s5dvzZqG75F5xxo= =hOva -----END PGP SIGNATURE-----