-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 08 May 2026 14:19:08 +0200 Source: libpng1.6 Binary: libpng-dev libpng-tools libpng-tools-dbgsym libpng16-16-udeb libpng16-16t64 libpng16-16t64-dbgsym Architecture: riscv64 Version: 1.6.48-1+deb13u5 Distribution: trixie-security Urgency: high Maintainer: riscv64 Build Daemon (rv-osuosl-02) Changed-By: Tobias Frost Description: libpng-dev - PNG library - development (version 1.6) libpng-tools - PNG library - tools (version 1.6) libpng16-16-udeb - PNG library - minimal runtime library (version 1.6) (udeb) libpng16-16t64 - PNG library - runtime (version 1.6) Closes: 1133051 Changes: libpng1.6 (1.6.48-1+deb13u5) trixie-security; urgency=high . * Security upload targeting trixie. * CVE-2026-34757 - Use after free. (Closes: #1133051) * Cherry-pick upstream regression fix for previously fixed CVE 2026-33416. Checksums-Sha1: 0e1f33f5801df4e01df7616660222f45376f32c7 517348 libpng-dev_1.6.48-1+deb13u5_riscv64.deb d8999ba9b23f81002bde433577ac43184e47f859 48376 libpng-tools-dbgsym_1.6.48-1+deb13u5_riscv64.deb d2f68126574d1b67f4706af21936e03e03a90620 130632 libpng-tools_1.6.48-1+deb13u5_riscv64.deb c3fefbbba5361dc556718f9ffec406f8a3a1593b 8128 libpng1.6_1.6.48-1+deb13u5_riscv64-buildd.buildinfo 27a867c6451b125ebc8fcaff0ee92c42309d3199 99216 libpng16-16-udeb_1.6.48-1+deb13u5_riscv64.udeb 0deead4c30eb3e395357631d23e8f024d46b4487 240480 libpng16-16t64-dbgsym_1.6.48-1+deb13u5_riscv64.deb 4964c5345395422e6cb44d8668cde6aa0c1a231c 286852 libpng16-16t64_1.6.48-1+deb13u5_riscv64.deb Checksums-Sha256: 02905e2c93cc4360d1a4be49fe05409cd0c1529467724513eff90e221fa8b7e3 517348 libpng-dev_1.6.48-1+deb13u5_riscv64.deb 846a976827f8ee10317b22fe5579c1154fbf73675994bdef1ae8fdf9d7738b8f 48376 libpng-tools-dbgsym_1.6.48-1+deb13u5_riscv64.deb c5a15521df08d4d1a953f20c05e30c00557f9d70311aa41210554b35818bc4df 130632 libpng-tools_1.6.48-1+deb13u5_riscv64.deb 1bb37821a193b85ba6bf354a50713c64b73735919cd3c525ecbb4a98ff6c36a6 8128 libpng1.6_1.6.48-1+deb13u5_riscv64-buildd.buildinfo fb6940c2e6d7cb65ecc75be079e842e6f5938fc30a2359ef258551342063a27b 99216 libpng16-16-udeb_1.6.48-1+deb13u5_riscv64.udeb 5d8bd0f0cf01678100065bc38c47c379fc003e6b4c321450827b332385ca076e 240480 libpng16-16t64-dbgsym_1.6.48-1+deb13u5_riscv64.deb cd8970f0b5cf015c4ed58b2fcb43ab5069d2e72a4c520d01cce308e178cc36cd 286852 libpng16-16t64_1.6.48-1+deb13u5_riscv64.deb Files: 4e611bbb7ea030bff275ce22242a1a24 517348 libdevel optional libpng-dev_1.6.48-1+deb13u5_riscv64.deb d6296a4f3c421926371e528b6f536346 48376 debug optional libpng-tools-dbgsym_1.6.48-1+deb13u5_riscv64.deb d55657519dd7d1dd4c3df67476e32674 130632 libdevel optional libpng-tools_1.6.48-1+deb13u5_riscv64.deb 05cbf34806bfb4356d3f5a75791861c5 8128 libs optional libpng1.6_1.6.48-1+deb13u5_riscv64-buildd.buildinfo 1bdb7129b2fcee293b3bd8c3dd006a68 99216 debian-installer optional libpng16-16-udeb_1.6.48-1+deb13u5_riscv64.udeb 29691087af924859f99dde0cff7b048f 240480 debug optional libpng16-16t64-dbgsym_1.6.48-1+deb13u5_riscv64.deb 8ce3802df8a1eeeaa5a9753b95c1f314 286852 libs optional libpng16-16t64_1.6.48-1+deb13u5_riscv64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE/AxPdLOtOshqz3vw/Fc5EAGpa+sFAmn+FHIACgkQ/Fc5EAGp a+u0Pg/+PoUFmCVlBm48+uSXoD9vhuoIidZIkJXXIxMtsGT+t5/cJzNSCmLnINyb Dfi0Sah+YFk4Eqc25ZYZI306uFG+GTaNnpZkmmvP1qKpcqq1ucrLyepRhxJzj6Z8 oDb0M9ZpKSh+jzv5wa1SQT2NltxP1YExujbDUjL5D2M+uf63x11Pa2FXG5wLIKs8 NpYiNbB7TgCb8ThubvmqKo90CTg5bChdT75kGNQphV6UAvvO+EoAcjKEK4/25UJx civOT3pxwrlCVJkcw6ZwLz9gtRBgReLqmgw35GifrK+YNVnQQdo1gPNa39U2TkmI dj94jQJw+vFI9cXiaP7CW23BJPqMb0U8EZL4MmqzOHdBqFItZ0a3qCTIpPV3NFnf ZbOGCUOlH41qs2GhVyNgX7sVsUm/5OCqzoKtEsxx1BGx4VsxnjGL3uUCn72kUqrB nfqhkbTgkWlcKYXt2fyzkQllRb595K6E9zzRQ0/S8p0sAUG1gjcz6XVBDtaavt6v lNfBzN1F7NvZFloFkT8E3HRejs3c+hW0CEGAfIMaS9lYx/jeSvXG4Cbyowr/1E0h nnfwKGj979vJ+a1h1rpldD/0W0ZQ5bv6p1DF3KtEZAzT3d2VpEiCygBzitx+tyO7 phShnjxy35Sf/7caez1hxwb3XHlYV4rnLEtKRdOSaGn+/q9xz+c= =43Vg -----END PGP SIGNATURE-----