-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 01 Jan 2026 06:46:01 +0100 Source: gnupg2 Binary: dirmngr dirmngr-dbgsym gnupg-utils gnupg-utils-dbgsym gpg gpg-agent gpg-agent-dbgsym gpg-dbgsym gpg-wks-client gpg-wks-client-dbgsym gpg-wks-server gpg-wks-server-dbgsym gpgconf gpgconf-dbgsym gpgsm gpgsm-dbgsym gpgv gpgv-dbgsym gpgv-static gpgv-static-dbgsym gpgv-udeb scdaemon scdaemon-dbgsym tpm2daemon tpm2daemon-dbgsym Architecture: amd64 Version: 2.4.7-21+deb13u1 Distribution: trixie Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-csail-01) Changed-By: Andreas Metzler Description: dirmngr - GNU privacy guard - network certificate management service gnupg-utils - GNU privacy guard - utility programs gpg - GNU Privacy Guard -- minimalist public key operations gpg-agent - GNU privacy guard - cryptographic agent gpg-wks-client - GNU privacy guard - Web Key Service client gpg-wks-server - GNU privacy guard - Web Key Service server gpgconf - GNU privacy guard - core configuration utilities gpgsm - GNU privacy guard - S/MIME version gpgv - GNU privacy guard - signature verification tool gpgv-static - minimal signature verification tool (static build) gpgv-udeb - minimal signature verification tool (udeb) scdaemon - GNU privacy guard - smart card support tpm2daemon - GNU privacy guard - TPM2 support Closes: 1124221 Changes: gnupg2 (2.4.7-21+deb13u1) trixie; urgency=high . * Avoid potential downgrade to SHA1 in 3rd party key signatures. https://gpg.fail/sha1 #12 Patch from STABLE-BRANCH-2-4 * gpg: Error out on unverified output for non-detached signatures. https://gpg.fail/detached #1 Patch from STABLE-BRANCH-2-4 * gpg: Fix possible memory corruption in the armor parser (CVE-2025-68973) https://gpg.fail/memcpy #5 Patch from STABLE-BRANCH-2-4 (Closes: #1124221) * gpg: Do not use a default when asking for another output filename. https://gpg.fail/filename #2 Unfuzzed patch from GIT master Checksums-Sha1: 38a0b3ea7773e1ba83e5397de38da554db903aec 1037812 dirmngr-dbgsym_2.4.7-21+deb13u1_amd64.deb 96cbe8dc00b92f2e3a7d9d7e417a4344570b718a 383552 dirmngr_2.4.7-21+deb13u1_amd64.deb 49ea614b0356bc06a7390f048fc0502fba1707b8 770404 gnupg-utils-dbgsym_2.4.7-21+deb13u1_amd64.deb 01f5a2213d55c261354b74df1f441fee6cd3ffef 193884 gnupg-utils_2.4.7-21+deb13u1_amd64.deb 3b9de4b9fa96ce93f6c01f7d55367347e0653240 19620 gnupg2_2.4.7-21+deb13u1_amd64-buildd.buildinfo 493d5774b9695fe29bdf40bd0431604c84206b87 973384 gpg-agent-dbgsym_2.4.7-21+deb13u1_amd64.deb 4ea3d392fb01fb651e6ae7e2614e77ab0cdf537f 270604 gpg-agent_2.4.7-21+deb13u1_amd64.deb e78fd62389935836709be31b170e1fe09956f0cd 1773860 gpg-dbgsym_2.4.7-21+deb13u1_amd64.deb 237b144f63d5c7775198b9623e10329ce3a36f4d 293048 gpg-wks-client-dbgsym_2.4.7-21+deb13u1_amd64.deb 566777949e21496e48d2231d93b123f4c7022cf9 108316 gpg-wks-client_2.4.7-21+deb13u1_amd64.deb 8ad5980597960e6c69fd99cfee98d1655d0be6e7 259636 gpg-wks-server-dbgsym_2.4.7-21+deb13u1_amd64.deb 2b6f1046344fa4e6be79ec352bd855ee382a6522 95824 gpg-wks-server_2.4.7-21+deb13u1_amd64.deb 97e3febab6fa3b20a330b894fd93a2ec197e835e 635208 gpg_2.4.7-21+deb13u1_amd64.deb 72e63abc5bff00f9b06803bad44fa3607087ec94 343356 gpgconf-dbgsym_2.4.7-21+deb13u1_amd64.deb 5ca8873ea1ec89d5131c75051e5167f8d537a20a 129008 gpgconf_2.4.7-21+deb13u1_amd64.deb 080439d8ac70f0a39f6e186c9c21a805306aee7f 744520 gpgsm-dbgsym_2.4.7-21+deb13u1_amd64.deb e4b5418d165fb9d09b807cd38e96c0504020be7c 275088 gpgsm_2.4.7-21+deb13u1_amd64.deb 5135d04a92729d63a214afe5af0d0f3fd62a3115 676268 gpgv-dbgsym_2.4.7-21+deb13u1_amd64.deb 7abd852e58a40e871478a8f66e0d4741cad757be 735068 gpgv-static-dbgsym_2.4.7-21+deb13u1_amd64.deb 14b13cb28f74f8b2491b1e8b396fbb112c4a9c1e 1201828 gpgv-static_2.4.7-21+deb13u1_amd64.deb f22b9036b1e5929350d3b5680bd02464b5a708fe 221964 gpgv-udeb_2.4.7-21+deb13u1_amd64.udeb 8eb0b9c10d475a24268b33d7e75559c8dc3e410b 240752 gpgv_2.4.7-21+deb13u1_amd64.deb 4c9a0a8452d9bfff4f5bfd0b1d75e336804e327c 1100204 scdaemon-dbgsym_2.4.7-21+deb13u1_amd64.deb f993f1d1630bd7330879695c8cbaba32a66491d3 346908 scdaemon_2.4.7-21+deb13u1_amd64.deb bda4446e45d2842fa3c6f7d18c8458bdf6082add 196404 tpm2daemon-dbgsym_2.4.7-21+deb13u1_amd64.deb 729e597ce132d115ea8b439c9a2dbcdeec922800 70340 tpm2daemon_2.4.7-21+deb13u1_amd64.deb Checksums-Sha256: 4a4354d9d47e48357f3d8f7d2a9e962855d55481beb2db02c40f8f8c67db9a76 1037812 dirmngr-dbgsym_2.4.7-21+deb13u1_amd64.deb 9030d369930f09e29680b65810fd72fde5158db24e15ed646992f6d0f5f9a8d8 383552 dirmngr_2.4.7-21+deb13u1_amd64.deb 045a64b16a8e202f4ad4101007356f87131e8af75578103dbf8c05f0b1038d7d 770404 gnupg-utils-dbgsym_2.4.7-21+deb13u1_amd64.deb ff2edfbd46533d9e6676d17b01981e5825913c08511324cfcabdd668d98496e8 193884 gnupg-utils_2.4.7-21+deb13u1_amd64.deb 4ee4f763aaab70252d70a198181662940265a4187b1843004f4f40e36e51dffc 19620 gnupg2_2.4.7-21+deb13u1_amd64-buildd.buildinfo 986632a6908a34136010bfddff7d8baf4e586797cb22a1c60e20e8913d82e60b 973384 gpg-agent-dbgsym_2.4.7-21+deb13u1_amd64.deb 4a1543e42c47435ed4d6730718bfc932f66a76673b590627edeee0bfa10df422 270604 gpg-agent_2.4.7-21+deb13u1_amd64.deb 1f81dba4398113260df02111345a51aaad9111fe61960da795432470f7e04e47 1773860 gpg-dbgsym_2.4.7-21+deb13u1_amd64.deb 7fc08dbf5bdcc94cdc857476730d9b357c9c920b50e1bbac86c3ecf11e2a3e5f 293048 gpg-wks-client-dbgsym_2.4.7-21+deb13u1_amd64.deb f0f2968e059029b04b893f348c4d3cbd6ae0ff0131d7a098895a5157ef394d48 108316 gpg-wks-client_2.4.7-21+deb13u1_amd64.deb 13bdd179fb77b5559ac3baa4a4cde3b2bae094187aa34209fbbd925e4290b892 259636 gpg-wks-server-dbgsym_2.4.7-21+deb13u1_amd64.deb d271901c143608ac03ad6d33e8d38dbe9596b9922e06cf8c00006fe6650d0cf7 95824 gpg-wks-server_2.4.7-21+deb13u1_amd64.deb d776251bf5ecd135ab2d28bd8dbc17af2c3f95e4ad8ed199cdef45583e430e2f 635208 gpg_2.4.7-21+deb13u1_amd64.deb 641066d2d3832a406299925569a34effcfc512b0a9c7ea0796ed10853b6fc395 343356 gpgconf-dbgsym_2.4.7-21+deb13u1_amd64.deb 55736895d42cea740e0dfb3a0d59051109ed39ac55745aa146e6dde90b90f515 129008 gpgconf_2.4.7-21+deb13u1_amd64.deb 2f6df7b30ed56bf06b4681e87c68f0adf41a39f94735d5b6eeef21220b79cb7f 744520 gpgsm-dbgsym_2.4.7-21+deb13u1_amd64.deb 993cbfe682003a558b98b95844227ee224af854b0f0a64dce850157c4f4a705f 275088 gpgsm_2.4.7-21+deb13u1_amd64.deb 0089bff9a62dc2ee32425493655c0a86e67a26b275c34987ae31a3c13b370465 676268 gpgv-dbgsym_2.4.7-21+deb13u1_amd64.deb 196bdca2202880d28590be8a7798dd7bed9d9ce0ee6c0bfd166b8dabfbeafc3a 735068 gpgv-static-dbgsym_2.4.7-21+deb13u1_amd64.deb d02e872a3da2ef97de569d3b35d2fe404a7956e1482e12be8760051f31b4eee6 1201828 gpgv-static_2.4.7-21+deb13u1_amd64.deb fee17f231b03858655e69142274c18a25666bfe3ab0fda917fd583e0b689ea47 221964 gpgv-udeb_2.4.7-21+deb13u1_amd64.udeb 62abb23bfff2ec0ffa9ab59ce268773f39848ef4d2a9c7bd52f7e706f41c4a32 240752 gpgv_2.4.7-21+deb13u1_amd64.deb f1903ce349b00cc6193945591057ff8299eb6bc853e01831eb63ceade193be94 1100204 scdaemon-dbgsym_2.4.7-21+deb13u1_amd64.deb aff0d997d8d1d63a10f27813ee8a8677cb0b1427898b697fb72f5390ff22b81d 346908 scdaemon_2.4.7-21+deb13u1_amd64.deb 27c9a642af2834cece9d9ae4f233a44b30fd8f189c60c9de77b7e661534593c9 196404 tpm2daemon-dbgsym_2.4.7-21+deb13u1_amd64.deb 43cc11ab2d3679f2b1dcf3daef51aa2f7a719bacbc110cfe330c8603a0a58632 70340 tpm2daemon_2.4.7-21+deb13u1_amd64.deb Files: 93868f73bfbe2709206868ab298edadc 1037812 debug optional dirmngr-dbgsym_2.4.7-21+deb13u1_amd64.deb 7ccb2a2e5d11da6b5b49757eb0bb40d9 383552 utils optional dirmngr_2.4.7-21+deb13u1_amd64.deb 257f36499900922317016d9c39d5c4fa 770404 debug optional gnupg-utils-dbgsym_2.4.7-21+deb13u1_amd64.deb 1e2cefebe773318fb86deeec016f0b6b 193884 utils optional gnupg-utils_2.4.7-21+deb13u1_amd64.deb 8516c1d21c6c8d0b847b304f17895448 19620 utils optional gnupg2_2.4.7-21+deb13u1_amd64-buildd.buildinfo 4e890c08851b65a0c73711b96cacb48a 973384 debug optional gpg-agent-dbgsym_2.4.7-21+deb13u1_amd64.deb eda5a8bfb038713b746284d48ccbcb48 270604 utils optional gpg-agent_2.4.7-21+deb13u1_amd64.deb bef4a0f8cd71345959104d90e6383206 1773860 debug optional gpg-dbgsym_2.4.7-21+deb13u1_amd64.deb ba099069323ef0b6a1efb28f3de91dcb 293048 debug optional gpg-wks-client-dbgsym_2.4.7-21+deb13u1_amd64.deb ef520b6cb286e9094944ca0c6d27bb65 108316 utils optional gpg-wks-client_2.4.7-21+deb13u1_amd64.deb 19c5da70f5329952de94ba85b5aa5566 259636 debug optional gpg-wks-server-dbgsym_2.4.7-21+deb13u1_amd64.deb eb2be0d60f86bdca4768b69444c134e3 95824 utils optional gpg-wks-server_2.4.7-21+deb13u1_amd64.deb 6530ee7ffd712ad6c5e9e8f96326c1a1 635208 utils optional gpg_2.4.7-21+deb13u1_amd64.deb 1317f7e009de9a0ea71bbff113c96a94 343356 debug optional gpgconf-dbgsym_2.4.7-21+deb13u1_amd64.deb 2551a8eb6a2d84ac8307d731269f18ba 129008 utils optional gpgconf_2.4.7-21+deb13u1_amd64.deb 9533beaa990c5bdf484a74544ecda125 744520 debug optional gpgsm-dbgsym_2.4.7-21+deb13u1_amd64.deb ae54c47d78d28cb7db11b360e79fd0d7 275088 utils optional gpgsm_2.4.7-21+deb13u1_amd64.deb b9dbf387a9cd5debc9f0aabaf1bdc044 676268 debug optional gpgv-dbgsym_2.4.7-21+deb13u1_amd64.deb 2dcc64d4266bb7b4705f98a78f587612 735068 debug optional gpgv-static-dbgsym_2.4.7-21+deb13u1_amd64.deb 97212a67560f2d4ddab761f304723d79 1201828 utils optional gpgv-static_2.4.7-21+deb13u1_amd64.deb 61dbb1ae72b0428f2a3f99e57e3b624d 221964 debian-installer optional gpgv-udeb_2.4.7-21+deb13u1_amd64.udeb 31b88bd7e26bc528151e4614817f117b 240752 utils important gpgv_2.4.7-21+deb13u1_amd64.deb 7c05ab1a44a002b05c120d486c7cd01b 1100204 debug optional scdaemon-dbgsym_2.4.7-21+deb13u1_amd64.deb 990d3ba9a3bce0203ac245a0b30248db 346908 utils optional scdaemon_2.4.7-21+deb13u1_amd64.deb e48cc81680479190c9985b0111212f93 196404 debug optional tpm2daemon-dbgsym_2.4.7-21+deb13u1_amd64.deb f9b8fd41835f33f3338b702677d1a587 70340 utils optional tpm2daemon_2.4.7-21+deb13u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXNeYFUF3FbHcrtSeIy3Pg040HrAFAmlW88wACgkQIy3Pg040 HrDK8xAAjKI5SqT8ZoeN+IjbDgmHaYPkInEa4h/xHLuF0i5Na+xQg1N2d8MYturf qMphIXKC/f3Q0UlJf10foUNfe8n4NN06C2sFU21wQ/8d9x4B7ZKSVJ5sUvJkDNrW rts67OMRRUgBbZGwP3ZtzUEtv5FsL+jbbWdhIOTDiyBYnm5cG/wM8J/rOk3sZyHy ZLxE5610FeuecWae7xbVPbdZKIP+U2KLoBlk09e38I1jvxTYqIFFfyWjdzpqas9S Wera6JVjcKCLH8X/uhPpeWI3sVOuqSfH5RjhrbDaPTYiR79Ayc8lQsafj15Py2YG mz2uZU4VhhLwvMd9M94l+akZm7Xkk9ovJNXUSxuuoskveuwfy/J8illu2Y95YFW+ RCbsqmLyr4482ZrE3SUG9wdjlLjTjW/yYNBcsxog4e7DSmrV1qQfuELXTZdVXGxz 0IK34iM56PceIAlBzjoSsUiAo7AAzhtHL22k0PjRn87Se7IFoXp98CE8Gq0/8nJx 8H6DyTsMD9E+hhW+/dIRTmw3EW93cK0zjzkzannRvLZBEybBvmcqj0OlU5NnI/vT KQL9imMQaG9KRevTHohzGX/vJ0ax54rSyuzaVk2kNwuVwyyYz8H8YB65HAWQs8wa 6Pf99Msso72L72MdNW5yGASrosEqWtcRoz3z5OlvT50CVe5t1Rs= =6I9z -----END PGP SIGNATURE-----