-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 12 Dec 2025 18:43:13 +0000 Source: glib2.0 Binary: gir1.2-girepository-3.0 gir1.2-girepository-3.0-dev gir1.2-glib-2.0 gir1.2-glib-2.0-dev girepository-tools girepository-tools-dbgsym libgio-2.0-dev libgio-2.0-dev-bin libgio-2.0-dev-bin-dbgsym libgirepository-2.0-0 libgirepository-2.0-0-dbgsym libgirepository-2.0-dev libglib2.0-0t64 libglib2.0-0t64-dbgsym libglib2.0-bin libglib2.0-bin-dbgsym libglib2.0-dev libglib2.0-dev-bin libglib2.0-tests libglib2.0-tests-dbgsym libglib2.0-udeb Architecture: amd64 Version: 2.84.4-3~deb13u2 Distribution: trixie Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) Changed-By: Simon McVittie Description: gir1.2-girepository-3.0 - Introspection data for GIRepository library, API version 3.0 gir1.2-girepository-3.0-dev - GIR XML for GIRepository library, API version 3.0 gir1.2-glib-2.0 - Introspection data for GLib, GObject, Gio and GModule gir1.2-glib-2.0-dev - GIR XML for GLib, GObject, Gio and GModule girepository-tools - Tools for working with GObject-Introspection repositories libgio-2.0-dev - Development files for the GLib, GObject and GIO libraries libgio-2.0-dev-bin - Development utilities for GLib, GObject and GIO libraries libgirepository-2.0-0 - GLib runtime library for handling GObject introspection data libgirepository-2.0-dev - Development files for the GObject introspection library libglib2.0-0t64 - GLib library of C routines libglib2.0-bin - Programs for the GLib library libglib2.0-dev - Development metapackage for the GLib family of libraries libglib2.0-dev-bin - Development utilities for the GLib library libglib2.0-tests - GLib library of C routines - installed tests libglib2.0-udeb - GLib library of C routines - minimal runtime (udeb) Closes: 1121488 1122346 1122347 Changes: glib2.0 (2.84.4-3~deb13u2) trixie; urgency=medium . * d/patches: Add patches from 2.86.3 upstream to avoid integer overflows - d/p/gconvert-Error-out-if-g_escape_uri_string-would-overflow.patch, d/p/fuzzing-Add-fuzz-tests-for-g_filename_-to-from-_uri.patch: Fix an integer overflow when interpolating hundreds of megabytes of unescaped text into a URI, and add test coverage (CVE-2025-13601, glib#3827 upstream, Closes: #1121488) - d/p/gvariant-parser-Fix-potential-integer-overflow-parsing-by.patch: Fix an integer overflow when parsing very large strings in GVariant text format (CVE-2025-14087, glib#3834 upstream, Closes: #1122347) - d/p/gvariant-parser-Use-size_t-to-count-numbers-of-child-elem.patch, d/p/gvariant-parser-Convert-error-handling-code-to-use-size_t.patch: Fix other potential integer overflows parsing very large container types in GVariant text format, related to CVE-2025-14087 - d/p/gfileattribute-Fix-integer-overflow-calculating-escaping-.patch: Fix an integer overflow when escaping invalid characters in very large file attributes (CVE-2025-14512, glib#3845 upstream, Closes: #1122346) Checksums-Sha1: 8f24d36202266f402a201d098c9c85c33c8a7c83 84584 gir1.2-girepository-3.0-dev_2.84.4-3~deb13u2_amd64.deb 7e76748096e089fed6a0db377fef195faece4bbe 61448 gir1.2-girepository-3.0_2.84.4-3~deb13u2_amd64.deb df07c5442a77246145927a5b8d55163909ec884e 916644 gir1.2-glib-2.0-dev_2.84.4-3~deb13u2_amd64.deb c09337607984d476029c59f840c1e6b62f35d376 199020 gir1.2-glib-2.0_2.84.4-3~deb13u2_amd64.deb 7a6e8fdfc3799f6a29f2ec9730a7555814671c81 325884 girepository-tools-dbgsym_2.84.4-3~deb13u2_amd64.deb 1c54296836b72d88ef8d640db60cc8940ab60443 150632 girepository-tools_2.84.4-3~deb13u2_amd64.deb ef4728b094ef3716d83b1bfaab565415824b2fc7 15899 glib2.0_2.84.4-3~deb13u2_amd64-buildd.buildinfo 30602b34a3304f79e1fd36c88ba2d63b2c9808d2 81868 libgio-2.0-dev-bin-dbgsym_2.84.4-3~deb13u2_amd64.deb 46f12e87af8f6b5d6affa3cf19a7f1c45cc9ac1c 166896 libgio-2.0-dev-bin_2.84.4-3~deb13u2_amd64.deb 3f1e866395b07597a07cc546c76361d0abd11689 1688564 libgio-2.0-dev_2.84.4-3~deb13u2_amd64.deb 2420e1779ce95f7cce0ea892f4ce5be33541ca95 335832 libgirepository-2.0-0-dbgsym_2.84.4-3~deb13u2_amd64.deb 4d43980021348996b6fe9e4d3ed2c0d8ab1164d1 143732 libgirepository-2.0-0_2.84.4-3~deb13u2_amd64.deb dd6c683db018fde777caa361e458a9a98b3d74aa 217696 libgirepository-2.0-dev_2.84.4-3~deb13u2_amd64.deb 74b60119af54456ad3c4f1998052a3b4a351f693 4581712 libglib2.0-0t64-dbgsym_2.84.4-3~deb13u2_amd64.deb 8b9551efe7941c516dfcb1b9e249067bd119d2a5 1518320 libglib2.0-0t64_2.84.4-3~deb13u2_amd64.deb b78c91f56a9744fcecade580ce088a9210616521 175004 libglib2.0-bin-dbgsym_2.84.4-3~deb13u2_amd64.deb 2c579fe23db9efde48e5ad94a60cdede924d3a2b 130616 libglib2.0-bin_2.84.4-3~deb13u2_amd64.deb 9291c74be5faf8472020931fec89cca032a27d03 55264 libglib2.0-dev-bin_2.84.4-3~deb13u2_amd64.deb 7a6d531fc7f02f39f4e9db42608b23f5ba298a3e 56056 libglib2.0-dev_2.84.4-3~deb13u2_amd64.deb d1e79936ba611fdaaf1a45c944465f4cd2fa1903 5919968 libglib2.0-tests-dbgsym_2.84.4-3~deb13u2_amd64.deb e87643dca5a3b0291a75098153dd83765d0e8dd3 2117692 libglib2.0-tests_2.84.4-3~deb13u2_amd64.deb 2c4f7f988e32e6eec349303c0a4c2cedc9f372be 2374828 libglib2.0-udeb_2.84.4-3~deb13u2_amd64.udeb Checksums-Sha256: d24e3b47b465d21317c43c4f8c25797eb48c3201739b36f6a452adf6024b2448 84584 gir1.2-girepository-3.0-dev_2.84.4-3~deb13u2_amd64.deb 2c8ea768f734175586b49f1650f615a5e0d64a41727ac8826389a68098a4137b 61448 gir1.2-girepository-3.0_2.84.4-3~deb13u2_amd64.deb d284acbabbb2ae855fc088ad2ddd16b78fcdd66aa39bc7848578f1aecbb290a4 916644 gir1.2-glib-2.0-dev_2.84.4-3~deb13u2_amd64.deb f2c764ea81311386fe0e68c49f84c3bc8ce51e87ee3efd9d4cd5008696feb99c 199020 gir1.2-glib-2.0_2.84.4-3~deb13u2_amd64.deb 82df6fb90f714b19917e5d6c81fe8b6ff5dfd7a4f3152a46f058e32652dcb7e7 325884 girepository-tools-dbgsym_2.84.4-3~deb13u2_amd64.deb a10e6dc7f0b9709f96de0ec5caf1f06392215c6602d0bda6bfa111b9360612df 150632 girepository-tools_2.84.4-3~deb13u2_amd64.deb 66e827442c9f0ccab9aadc695b79577ade4c0febf5bbcdfaf8fc140d51d57d52 15899 glib2.0_2.84.4-3~deb13u2_amd64-buildd.buildinfo d8dcfe4b5b134ad8a5af5c48e36db3df75ab887dd5d71b600146c25ac7728848 81868 libgio-2.0-dev-bin-dbgsym_2.84.4-3~deb13u2_amd64.deb 7965b52477eeacc289ded3562f41769cf9aeac567d7f12421507177e421558d8 166896 libgio-2.0-dev-bin_2.84.4-3~deb13u2_amd64.deb 7b47004d6a74875d4e4fc801a28a26557d7802433aaad74ddcefee40e5b61b36 1688564 libgio-2.0-dev_2.84.4-3~deb13u2_amd64.deb c05f00d57de378a0c547c8533894f312a1f95e24522bf01903f20fef2653c727 335832 libgirepository-2.0-0-dbgsym_2.84.4-3~deb13u2_amd64.deb 93914434064afc6d630d9358a2862239cca33b842a325255d61c5292dcae9d32 143732 libgirepository-2.0-0_2.84.4-3~deb13u2_amd64.deb 40bc0edfad7452f68ee3a6c73ec1ae9cfac3d76a373e8790377aeff413007ec8 217696 libgirepository-2.0-dev_2.84.4-3~deb13u2_amd64.deb fe7bcced38b8db7207a1d253234e830b0d0a257e6ab55cc761dcfd754c94c8b4 4581712 libglib2.0-0t64-dbgsym_2.84.4-3~deb13u2_amd64.deb 6d4c07e17b9809eca7078b49851da8e1d16e510e80897cc96681bd4c75b27353 1518320 libglib2.0-0t64_2.84.4-3~deb13u2_amd64.deb e94019d2b469960d30a91120bd674be601de06556d2dc4f0d3df0775fb351a16 175004 libglib2.0-bin-dbgsym_2.84.4-3~deb13u2_amd64.deb 5dca3b00dcbba8d2cebbf4f0d326c0923ec6bd4e7a2dee824201faf56235b3ae 130616 libglib2.0-bin_2.84.4-3~deb13u2_amd64.deb 63a236ca6783ad5d6bb76e49d7c94e9da7725b4c968dc086e64d3a067bfcd341 55264 libglib2.0-dev-bin_2.84.4-3~deb13u2_amd64.deb 9bdba595b11a9f0ad21147c77ffe24c77dd77f04479f689351699b0ffe6edbce 56056 libglib2.0-dev_2.84.4-3~deb13u2_amd64.deb 749d18389e786b6a152b5928e7da18cc157b7e0247d975f1b0421eba6bde6031 5919968 libglib2.0-tests-dbgsym_2.84.4-3~deb13u2_amd64.deb ee3d5a784347939d1f3cc2e79b3bb84f66fbf4d737d4caba7f22192c2e7b76ce 2117692 libglib2.0-tests_2.84.4-3~deb13u2_amd64.deb 2d45c7711e027847c7adb7cec85361506d652bb5fb9feb08f88b4842b41df158 2374828 libglib2.0-udeb_2.84.4-3~deb13u2_amd64.udeb Files: 10a71c8e538671992cf243849a6c78ee 84584 libdevel optional gir1.2-girepository-3.0-dev_2.84.4-3~deb13u2_amd64.deb 213fc7a65978f9e753e7731e8aed4bb9 61448 introspection optional gir1.2-girepository-3.0_2.84.4-3~deb13u2_amd64.deb 72d61da27969a51405658434ca0df4a5 916644 libdevel optional gir1.2-glib-2.0-dev_2.84.4-3~deb13u2_amd64.deb 9aa7806ac00b3330ab18c6cbca51929a 199020 introspection optional gir1.2-glib-2.0_2.84.4-3~deb13u2_amd64.deb 456237e8908b7b03775e399c4ec4cf4b 325884 debug optional girepository-tools-dbgsym_2.84.4-3~deb13u2_amd64.deb 5b1af84c42b87969d21f4c68b19e6215 150632 libdevel optional girepository-tools_2.84.4-3~deb13u2_amd64.deb 11cd7608c52053184a816d38fe347a72 15899 libs optional glib2.0_2.84.4-3~deb13u2_amd64-buildd.buildinfo aeea15c253d0dd666a5056660bcde5a0 81868 debug optional libgio-2.0-dev-bin-dbgsym_2.84.4-3~deb13u2_amd64.deb 45d035f762e4e786190d02cac87a88b3 166896 libdevel optional libgio-2.0-dev-bin_2.84.4-3~deb13u2_amd64.deb c9e796fe7b9b19806ac3d41157a204c1 1688564 libdevel optional libgio-2.0-dev_2.84.4-3~deb13u2_amd64.deb 1f0e271d88abbd93fd0c2776bb308808 335832 debug optional libgirepository-2.0-0-dbgsym_2.84.4-3~deb13u2_amd64.deb d44a06865c740e74d79443a64581e8a0 143732 libs optional libgirepository-2.0-0_2.84.4-3~deb13u2_amd64.deb 225be8f612d7d69d6c4a6fee1c5ade2b 217696 libdevel optional libgirepository-2.0-dev_2.84.4-3~deb13u2_amd64.deb 314cf882e22949b8ce588ad05b3a078f 4581712 debug optional libglib2.0-0t64-dbgsym_2.84.4-3~deb13u2_amd64.deb 6b3d33a279ef0cb732a8d94d94b9addd 1518320 libs optional libglib2.0-0t64_2.84.4-3~deb13u2_amd64.deb 15971456d930dfeb3794c538ef811e9c 175004 debug optional libglib2.0-bin-dbgsym_2.84.4-3~deb13u2_amd64.deb cebfa67709870055119c48de8df3c808 130616 misc optional libglib2.0-bin_2.84.4-3~deb13u2_amd64.deb c0d5f232c71449d87cd3a8b4a0f9dde1 55264 libdevel optional libglib2.0-dev-bin_2.84.4-3~deb13u2_amd64.deb 58973d63710015d29bfff64d7c3e1757 56056 libdevel optional libglib2.0-dev_2.84.4-3~deb13u2_amd64.deb 59e5dca3e268dd9598cfb576cdd3265c 5919968 debug optional libglib2.0-tests-dbgsym_2.84.4-3~deb13u2_amd64.deb 3e6c783b1ed77c90de8e8b1251e8d760 2117692 libs optional libglib2.0-tests_2.84.4-3~deb13u2_amd64.deb 018a8e1f5712f97e92816be95c2d9d2f 2374828 debian-installer optional libglib2.0-udeb_2.84.4-3~deb13u2_amd64.udeb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEaPzFtKPtF0JrKPV5iZlfn74WV6kFAmlIHekACgkQiZlfn74W V6kvJA//ZqwJOzd+aIQoo+eKNmFRWZSYF6edYh20Cedq+F6hOYaKrmF4GVC/hhWS ggZcZud6w/9XyBU4+nEYoKpNUCQooEN3/3I7BzR5ecRWGB5Bqg3zReJP9A1VhEBE 6L+hx7gTp7wFf7XW/HDi15XLvCidd0GbGPp6f4S9aeWIW/JESJJK7h2ZKCuhX/UZ gM3ErN4UB01k6LKyjI9qdqG6+KdtL40vM8lkHKpdFpe3VoqUUD7dbYZvCNvNkloh yl4szpLTdfZ5xZ9uwqM7bYpoUoflgPvwgY1NTr+hpezExv40twl7URgjNvx7xRVn eLypGto3L+QB1JVjC4Gi8dZaIO21IFdTELTyOoScK6PrGtErNFz0HMuYreYp2wCF uknTsUR3Ajtoglf42JXqb/rOIscpnhaRj9AguEWnedX1qKYy9pANbN+a9hWghHZm 6cWvgFNAPWpSfK1g/9iBQvfVhJTxlZ6WbB50IBn+4S4hXMc/LwvxIxRqoDXmeEs+ nJfVMaPOIgKRbEUsM5ReY43cB7gVJGkb6E5FmtlA9fD/MAiSX3U2rvfY/MRnywvX 2lOCBw4UZ76ZPyl0A2a1MjTG5jl1qUtW1ZVX+KwfOImko7+ppQMDV6uOtMiWWAzl dimnLVPeubbaFztQCZ2ggUof59WGyS5nDzwMBt0SLfW83XyUX0c= =3XNI -----END PGP SIGNATURE-----