-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 12 Dec 2025 18:43:13 +0000 Source: glib2.0 Binary: gir1.2-girepository-3.0 gir1.2-girepository-3.0-dev gir1.2-glib-2.0 gir1.2-glib-2.0-dev girepository-tools girepository-tools-dbgsym libgio-2.0-dev libgio-2.0-dev-bin libgio-2.0-dev-bin-dbgsym libgirepository-2.0-0 libgirepository-2.0-0-dbgsym libgirepository-2.0-dev libglib2.0-0t64 libglib2.0-0t64-dbgsym libglib2.0-bin libglib2.0-bin-dbgsym libglib2.0-dev libglib2.0-dev-bin libglib2.0-tests libglib2.0-tests-dbgsym libglib2.0-udeb Architecture: i386 Version: 2.84.4-3~deb13u2 Distribution: trixie Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-ubc-02) Changed-By: Simon McVittie Description: gir1.2-girepository-3.0 - Introspection data for GIRepository library, API version 3.0 gir1.2-girepository-3.0-dev - GIR XML for GIRepository library, API version 3.0 gir1.2-glib-2.0 - Introspection data for GLib, GObject, Gio and GModule gir1.2-glib-2.0-dev - GIR XML for GLib, GObject, Gio and GModule girepository-tools - Tools for working with GObject-Introspection repositories libgio-2.0-dev - Development files for the GLib, GObject and GIO libraries libgio-2.0-dev-bin - Development utilities for GLib, GObject and GIO libraries libgirepository-2.0-0 - GLib runtime library for handling GObject introspection data libgirepository-2.0-dev - Development files for the GObject introspection library libglib2.0-0t64 - GLib library of C routines libglib2.0-bin - Programs for the GLib library libglib2.0-dev - Development metapackage for the GLib family of libraries libglib2.0-dev-bin - Development utilities for the GLib library libglib2.0-tests - GLib library of C routines - installed tests libglib2.0-udeb - GLib library of C routines - minimal runtime (udeb) Closes: 1121488 1122346 1122347 Changes: glib2.0 (2.84.4-3~deb13u2) trixie; urgency=medium . * d/patches: Add patches from 2.86.3 upstream to avoid integer overflows - d/p/gconvert-Error-out-if-g_escape_uri_string-would-overflow.patch, d/p/fuzzing-Add-fuzz-tests-for-g_filename_-to-from-_uri.patch: Fix an integer overflow when interpolating hundreds of megabytes of unescaped text into a URI, and add test coverage (CVE-2025-13601, glib#3827 upstream, Closes: #1121488) - d/p/gvariant-parser-Fix-potential-integer-overflow-parsing-by.patch: Fix an integer overflow when parsing very large strings in GVariant text format (CVE-2025-14087, glib#3834 upstream, Closes: #1122347) - d/p/gvariant-parser-Use-size_t-to-count-numbers-of-child-elem.patch, d/p/gvariant-parser-Convert-error-handling-code-to-use-size_t.patch: Fix other potential integer overflows parsing very large container types in GVariant text format, related to CVE-2025-14087 - d/p/gfileattribute-Fix-integer-overflow-calculating-escaping-.patch: Fix an integer overflow when escaping invalid characters in very large file attributes (CVE-2025-14512, glib#3845 upstream, Closes: #1122346) Checksums-Sha1: b2c2591f2cf6dd54f7929708b147d0517697fd55 84584 gir1.2-girepository-3.0-dev_2.84.4-3~deb13u2_i386.deb 6a94506ce080efa5dcae7941b28327e0acc0a39e 61448 gir1.2-girepository-3.0_2.84.4-3~deb13u2_i386.deb 4edad125c2d8a5ad948ed51fe0d946f8b07e9e9a 916656 gir1.2-glib-2.0-dev_2.84.4-3~deb13u2_i386.deb fdce5bf6e47a1917d5775dcb121eb6a12b9b6394 198808 gir1.2-glib-2.0_2.84.4-3~deb13u2_i386.deb 957f5781e1d93ea4b7bbbd4187773c747779a114 288588 girepository-tools-dbgsym_2.84.4-3~deb13u2_i386.deb 2e2f7e33cefb4ae44657d0227fa5baee23abbfc1 158592 girepository-tools_2.84.4-3~deb13u2_i386.deb dce420835f23df9c4713afa4db9bf6848d8972d0 15743 glib2.0_2.84.4-3~deb13u2_i386-buildd.buildinfo 9b763693f6afe890147b5b775c2f9f6130f53347 73432 libgio-2.0-dev-bin-dbgsym_2.84.4-3~deb13u2_i386.deb fa59e3ef5540976c33f91fed3be8286d937c0981 167412 libgio-2.0-dev-bin_2.84.4-3~deb13u2_i386.deb 0337031b37d05a60caaa6b696f421cb9aa83b35e 1803196 libgio-2.0-dev_2.84.4-3~deb13u2_i386.deb 9dcc4a86439795f2862c4694b3ea26f7f90774b0 292344 libgirepository-2.0-0-dbgsym_2.84.4-3~deb13u2_i386.deb bb034ae71203f3853571d78ba66d5af1fcd1ef0b 149432 libgirepository-2.0-0_2.84.4-3~deb13u2_i386.deb de5acb79a70c300a3059b5558f8b531d113ee1e4 232832 libgirepository-2.0-dev_2.84.4-3~deb13u2_i386.deb 52767858c1a4f98f48bbcdc6538883239e69b88a 3807660 libglib2.0-0t64-dbgsym_2.84.4-3~deb13u2_i386.deb 80ff1bce64516545b43f679d39ab623aef782c42 1588072 libglib2.0-0t64_2.84.4-3~deb13u2_i386.deb 9fee178bd90006538a7c818885c63b65415e6587 153960 libglib2.0-bin-dbgsym_2.84.4-3~deb13u2_i386.deb 933f0a41acb5aa80c1f5b4e375047b1799088b5c 133920 libglib2.0-bin_2.84.4-3~deb13u2_i386.deb 9b9e5b0c7b9c5ab19ada4fbdd76c0ffe2ccdbb8b 55264 libglib2.0-dev-bin_2.84.4-3~deb13u2_i386.deb 5bbd6db13e6df3cbc272e8aca4a73d159a963412 56052 libglib2.0-dev_2.84.4-3~deb13u2_i386.deb 0ec6455888e017c371b895f8600a32e2eb25fe69 5002004 libglib2.0-tests-dbgsym_2.84.4-3~deb13u2_i386.deb bf33b39ccd17da8ceaa62b2631dc05b890cb9a23 2017036 libglib2.0-tests_2.84.4-3~deb13u2_i386.deb eeee2d1ac55989f6daea89aad18c3a6dc201917c 2444516 libglib2.0-udeb_2.84.4-3~deb13u2_i386.udeb Checksums-Sha256: cb4d4fa923e376194d59d2159d262bd2b897a8b89ab33a4c4880d16628b25fa5 84584 gir1.2-girepository-3.0-dev_2.84.4-3~deb13u2_i386.deb 896f7165428d4c02a320cb512858edaff80102345a9fa10206ea21953c4832ed 61448 gir1.2-girepository-3.0_2.84.4-3~deb13u2_i386.deb cab6b8cbf089df152485e2fdf0515033899f5b9a046b88790e1fdc4250405254 916656 gir1.2-glib-2.0-dev_2.84.4-3~deb13u2_i386.deb 69415fc37cd04bc98fe5848e15ec8b4e73cab30ee60b39ef14efa95aa8bcc8b5 198808 gir1.2-glib-2.0_2.84.4-3~deb13u2_i386.deb b872338eaaf0a94db9f77d3bfe2745c8eaf9f5f2f2e9b03674eac06902b98bd4 288588 girepository-tools-dbgsym_2.84.4-3~deb13u2_i386.deb d0b7675f6512d3452cc897822f20fc7f92538d5fff94f896e6d4b1eed6f545f3 158592 girepository-tools_2.84.4-3~deb13u2_i386.deb 905500c1b60d2ebf30d712d6b5409f9974c13cfbb07216c50500e79cf9fe53ec 15743 glib2.0_2.84.4-3~deb13u2_i386-buildd.buildinfo fa16d3f68743949320a439858873fd3a5a1b5a5f2a4d8182fe004e6ed888e35d 73432 libgio-2.0-dev-bin-dbgsym_2.84.4-3~deb13u2_i386.deb c1c94ca9c1a325a8b5644cf42200bc4e7103d3ecdd84234929565729ce5a0896 167412 libgio-2.0-dev-bin_2.84.4-3~deb13u2_i386.deb b46f325eb941c9b4e0025f2952413c75a02f9cdaf8f5a55979c2bce43aee66cf 1803196 libgio-2.0-dev_2.84.4-3~deb13u2_i386.deb 9942c6a231e171b521f1e9db48ba90c75f04e9c152d559625a3b88326e9b7161 292344 libgirepository-2.0-0-dbgsym_2.84.4-3~deb13u2_i386.deb afefc6ab686d91472ca00619bd41e35131905f86d18ab699a20efe1c0fb1ae2b 149432 libgirepository-2.0-0_2.84.4-3~deb13u2_i386.deb 2129f9d1719ee24c46f50b5cae30c0cd8dff70d16880f8a9f90faea432345a0c 232832 libgirepository-2.0-dev_2.84.4-3~deb13u2_i386.deb e0168c96399fd9235c0e924fe7929efec20102f049adf8cfff8188ebf36fb5e1 3807660 libglib2.0-0t64-dbgsym_2.84.4-3~deb13u2_i386.deb eead74ad2827a8535221b76ef60d0f95b98995c6fb4614d876b9f495a403916e 1588072 libglib2.0-0t64_2.84.4-3~deb13u2_i386.deb cd334ce7104c775f1b8b1288c4c421454634153d7229880ddec02d000362ccb5 153960 libglib2.0-bin-dbgsym_2.84.4-3~deb13u2_i386.deb 287b8fe162590b1c781e78a3b178b1e4cafe49aab30c649b56638c8ce6d10d3e 133920 libglib2.0-bin_2.84.4-3~deb13u2_i386.deb 67eccf64641cb0c5dc1faf01a0ecc742d3262a0969d8e6a69fb9d9c536455ae4 55264 libglib2.0-dev-bin_2.84.4-3~deb13u2_i386.deb 382e2aacd23d64d2c38e30057f4457f0111e12870e6f931dc1f36dbc9d8f1a81 56052 libglib2.0-dev_2.84.4-3~deb13u2_i386.deb 878e4237b9bcb1a50da5a317cd2b38c3a1df775cef11ef178a1263279da86626 5002004 libglib2.0-tests-dbgsym_2.84.4-3~deb13u2_i386.deb f5addd2089943ff9590c9bb05339912cd7d242232a850ab6c484ce15ede8bbe3 2017036 libglib2.0-tests_2.84.4-3~deb13u2_i386.deb 5115f14ca4f2cee3e0af89cb58f1710b00cfb43efe033d0ae7b61edfe5c22800 2444516 libglib2.0-udeb_2.84.4-3~deb13u2_i386.udeb Files: 9cea4cf850690028b5ec17b9ebfd7093 84584 libdevel optional gir1.2-girepository-3.0-dev_2.84.4-3~deb13u2_i386.deb 125cb2d21c7d1765eef0da35b74af093 61448 introspection optional gir1.2-girepository-3.0_2.84.4-3~deb13u2_i386.deb 64dff303899e1f7f4160da4c8931be31 916656 libdevel optional gir1.2-glib-2.0-dev_2.84.4-3~deb13u2_i386.deb aab43f4e88131e263a4d95925f163e26 198808 introspection optional gir1.2-glib-2.0_2.84.4-3~deb13u2_i386.deb 17557867dd9b1123183e51fc29d370ce 288588 debug optional girepository-tools-dbgsym_2.84.4-3~deb13u2_i386.deb e25afb0859a0e44d16c5d2e818d29fbe 158592 libdevel optional girepository-tools_2.84.4-3~deb13u2_i386.deb 65144fb45189e34771df1358757430bb 15743 libs optional glib2.0_2.84.4-3~deb13u2_i386-buildd.buildinfo dff3264cd9075482ef2f9dc87f1cc34d 73432 debug optional libgio-2.0-dev-bin-dbgsym_2.84.4-3~deb13u2_i386.deb fabc88cf4c0a9ef2484171035d6fc362 167412 libdevel optional libgio-2.0-dev-bin_2.84.4-3~deb13u2_i386.deb f70e504e7201791e7631281ece0adbda 1803196 libdevel optional libgio-2.0-dev_2.84.4-3~deb13u2_i386.deb 82c7adfd99b5970823f129e4f3de6d82 292344 debug optional libgirepository-2.0-0-dbgsym_2.84.4-3~deb13u2_i386.deb 2083b4f21aa2952b3b5b6f4160fd87f9 149432 libs optional libgirepository-2.0-0_2.84.4-3~deb13u2_i386.deb 86dde2872ef472626b5f11192bd131cc 232832 libdevel optional libgirepository-2.0-dev_2.84.4-3~deb13u2_i386.deb 20153deb467e8ab3a86b4db7cf27c9c5 3807660 debug optional libglib2.0-0t64-dbgsym_2.84.4-3~deb13u2_i386.deb 053e7b4d525fa650e8474d2635d9a586 1588072 libs optional libglib2.0-0t64_2.84.4-3~deb13u2_i386.deb 489942854978f8ac9995a3dcbe64a1f0 153960 debug optional libglib2.0-bin-dbgsym_2.84.4-3~deb13u2_i386.deb 7bf928d7528c3b97f1bd9b88765d24ad 133920 misc optional libglib2.0-bin_2.84.4-3~deb13u2_i386.deb 28d28c6b8347f93c9c524ca9457aa455 55264 libdevel optional libglib2.0-dev-bin_2.84.4-3~deb13u2_i386.deb 0e5029245ca6041e4f9b17bb5522d194 56052 libdevel optional libglib2.0-dev_2.84.4-3~deb13u2_i386.deb ce22c8557dc9a1f338fde241963dde7c 5002004 debug optional libglib2.0-tests-dbgsym_2.84.4-3~deb13u2_i386.deb 14eb64479027bb86ad6b4639bc3a0863 2017036 libs optional libglib2.0-tests_2.84.4-3~deb13u2_i386.deb 63a36070e83f32c29964f6c7a081f070 2444516 debian-installer optional libglib2.0-udeb_2.84.4-3~deb13u2_i386.udeb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEc5vuvf2HND40bnI+8IREj/cRiTMFAmlIHVYACgkQ8IREj/cR iTNlyw/+NNWcrsYXNp4HBpPOWvAN4ATc135LqO9jTR1phsFQomT1VNXoJ2OoJCFf DcgW+848GhNbVRmR4jz/rJuk5naVamfb6czOaf5izDEpVplo9vi4cQnj3tbBQqfV hAkLMr45N0CBUV193+T2dvXagl1J04osIK+HjCSortqT/XIYFLM1qz1E9UkVAPe3 WMEOxEeT8mllHt5P0s4AtkjCNOruC0qmMiyxgqQuO59MZ+XXn+teR3J9w1ShJ0vh 5B8pRUawds8oA8797frB8EEgmPL5W0i9fbD5xOcIDEI0vpWqyBFMdKpnMv2haKdk W3BGTs+XkjkSc9hfkwaYwfoWPXLX50U4AwTPeVXhIr2BzPI07OzYaU4sSECVN3iV jEHlHdLIQOGVhAOid9vLMzJUfJvXiCnKkQJokLxcKADhDNXn4OwvlaVMpK1iiHVY tP34m1vHH9N4ogd1SchucHCzrO1UQYFY1g+wAEov7uLsY5PglPOlbkjEqQ5Q45TE W1H4RjJ0hC6YWzfElkbdWEMVQugKDwXw6UQCVpyCEFOZL+cKWbETHbvbfhRaz/ob AN/bGVOF8TuqwXKFBUSgOpeEyZayQhJ9s0YYzhAJbuT/tP6CqGW0Iw4AhXlc9ZzI wY+yV7J6Nm2tCZofxUKLEfZ//gH0EAuW7dmAsGLHPetlenyb4m4= =9r8G -----END PGP SIGNATURE-----