-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 06 Dec 2025 11:10:16 +0100 Source: libpng1.6 Binary: libpng-dev libpng-tools libpng-tools-dbgsym libpng16-16-udeb libpng16-16t64 libpng16-16t64-dbgsym Architecture: armhf Version: 1.6.48-1+deb13u1 Distribution: trixie-security Urgency: high Maintainer: arm Build Daemon (arm-conova-01) Changed-By: Tobias Frost Description: libpng-dev - PNG library - development (version 1.6) libpng-tools - PNG library - tools (version 1.6) libpng16-16-udeb - PNG library - minimal runtime library (version 1.6) (udeb) libpng16-16t64 - PNG library - runtime (version 1.6) Closes: 1121216 1121217 1121218 1121219 1121877 Changes: libpng1.6 (1.6.48-1+deb13u1) trixie-security; urgency=high . * Security upload targeting trixie. * Backport fixes for: - CVE-2025-64505 - Heap buffer over-read (Closes: #1121219) - CVE-2025-64506 - Heap buffer over-read (Closes: #1121218) - CVE-2025-64720 - Heap buffer overflow (Closes: #1121217) - CVE-2025-65018 - Heap buffer overflow (Closes: #1121216) - CVE-2025-66293 - Out-of-bounds read (Closes: #1121877) * Set gbp.conf for trixie and enable salsa CI Checksums-Sha1: e270ab73ba387978e98670c4ca68bf70f5b041f2 349556 libpng-dev_1.6.48-1+deb13u1_armhf.deb 8b9f84ded2bc4164d9970c4015004f4116f0f09a 48528 libpng-tools-dbgsym_1.6.48-1+deb13u1_armhf.deb d9b5d7753401759742f6cd62fa1688f566e731d1 127424 libpng-tools_1.6.48-1+deb13u1_armhf.deb de0d8c7e532cb62ddaa482b689d69a64d1fe412b 7977 libpng1.6_1.6.48-1+deb13u1_armhf-buildd.buildinfo 3318278facaa9ae43a9ee7fd6cfb9cc3962dd93b 76660 libpng16-16-udeb_1.6.48-1+deb13u1_armhf.udeb e33b4e04618b907f040a9d9032b03dcadb16b194 247072 libpng16-16t64-dbgsym_1.6.48-1+deb13u1_armhf.deb 657050f89bacf1be09577974e0138ed7a3496c7e 264152 libpng16-16t64_1.6.48-1+deb13u1_armhf.deb Checksums-Sha256: aa1730fc630533fddb611fa877290995a71537a531d26547b44a669f19a28328 349556 libpng-dev_1.6.48-1+deb13u1_armhf.deb 46e775ffa23456b6d89f4d2beafcdf582ba03c1c953d8c255630dd513b767987 48528 libpng-tools-dbgsym_1.6.48-1+deb13u1_armhf.deb e6fc4bb8ec2c376656925dffa6e063acfd3297975ecdc95f64784e9c29bc7f5b 127424 libpng-tools_1.6.48-1+deb13u1_armhf.deb 3f41e62843d6345bd06f9cffe8c75d424936063b4e5f3b21b87919e3311b5736 7977 libpng1.6_1.6.48-1+deb13u1_armhf-buildd.buildinfo b1a6545038b1b2028466757c339746902285981ccbdb01313cbca8ab577fd9e7 76660 libpng16-16-udeb_1.6.48-1+deb13u1_armhf.udeb e50747247207a50c7cf27ef661dbff5b4b756d2a8ff0cc4301f9717b121a7c6b 247072 libpng16-16t64-dbgsym_1.6.48-1+deb13u1_armhf.deb 3e38a420e634a574725f6662b37a42f745310012bb750c9dc5ec4055ed26e12d 264152 libpng16-16t64_1.6.48-1+deb13u1_armhf.deb Files: bf219d2790976117e1fec23ff2764ec2 349556 libdevel optional libpng-dev_1.6.48-1+deb13u1_armhf.deb 2da01c5bb3ad467acc83d77df94104f4 48528 debug optional libpng-tools-dbgsym_1.6.48-1+deb13u1_armhf.deb 4f3142ad2877a9f320e553084ba09685 127424 libdevel optional libpng-tools_1.6.48-1+deb13u1_armhf.deb cb4a9e98497f69837d9ce0f7b8a7807e 7977 libs optional libpng1.6_1.6.48-1+deb13u1_armhf-buildd.buildinfo a00dc4a1add78743ad41424ae96921b6 76660 debian-installer optional libpng16-16-udeb_1.6.48-1+deb13u1_armhf.udeb 7865566f4bda145ee1c673d7c667f723 247072 debug optional libpng16-16t64-dbgsym_1.6.48-1+deb13u1_armhf.deb b550400f60c5f3a5a15e8fca27278f5b 264152 libs optional libpng16-16t64_1.6.48-1+deb13u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEO4qAQUSIo2p/kVRf8U6eOZMpj68FAmk0SFYACgkQ8U6eOZMp j68HAw//WQlptNMvJrrDRyIU9e1BlZE54GRrSaM9mrbeKsN2q15y68t/vYxdYUjA FcLZ4ZxZUhufMIedmBpQjuRBLPvWvzwDWqFYP+bVY3ZnXY8oPEnTYWF9glh3WXup V23xIfGkQZeUgAe5swzyO3fxUbyX9ZdFSd8An6rZ3qKIYwLQAQISBZU9RwH1Bvpg DunoCy9X4tWDmQ+w/ejrWbpUwmIoWyt2s1mZYFmb2cqwewFl1dYIg6VpegeSe6YT kAWOpL0ggowlV67On49TdRK+YXuG5prk/e1BfzuFeLkvlbl1LCL3oD/bcjT0Z1r9 IDyyUHKPqWZlbaLdoFkdzA20/rZL1IJqYfM0k0wWFrIpg6EXZqMhZJkpqSATgiod 3cbKRe9x+tt3L+cnfYGxQwMvSjrpzkHt6AYUSwe3IGZQUFErYx0zU//Ovw9Xp2eA 4ISezkrmTFdGrBs2oVs1/gtt+EJTa43xxAV9YZEQf/bOLeqKHv/Oz8AKqRjH+I/4 WMWwPJRZPIK5yapWj10WudbAhTXVR2x5YNO0ytvB0GuM18Ow9GV8QKS7TEDBIDNU 06JnGaHB8tTW1Sqcx96dI2fUFmrZ2pEyoVHRAsj0kv+hpadntYdYLXBGaaC+UGvW RMaue/d4DI0rZvldT3BXkKh1cuWyZHGgk0VvTe/SaSYAx40glus= =bcqu -----END PGP SIGNATURE-----