-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 30 Mar 2026 20:59:03 +0200 Source: libpng1.6 Binary: libpng-dev libpng-tools libpng-tools-dbgsym libpng16-16 libpng16-16-dbgsym libpng16-16-udeb Architecture: amd64 Version: 1.6.39-2+deb12u4 Distribution: bookworm-security Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) Changed-By: Tobias Frost Description: libpng-dev - PNG library - development (version 1.6) libpng-tools - PNG library - tools (version 1.6) libpng16-16 - PNG library - runtime (version 1.6) libpng16-16-udeb - PNG library - minimal runtime library (version 1.6) (udeb) Closes: 1132012 1132013 Changes: libpng1.6 (1.6.39-2+deb12u4) bookworm-security; urgency=medium . * Security upload targeting bookworm. * Backporting upstream fixes for: - CVE-2026-33416 - Use-after-free (Closes: #1132012) - CVE-2026-33636 - OOB read/write on ARM plattforms (Closes: #1132013) Checksums-Sha1: b2accd4613082b921d9cc750c0254acaf89d4a20 359880 libpng-dev_1.6.39-2+deb12u4_amd64.deb 398c0cf42bacc7bb68b14a415ba2ab7cfb13c073 50228 libpng-tools-dbgsym_1.6.39-2+deb12u4_amd64.deb 9a0f13293a4c60bdb253a8c05cffd7b1a72c248b 127420 libpng-tools_1.6.39-2+deb12u4_amd64.deb d94618092ff19066ea7bdba587be9235eaf8a1a2 7536 libpng1.6_1.6.39-2+deb12u4_amd64-buildd.buildinfo 6a0f8586c2cb1f4b0f72411300e79f90b3020431 246740 libpng16-16-dbgsym_1.6.39-2+deb12u4_amd64.deb 49c6b20ffd6bae653d863eb0553d7e5fadcccb56 93420 libpng16-16-udeb_1.6.39-2+deb12u4_amd64.udeb a190b967130b4b9ad384e5ada608b85b44688ea7 276412 libpng16-16_1.6.39-2+deb12u4_amd64.deb Checksums-Sha256: 8637748aaf001d86bf3a61430031b34ae5a70f6ad15e3f8f29f380cb9856cdb3 359880 libpng-dev_1.6.39-2+deb12u4_amd64.deb bb568e4546649ff7c23b23c4b96216ea9ae0fe710b883ec3bd1eeb437a26b121 50228 libpng-tools-dbgsym_1.6.39-2+deb12u4_amd64.deb 568e1e07a87109020b405db9cbcda11a7d6d702aec767ce59f7e12c3ea99602c 127420 libpng-tools_1.6.39-2+deb12u4_amd64.deb a6381808a3d17b3fafeaad5065dc0c7cc305f1407daeea58c22362639448719c 7536 libpng1.6_1.6.39-2+deb12u4_amd64-buildd.buildinfo 3e665866b6f52140840cfa751f35488ecbf400894b9cb7ba49d95c0078c42a89 246740 libpng16-16-dbgsym_1.6.39-2+deb12u4_amd64.deb 802c0ba0e493c58d1f9d28e380aeb6a6a231369f7a773a4938dfa20db9c2d0e0 93420 libpng16-16-udeb_1.6.39-2+deb12u4_amd64.udeb 52b4d38170f59e508a3274920457af53530ea660d8287d435eb5bc79340aff93 276412 libpng16-16_1.6.39-2+deb12u4_amd64.deb Files: d198aad354cbb982492091895ba324f0 359880 libdevel optional libpng-dev_1.6.39-2+deb12u4_amd64.deb 5eff867b9372f50def6a223bc83db3ae 50228 debug optional libpng-tools-dbgsym_1.6.39-2+deb12u4_amd64.deb 3ad50f0594fcf055fc60e89c24fe591d 127420 libdevel optional libpng-tools_1.6.39-2+deb12u4_amd64.deb 0811c8e3a25e9b2986ee14df29843c6a 7536 libs optional libpng1.6_1.6.39-2+deb12u4_amd64-buildd.buildinfo 423c3582964b0efaaf6177e24a5e53e5 246740 debug optional libpng16-16-dbgsym_1.6.39-2+deb12u4_amd64.deb 79fd1573b1e402be48965bef0d3a8337 93420 debian-installer optional libpng16-16-udeb_1.6.39-2+deb12u4_amd64.udeb bc5f1be29e8706eadb5c50be3d6f64a1 276412 libs optional libpng16-16_1.6.39-2+deb12u4_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7cQ9mRD4+dWjjrb6PkCWRKsh20cFAmnL+E4ACgkQPkCWRKsh 20dd0w//d1BknTnXvob2REZlSlV5ed/6sO3Ds2P/JqtoeUkp/aTRbuh8Yy68EPHO mOBImicdtTZrXcvA5M5jRT/9UzyiBshI7LXOOlmXCRUPQrkC56N0ruj7GDMaYa8b GX0AXZaB6C42bN1KjHMdPeb3z9Y2iG62H+0gNckcX9RzdLiSzg13hfIMkby0MiHW Px2O4nbU7nYgVpQXCsB+nAcb2cDEZux3q/BhspVkK3Gjqj9+FmuJF/bvtdpF3CqJ sHAUOvLlV9TYgajXY4dzRK/J3VwH+61q4OYYt+zgHvbGE4Yuj6NV5gW0DVL5GhPM Hob6GMG1FVIbEotXG1ZWfnHtbybFt/AnL4FV3HGn/cF5oBU4B0V+Xn3MwiNAO1+a /zwyxr5UCkKSCJbfur05jb14BvDUaIatvuMKX7GYdTTqB6Sm1waf4KLCiDgsBzIC gloyLLp//4H8lvNluU0cQ7r/MvF7URYT0sGrpi6llzJgwzzjrRxmXe+2T8Ub+xgQ eWz1OlLWVkvD3W5cRqlJPxbn4Uax97+SukgjmehQ4C6wcCDYU8wwdbzXncQale4i B73O5mpj0BzMpJVLGeMZdczcHOW1eq/Ncrl941eSmY449ow74b5ch0zPYPoof46d 11FZa69YupFf5AeLO/YpGkz2/vRU3wAQvAd6xrYdMBTJ30XglEo= =5U3N -----END PGP SIGNATURE-----