-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 30 Mar 2026 20:59:03 +0200 Source: libpng1.6 Binary: libpng-dev libpng-tools libpng-tools-dbgsym libpng16-16 libpng16-16-dbgsym libpng16-16-udeb Architecture: arm64 Version: 1.6.39-2+deb12u4 Distribution: bookworm-security Urgency: medium Maintainer: arm Build Daemon (arm-ubc-02) Changed-By: Tobias Frost Description: libpng-dev - PNG library - development (version 1.6) libpng-tools - PNG library - tools (version 1.6) libpng16-16 - PNG library - runtime (version 1.6) libpng16-16-udeb - PNG library - minimal runtime library (version 1.6) (udeb) Closes: 1132012 1132013 Changes: libpng1.6 (1.6.39-2+deb12u4) bookworm-security; urgency=medium . * Security upload targeting bookworm. * Backporting upstream fixes for: - CVE-2026-33416 - Use-after-free (Closes: #1132012) - CVE-2026-33636 - OOB read/write on ARM plattforms (Closes: #1132013) Checksums-Sha1: 1f806b18e9395f5b449e198846c01d617ea1bcb1 355208 libpng-dev_1.6.39-2+deb12u4_arm64.deb 388683e0cac6e2738e367fba79bbed9246acf3cd 49424 libpng-tools-dbgsym_1.6.39-2+deb12u4_arm64.deb c88fcb86a23293395417b990eca515422b782aff 126420 libpng-tools_1.6.39-2+deb12u4_arm64.deb c7be2cbf8f3e5d75f5ce9cb951b67e94215b0c90 7535 libpng1.6_1.6.39-2+deb12u4_arm64-buildd.buildinfo bc3656ae14861ff3fd684c9f2fbe1feef87d64c6 257260 libpng16-16-dbgsym_1.6.39-2+deb12u4_arm64.deb 26ade21d2c330aee48a8b1a34de65d7cb4c30318 87076 libpng16-16-udeb_1.6.39-2+deb12u4_arm64.udeb c0ac76c54a0a607ecbba73f6df5a4bc641a41437 269984 libpng16-16_1.6.39-2+deb12u4_arm64.deb Checksums-Sha256: 380f54f281ff3844ee620d251e7e84eb5d33c730f1f144a070225995ad6931a4 355208 libpng-dev_1.6.39-2+deb12u4_arm64.deb 2a6eb628d59bbb049375d01d7bd1dafaaa9a1c0c3c20a687987a0185bb6065df 49424 libpng-tools-dbgsym_1.6.39-2+deb12u4_arm64.deb d4b8344ce124f358a2a5787a99444919e5b900e63038cf26c0194fe5aa00fd59 126420 libpng-tools_1.6.39-2+deb12u4_arm64.deb e9914223340485011e11a13502d6ca25e2438b16e9098a517f411221c35c9846 7535 libpng1.6_1.6.39-2+deb12u4_arm64-buildd.buildinfo 9a59eea9ca719f676123aada715b619cd216d9f38c848107ed7b1a1fe995eb4c 257260 libpng16-16-dbgsym_1.6.39-2+deb12u4_arm64.deb 36a6681e197de43d8de48aae1b7fef6d27e35ff65d5ca9393b019a00bb117878 87076 libpng16-16-udeb_1.6.39-2+deb12u4_arm64.udeb 26ef6e9ae4a87ac9566501eb0888fbdee726c0025450e792dc910a8a005b7b05 269984 libpng16-16_1.6.39-2+deb12u4_arm64.deb Files: 4fd5bc9bf0af0353de3c887cf4574229 355208 libdevel optional libpng-dev_1.6.39-2+deb12u4_arm64.deb 7f927aa81d43debd4a7bb3cbe29c791f 49424 debug optional libpng-tools-dbgsym_1.6.39-2+deb12u4_arm64.deb 3824518c8e9682a0bcdcae5acc971a79 126420 libdevel optional libpng-tools_1.6.39-2+deb12u4_arm64.deb 37f3a74c8c9f630404666982e7a5cc19 7535 libs optional libpng1.6_1.6.39-2+deb12u4_arm64-buildd.buildinfo ccf4b013ff19d5c275dfa16702ce4f11 257260 debug optional libpng16-16-dbgsym_1.6.39-2+deb12u4_arm64.deb 322755164f391bc81a2ed05715672550 87076 debian-installer optional libpng16-16-udeb_1.6.39-2+deb12u4_arm64.udeb f81e67ea3d84c1b1adc69f3bd1dfb017 269984 libs optional libpng16-16_1.6.39-2+deb12u4_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEJkN0BnKzGWWW6tS+G5VHrWJmwgcFAmnL+D4ACgkQG5VHrWJm wgdlmxAAzYfpqIHldzenxfep9vKg+4e+cLCKlc4vZNbMsksPGUMCmZbzXiXUHxCj 4Ktl8AsCnc0RhgNsZ36ww+7QotOCC5dMIRlXdKVMS0hE8f5n+i3gQR8PaBazip0E svzaft/ZjuBqNsLdAhC++1j9CXq7zPJ7CG0cnB138YSvAH7gK0Sog17xPXmIeMI+ NIleGXil4iPzOY1+ACEtXsHn5jVYeC5K7nyCnf8mRqyvlq4EaMQ2n0JC3ncGI5ga TXhMSglaVkdLi4r4Gvq8iF6F/OjrH00mrHjSEtCrVjRLWnlQqwL9OJEFWe4tonkE rWty1ckGYIo38RgyXSvvdOQsarK92FyTf2xm0CmCFktOBk16NGOpJQwC55bnfpms IrwcG8bKO6Ve+CJChQgcbnJomTwtKSdsr+jyrsuYMbtcp9zzgD+9tXVLBQ9vvqNM ozBHEphhHj96gvPutlfxmPbEEjxxpxBE/sZDuA6SHHJ9/HflffX34sjPdw2NBvVu 7B3azBDi2EK/d3HXnFntzqxHNx29UOq52Pmrk6tBO5scXGbeajaOyA5RhtGef4Qe qtWPpgT7mMtu/9iZvtXYNd/BUEv0j+VQc7NE9KhbQTr/tyAfHTTwq6rtY+A4OxvE 1bc4VFYTLgFdd9jD9jV1ozoPXD4bw1Bio/pHvQ+Mti7BDcVkXwU= =jyf9 -----END PGP SIGNATURE-----