-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 12 Dec 2025 18:43:13 +0000 Source: glib2.0 Binary: gir1.2-girepository-3.0 gir1.2-girepository-3.0-dev gir1.2-glib-2.0 gir1.2-glib-2.0-dev girepository-tools girepository-tools-dbgsym libgio-2.0-dev libgio-2.0-dev-bin libgio-2.0-dev-bin-dbgsym libgirepository-2.0-0 libgirepository-2.0-0-dbgsym libgirepository-2.0-dev libglib2.0-0t64 libglib2.0-0t64-dbgsym libglib2.0-bin libglib2.0-bin-dbgsym libglib2.0-dev libglib2.0-dev-bin libglib2.0-tests libglib2.0-tests-dbgsym libglib2.0-udeb Architecture: riscv64 Version: 2.84.4-3~deb13u2 Distribution: trixie Urgency: medium Maintainer: riscv64 Build Daemon (rv-manda-03) Changed-By: Simon McVittie Description: gir1.2-girepository-3.0 - Introspection data for GIRepository library, API version 3.0 gir1.2-girepository-3.0-dev - GIR XML for GIRepository library, API version 3.0 gir1.2-glib-2.0 - Introspection data for GLib, GObject, Gio and GModule gir1.2-glib-2.0-dev - GIR XML for GLib, GObject, Gio and GModule girepository-tools - Tools for working with GObject-Introspection repositories libgio-2.0-dev - Development files for the GLib, GObject and GIO libraries libgio-2.0-dev-bin - Development utilities for GLib, GObject and GIO libraries libgirepository-2.0-0 - GLib runtime library for handling GObject introspection data libgirepository-2.0-dev - Development files for the GObject introspection library libglib2.0-0t64 - GLib library of C routines libglib2.0-bin - Programs for the GLib library libglib2.0-dev - Development metapackage for the GLib family of libraries libglib2.0-dev-bin - Development utilities for the GLib library libglib2.0-tests - GLib library of C routines - installed tests libglib2.0-udeb - GLib library of C routines - minimal runtime (udeb) Closes: 1121488 1122346 1122347 Changes: glib2.0 (2.84.4-3~deb13u2) trixie; urgency=medium . * d/patches: Add patches from 2.86.3 upstream to avoid integer overflows - d/p/gconvert-Error-out-if-g_escape_uri_string-would-overflow.patch, d/p/fuzzing-Add-fuzz-tests-for-g_filename_-to-from-_uri.patch: Fix an integer overflow when interpolating hundreds of megabytes of unescaped text into a URI, and add test coverage (CVE-2025-13601, glib#3827 upstream, Closes: #1121488) - d/p/gvariant-parser-Fix-potential-integer-overflow-parsing-by.patch: Fix an integer overflow when parsing very large strings in GVariant text format (CVE-2025-14087, glib#3834 upstream, Closes: #1122347) - d/p/gvariant-parser-Use-size_t-to-count-numbers-of-child-elem.patch, d/p/gvariant-parser-Convert-error-handling-code-to-use-size_t.patch: Fix other potential integer overflows parsing very large container types in GVariant text format, related to CVE-2025-14087 - d/p/gfileattribute-Fix-integer-overflow-calculating-escaping-.patch: Fix an integer overflow when escaping invalid characters in very large file attributes (CVE-2025-14512, glib#3845 upstream, Closes: #1122346) Checksums-Sha1: 06ed9497dbf2311de04f7dec13482b8ffea685e1 84584 gir1.2-girepository-3.0-dev_2.84.4-3~deb13u2_riscv64.deb 118a7eb156cc1378f5366113f960583c96935da4 61448 gir1.2-girepository-3.0_2.84.4-3~deb13u2_riscv64.deb 2c562a427d63082a379c548b3be5a0a46ab44e81 916608 gir1.2-glib-2.0-dev_2.84.4-3~deb13u2_riscv64.deb d8d273abf64619aa3aecedc48a2b2741bb9d8b48 199076 gir1.2-glib-2.0_2.84.4-3~deb13u2_riscv64.deb 5bba660bae9b1b6b8fc066f7d045950938e7d985 292352 girepository-tools-dbgsym_2.84.4-3~deb13u2_riscv64.deb dea2a61d2d8fd4046e5138f411a394fad9d744dd 146260 girepository-tools_2.84.4-3~deb13u2_riscv64.deb 944c1c196965c8cf8261780645e52c1818367e45 15957 glib2.0_2.84.4-3~deb13u2_riscv64-buildd.buildinfo 767a89b6961dcb48b139aa277b8e4d8697dbe700 77692 libgio-2.0-dev-bin-dbgsym_2.84.4-3~deb13u2_riscv64.deb 0996440c1fa8aa64e5384779ac96eeea6c6f8e4f 166004 libgio-2.0-dev-bin_2.84.4-3~deb13u2_riscv64.deb bf679166a45b7e203843b5f2ac95462b671722a8 4049156 libgio-2.0-dev_2.84.4-3~deb13u2_riscv64.deb 18cf6e3d418a027772f0bf6659d2741aa68a156e 310208 libgirepository-2.0-0-dbgsym_2.84.4-3~deb13u2_riscv64.deb 8b0ab7435835a756c1268812ec50e664176c3dc8 143708 libgirepository-2.0-0_2.84.4-3~deb13u2_riscv64.deb dcc1a4278c18ff45b9865be1ba569f5148f91203 441880 libgirepository-2.0-dev_2.84.4-3~deb13u2_riscv64.deb 28bf647209b40085612a181ff17c69a49b0d839d 4312936 libglib2.0-0t64-dbgsym_2.84.4-3~deb13u2_riscv64.deb d6ea3bb4e74fd3a757321428065090279d04f1bd 1527788 libglib2.0-0t64_2.84.4-3~deb13u2_riscv64.deb 70f764cd3a17adef4f4bcfa47333a21e4b4150e2 167284 libglib2.0-bin-dbgsym_2.84.4-3~deb13u2_riscv64.deb 1425ad6f7e820bbbed6eea8c570f015135e4d487 128236 libglib2.0-bin_2.84.4-3~deb13u2_riscv64.deb 3631b9384dccce57e3f9a1a9af36aab2e21d9845 55268 libglib2.0-dev-bin_2.84.4-3~deb13u2_riscv64.deb 198514231a05ab8f217e6d258256e7c7b071d8c4 56056 libglib2.0-dev_2.84.4-3~deb13u2_riscv64.deb 23fc32d370bd95134158cc48bf1de0100e776158 5715064 libglib2.0-tests-dbgsym_2.84.4-3~deb13u2_riscv64.deb 3708b0e9c4749cb815c50888fec943a09d6568c3 2028528 libglib2.0-tests_2.84.4-3~deb13u2_riscv64.deb e5add614ba6bfd99c85471048906fe68758b83d6 2386496 libglib2.0-udeb_2.84.4-3~deb13u2_riscv64.udeb Checksums-Sha256: 653e6602364720cae105616a52638f615188d78e63c151383bd99dad61e6dbc2 84584 gir1.2-girepository-3.0-dev_2.84.4-3~deb13u2_riscv64.deb 0053385bde7d215929b81b79a989f4a473779be6e1f75ce44a30d6043b98a916 61448 gir1.2-girepository-3.0_2.84.4-3~deb13u2_riscv64.deb 8b8bcda197aaf004435ca6b6dbad675664063b0f0e9f71e86d85bcbabe1d7241 916608 gir1.2-glib-2.0-dev_2.84.4-3~deb13u2_riscv64.deb e1d063dced42e8f27e0e8bba08c659ab5bae2953fbc20db6108dcf2a47cae272 199076 gir1.2-glib-2.0_2.84.4-3~deb13u2_riscv64.deb df7298665c920eb6a8a6922f815fc267d10b28653b0938cdc8d15060f8f8a4a8 292352 girepository-tools-dbgsym_2.84.4-3~deb13u2_riscv64.deb 1c4315aa8b424265640830ff891cfee082b0f61c03506a9002c2c006ffb2e45d 146260 girepository-tools_2.84.4-3~deb13u2_riscv64.deb 477a681398782b281f624128fdfbc1ef33c448676d1601ccc177465629a5c957 15957 glib2.0_2.84.4-3~deb13u2_riscv64-buildd.buildinfo f0aa90a3314538badb7995ebc28d17419f1c662147f432aa5d4f83bb483a8098 77692 libgio-2.0-dev-bin-dbgsym_2.84.4-3~deb13u2_riscv64.deb a4a8a1cbe8b4506890b4b212bc3962213ca6e39cdb6d93a9601337baa9b27bf0 166004 libgio-2.0-dev-bin_2.84.4-3~deb13u2_riscv64.deb 20f4675a58aec16003cfbaf5e11542039de09ee24a9a5c3909290bcd5b21c9c4 4049156 libgio-2.0-dev_2.84.4-3~deb13u2_riscv64.deb be6402a2f6ff7da00f39760facc6f259ba4765852c1fe0f01beae49e2e2aeec6 310208 libgirepository-2.0-0-dbgsym_2.84.4-3~deb13u2_riscv64.deb 4eb49d4bfad9296a6bc99ab4dc27d81f5322e12381e0a8c1a7db09bb0ed68bd3 143708 libgirepository-2.0-0_2.84.4-3~deb13u2_riscv64.deb f65120db6575bb444ef987f695a8993585f6dd62aa3aeb794b559961e7bfd45a 441880 libgirepository-2.0-dev_2.84.4-3~deb13u2_riscv64.deb a2a68f5d7b49bea8b3b94c423634f849df02d77a53cdfccb1fe4b888e3bfcb7b 4312936 libglib2.0-0t64-dbgsym_2.84.4-3~deb13u2_riscv64.deb 871f0878240b26721d952d348fdb76b4bcc31ef97a65260e40fd5ae6d5a8040a 1527788 libglib2.0-0t64_2.84.4-3~deb13u2_riscv64.deb 1594e5a472d6ef8688829b0f6a9f90317405756b3e31173f7cfe57c8d4c83d4c 167284 libglib2.0-bin-dbgsym_2.84.4-3~deb13u2_riscv64.deb 2e85d7562dc23e2a8bfcab0dced34bd996f500aa6def5e5963f7000f0d596fc9 128236 libglib2.0-bin_2.84.4-3~deb13u2_riscv64.deb cf45fa44997db587a7d92b5c53d007997db4f5c3f8c4eaf25ed9b120c38d001c 55268 libglib2.0-dev-bin_2.84.4-3~deb13u2_riscv64.deb dd564bda2d07a47d39f283d5dd189dcbf43ea39e0c21572946198086b9116391 56056 libglib2.0-dev_2.84.4-3~deb13u2_riscv64.deb 4dd85f425fb9eafc2089d04808c033888fb1b33cf603ec64ebbc483bddb15b72 5715064 libglib2.0-tests-dbgsym_2.84.4-3~deb13u2_riscv64.deb 1faddf67e29577492d9513eccd51313d85be7def95beeca4897340f6b2e062c2 2028528 libglib2.0-tests_2.84.4-3~deb13u2_riscv64.deb 079c7b5da13a9c5660666ce683d9ad3bf8809d2e934f2fb3ea759005a3709109 2386496 libglib2.0-udeb_2.84.4-3~deb13u2_riscv64.udeb Files: 4b70e9c7ef8ccbebd6e6cc9f5e0eee9a 84584 libdevel optional gir1.2-girepository-3.0-dev_2.84.4-3~deb13u2_riscv64.deb c4bb460d4384511b3ea284d20ab2b3cf 61448 introspection optional gir1.2-girepository-3.0_2.84.4-3~deb13u2_riscv64.deb 4cd4c579df878d9706d0f4454c57dee5 916608 libdevel optional gir1.2-glib-2.0-dev_2.84.4-3~deb13u2_riscv64.deb fdfd21b9c6aa68ef672b1ee20f04c940 199076 introspection optional gir1.2-glib-2.0_2.84.4-3~deb13u2_riscv64.deb 28cedaa89234ffcc1791bf9b998f81fa 292352 debug optional girepository-tools-dbgsym_2.84.4-3~deb13u2_riscv64.deb 39e8c3fae3f34f00e0d36fb9839bef37 146260 libdevel optional girepository-tools_2.84.4-3~deb13u2_riscv64.deb dd8644f960961d0687cf69715702a834 15957 libs optional glib2.0_2.84.4-3~deb13u2_riscv64-buildd.buildinfo 4f862a989b9d320ea3f780bb910d9e3a 77692 debug optional libgio-2.0-dev-bin-dbgsym_2.84.4-3~deb13u2_riscv64.deb d2f5d703c6a69b183f8fc607cef5effa 166004 libdevel optional libgio-2.0-dev-bin_2.84.4-3~deb13u2_riscv64.deb 2ee38149875097acd8279e671bc0dff5 4049156 libdevel optional libgio-2.0-dev_2.84.4-3~deb13u2_riscv64.deb 1ad832ab0c4e4d99ff7fd0d0ea766b14 310208 debug optional libgirepository-2.0-0-dbgsym_2.84.4-3~deb13u2_riscv64.deb 8cb48c7580d3914dc971f868deb5353f 143708 libs optional libgirepository-2.0-0_2.84.4-3~deb13u2_riscv64.deb 52eb0a177b2585067a4244523db754c4 441880 libdevel optional libgirepository-2.0-dev_2.84.4-3~deb13u2_riscv64.deb 504717406f62df94b77225a80eedb7cd 4312936 debug optional libglib2.0-0t64-dbgsym_2.84.4-3~deb13u2_riscv64.deb a84c5c12d25d4eb236f0907379f11ec6 1527788 libs optional libglib2.0-0t64_2.84.4-3~deb13u2_riscv64.deb a426c8527b4a523251d47e24df5811d3 167284 debug optional libglib2.0-bin-dbgsym_2.84.4-3~deb13u2_riscv64.deb 546ea867c1971bf143e4acd985b04638 128236 misc optional libglib2.0-bin_2.84.4-3~deb13u2_riscv64.deb b1c194986c822e01f3cc5719d94239a2 55268 libdevel optional libglib2.0-dev-bin_2.84.4-3~deb13u2_riscv64.deb d89ae12bea612ca9b30b2c3673fec487 56056 libdevel optional libglib2.0-dev_2.84.4-3~deb13u2_riscv64.deb 9eb50a33751e4848a301cba5b6fa41cb 5715064 debug optional libglib2.0-tests-dbgsym_2.84.4-3~deb13u2_riscv64.deb a8721cd12fc42a60dd4e2ccaefdacadc 2028528 libs optional libglib2.0-tests_2.84.4-3~deb13u2_riscv64.deb 21ff74a9d6720c258b6539459485ded5 2386496 debian-installer optional libglib2.0-udeb_2.84.4-3~deb13u2_riscv64.udeb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXZ9jHPkg/vETgMJZlJNduPxUf2oFAmlINs0ACgkQlJNduPxU f2q+jBAAoEsNjJFCPt6Gv9UHQnkCWedOPUU9TL381+rITmWC03mOuRUw9uYVVEwC OiQHux1n7O2cvtj0aMUM2mN94sVPC80l+pjuLP+SgCSVOMvsMfD2t5nmDh0lfG39 rz14EpOvJYVbD5st23RjIuO+SsB0wKEtVKYV1/4dcF/pMftCnFMK8tx3THBWZGXY YJhWruP7xU1Xya9wM8QeXyem5i94L1EA9Mytm3AYJ3l9+wUoZKiuFmnhFgiEPGuc CqA4fZGvNnZsH4cbPBXa5vCNyv/vv+0yZrNmVKMCo0Zf3m0lARH8T5/7ZVjf9TDE YmzvsNQLKokQUn2D2CYeMfAT76sNpnNjLWW3fCqvEk27tg57PwZ0FWyGHZCHxMmL nDCE7MXNRVcVmfCZSr8EfdKZiT+o/B+11bNHIhhwRI2lAlJ07VpO0GGkriFH8Kso DXgga0sN0zqxPEQ3i1KFGMaqQvKBfCOSPASHa3uMAYiP6iuAub5ujoWIVoFVGbEz 02El5MHck84n9DbZPUmq2zk99WNhschtNs1TCbaiLPE6LGDEHiCAUrCQ/hTapuJp 6bs5sCoXjjBXc/n6LV1KNhR+rOH2NRI/f6l2l1Xqe8FDeooM8Zr+/dhIZiUeuneC fJtH47sgzs/cPnFSV1n5C8+grBjxQzE50tozg5OkAskvzDLJemI= =4y8l -----END PGP SIGNATURE-----