-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 17 Apr 2026 07:48:04 -0300 Source: libexif Binary: libexif-dev libexif12 libexif12-dbgsym Architecture: riscv64 Version: 0.6.25-1+deb13u1 Distribution: trixie Urgency: medium Maintainer: riscv64 Build Daemon (rv-osuosl-02) Changed-By: Emmanuel Arias Description: libexif-dev - library to parse EXIF files (development files) libexif12 - library to parse EXIF files Closes: 1131116 1133922 1133923 Changes: libexif (0.6.25-1+deb13u1) trixie; urgency=medium . * Team upload. * d/patches/CVE-2026-40386.patch Add patch for CVE-2026-40386. - An integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs (Closes: #1133923). * d/patches/CVE-2026-40385.patch: Add patch for CVE-2026-40385. - An unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. (Closes: #1133922). * d/patches/CVE-2026-32775.patch: Add patch for CVE-2026-32775.patch. - If the exif_mnote_data_get_value function in MakerNotes gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow (Closes: #1131116). Checksums-Sha1: 7792a6559390db66bffe4fb5de1fa19e98922029 182888 libexif-dev_0.6.25-1+deb13u1_riscv64.deb 713b0d04adabee7c0dbd36bf82309ccc82dbfeff 128328 libexif12-dbgsym_0.6.25-1+deb13u1_riscv64.deb 519d0be31c79b33b081c54d060faa780cc6dd093 418008 libexif12_0.6.25-1+deb13u1_riscv64.deb 5d4e3c395c0488c160d632e53f8e7464eae97d99 8359 libexif_0.6.25-1+deb13u1_riscv64-buildd.buildinfo Checksums-Sha256: 26d83a37e9333245b6afc35d57ad0fd64b395129c5041912e9e190ee78af673c 182888 libexif-dev_0.6.25-1+deb13u1_riscv64.deb 23c6e3a1e01c39f0989f7140dadebd3ac6a88f3a2110d89ce1b02f14fdd93d81 128328 libexif12-dbgsym_0.6.25-1+deb13u1_riscv64.deb c87455c1786dcdd6cade93ad26d663cce846b0b35c14802468324f213e764559 418008 libexif12_0.6.25-1+deb13u1_riscv64.deb 4fb96d10d1a480cd6e7d4c4e3771690d0650b1c614b0255d1944bfff4fd4783f 8359 libexif_0.6.25-1+deb13u1_riscv64-buildd.buildinfo Files: fbfde8e0631ad91988b5cef3803e8db6 182888 libdevel optional libexif-dev_0.6.25-1+deb13u1_riscv64.deb 56be7fc4fb74a8515bf47f54f4c1ef6a 128328 debug optional libexif12-dbgsym_0.6.25-1+deb13u1_riscv64.deb d5d9e624581fc7803a00f71fbf075ca6 418008 libs optional libexif12_0.6.25-1+deb13u1_riscv64.deb a72997456fc2af34607e04752aad9156 8359 libs optional libexif_0.6.25-1+deb13u1_riscv64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE/AxPdLOtOshqz3vw/Fc5EAGpa+sFAmn/N8oACgkQ/Fc5EAGp a+uG/w/8CieTGy1bUxa+Z6gvpQ72YUeT274coH73zo+v+vCwXTcVW16jDK2U2acH buGFRgUns3/39TXuKliV4OsqZSVjrLlMcS67Fwe411276Neb+VxpTOcH3mWBPmrw jEqAPySO53jquje1jEhQ0hnLRniGCHQE4Lz2TiGxp6pIrUFNQS4r/nDq4vnJ/d57 9mi43Iw1a9V3F+bX6kOUHBbXKdczSeGT9/kF9hgq0EMHQw7fueAfdu/iOj5zP+/9 DTsPXluVEMpTwpyt+vaFa2LkI33rqINyvNElZ8P481ZqgB0LbHZRsPxsTeA2UZj9 kU134BYLqHUoRyWdtd6AdMONDu3LYxP7+fL9mQNy+y8TlXxm//6Lw6Miha1m7aiD KfflEliU08zENGk1zidyWmAVTF51cP4XbeM+IUchm2dUu9ZgY2SEPjFJjuqoKZi6 HdU4ZjrxTJiyLwIXqdyCbAyT+AXS/d5z7c1rz12Nobp1EBQx9ZaRW2VwhjqG69xz 8DjptYPUox4MksgTng5a+PJBzXPyinj/BGt9Vyv8ufmP9Wf0GNm8ldMFyXvanZlu yNqKWORQFEIs44GUaQNSSSTgiYMiEyIYlyaB+/weeE5PVOlBhPq+tOTHlEKr5zZk hvDaxnKGyohQ7kjbT9JqY6zu94DWvEecJZRlcy504lU0/XmLw9E= =BPb5 -----END PGP SIGNATURE-----