-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 08 May 2026 14:19:08 +0200 Source: libpng1.6 Binary: libpng-dev libpng-tools libpng-tools-dbgsym libpng16-16-udeb libpng16-16t64 libpng16-16t64-dbgsym Architecture: i386 Version: 1.6.48-1+deb13u5 Distribution: trixie-security Urgency: high Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Tobias Frost Description: libpng-dev - PNG library - development (version 1.6) libpng-tools - PNG library - tools (version 1.6) libpng16-16-udeb - PNG library - minimal runtime library (version 1.6) (udeb) libpng16-16t64 - PNG library - runtime (version 1.6) Closes: 1133051 Changes: libpng1.6 (1.6.48-1+deb13u5) trixie-security; urgency=high . * Security upload targeting trixie. * CVE-2026-34757 - Use after free. (Closes: #1133051) * Cherry-pick upstream regression fix for previously fixed CVE 2026-33416. Checksums-Sha1: c0df68455c01a3aa60e46bd22ffad9e27d36c453 374524 libpng-dev_1.6.48-1+deb13u5_i386.deb 80dbcf47266a3ed8d0d59b3f477f895ec8c6d3ce 49052 libpng-tools-dbgsym_1.6.48-1+deb13u5_i386.deb 2a9d556d1f1a9086041d3c9797676906567a3fdf 131116 libpng-tools_1.6.48-1+deb13u5_i386.deb f3d432339c185502377c69f6232c9086e30c297c 8052 libpng1.6_1.6.48-1+deb13u5_i386-buildd.buildinfo cce8156702c83e695cedaa642d38a26a77bc3136 102356 libpng16-16-udeb_1.6.48-1+deb13u5_i386.udeb 1780b2ee5e1dfcedba48147619325ac861cc19ad 218576 libpng16-16t64-dbgsym_1.6.48-1+deb13u5_i386.deb f7c95f54d0347e9908284cb1a7dfb128f3657331 290060 libpng16-16t64_1.6.48-1+deb13u5_i386.deb Checksums-Sha256: 901cac58a4b56fb8516a3e16f51fd7b1183075bbf391c9de6c452a808ffad82a 374524 libpng-dev_1.6.48-1+deb13u5_i386.deb 34b16ea4e7960223ceee55125d9c0e42ffb0cccb7b1a6c85825e6137330598d9 49052 libpng-tools-dbgsym_1.6.48-1+deb13u5_i386.deb 9a6b59360a073f560f7bce2ffcc06e193ba95f28f89fda41c3219326975e5a94 131116 libpng-tools_1.6.48-1+deb13u5_i386.deb 90bb9b1e414be38da64a5be210da7ad70ba38ca58fcb50fc32bd4242c02ee265 8052 libpng1.6_1.6.48-1+deb13u5_i386-buildd.buildinfo f4ffd4bd40f0cb3ea808394ef5123e28b79a6084dee2544c3823c147715d7df5 102356 libpng16-16-udeb_1.6.48-1+deb13u5_i386.udeb 793900f76ad770fc393ca8bac20a4a651169a4f3380570ceb0269ed39594eb36 218576 libpng16-16t64-dbgsym_1.6.48-1+deb13u5_i386.deb 907c103a7d17b2b39661f93a9f4e439cf5fb4ac1ee03c9d3cd2243d3f82e8970 290060 libpng16-16t64_1.6.48-1+deb13u5_i386.deb Files: 500ae71f5fc8139bf3d205f9300b592b 374524 libdevel optional libpng-dev_1.6.48-1+deb13u5_i386.deb 57465e7e57115a233492e28bb7662547 49052 debug optional libpng-tools-dbgsym_1.6.48-1+deb13u5_i386.deb f7aab1069b86530a54137cfccdc5fd3c 131116 libdevel optional libpng-tools_1.6.48-1+deb13u5_i386.deb 50aced30aa4f0a70d894e9ddbce48a38 8052 libs optional libpng1.6_1.6.48-1+deb13u5_i386-buildd.buildinfo 947f318e3f87770272be101b26f8b62d 102356 debian-installer optional libpng16-16-udeb_1.6.48-1+deb13u5_i386.udeb 5894f01f0deca6b03bf27c98b4121097 218576 debug optional libpng16-16t64-dbgsym_1.6.48-1+deb13u5_i386.deb 98ba32a555f3e374a7197044ab3595a7 290060 libs optional libpng16-16t64_1.6.48-1+deb13u5_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEPAUaMA0H0rOy6qBWf2INRiCdaWIFAmn+D5wACgkQf2INRiCd aWKkTg//TbLpC1W+7cLzrCrGGMh2W17cd8rZOGCYPLhfmMThO4g6hktJrwlyWeSq tCa7zo9SsipD/y/H/oMmIYzwFg49PH459qqlivQ8/dAEenj+pCjNze9Ol4nc/UoH pNNVcGv3IHsWfeNrpTrtbnMlWDwtUi4hT8Vbh4SujLuioecHjiGYTlT4blILAsWw ULgcCix6N3r22nDZnHbMZe1HtNLdXGRlXChn4zK8O3yJAQxoGKO7p9wpFmfR+elO 6WyoxnSqeNB4wrb96DUhH17WwKR3dMnDiyflNO6H5K95MRT9UF9ABgDQF8dQTvYc ruXRgquUywPqI3FjG/KSge4Gq3JxnnlZyB2b804SAvQM10jtpKHphlkFmFTGgnC9 BzA66x+miQf2okmfHbLWJx4R1Liw2+EQmhMTuxUz6yoJ+rNdhi1mglVc+ufR8ftE bYe+62nKryryf+y/VP3WPqAzSe4I3mKRfBcVNNJmjZvNJfbJ83F/QLOwjbaO0zbq TF5QuxOXnYJH1gVblNI8d1ed3xxOcfXUOIR57/dTlVWekC0gulbUcXMGdOg4tVkQ bVQpnu/AZvGRvFUQBk7hYHZD0wDqGi+BpJ5C/JYFV5jD/EguTWg5QDOVhm6Qw9NB szF5ZnHxGZgPs/ggrOExmcMQb5qLzMLm/YRX35StnP8lRiAcRlk= =xOmm -----END PGP SIGNATURE-----