-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 30 Mar 2026 20:59:03 +0200 Source: libpng1.6 Binary: libpng-dev libpng-tools libpng-tools-dbgsym libpng16-16 libpng16-16-dbgsym libpng16-16-udeb Architecture: armel Version: 1.6.39-2+deb12u4 Distribution: bookworm-security Urgency: medium Maintainer: arm Build Daemon (arm-ubc-03) Changed-By: Tobias Frost Description: libpng-dev - PNG library - development (version 1.6) libpng-tools - PNG library - tools (version 1.6) libpng16-16 - PNG library - runtime (version 1.6) libpng16-16-udeb - PNG library - minimal runtime library (version 1.6) (udeb) Closes: 1132012 1132013 Changes: libpng1.6 (1.6.39-2+deb12u4) bookworm-security; urgency=medium . * Security upload targeting bookworm. * Backporting upstream fixes for: - CVE-2026-33416 - Use-after-free (Closes: #1132012) - CVE-2026-33636 - OOB read/write on ARM plattforms (Closes: #1132013) Checksums-Sha1: c4520fb84d71d6bcf0e7f04efa1aa34b08587cf1 344504 libpng-dev_1.6.39-2+deb12u4_armel.deb 181db8f224276a7680181a65256ef57036638c01 47612 libpng-tools-dbgsym_1.6.39-2+deb12u4_armel.deb 17fb1e24de5a376f00667661599fd15dc141a4fd 124968 libpng-tools_1.6.39-2+deb12u4_armel.deb 5d8b7e3de45a12ddefa0deb2fa49feeeeffcae83 7377 libpng1.6_1.6.39-2+deb12u4_armel-buildd.buildinfo 89358a8dd2058b590f435a55cff12d3e58459706 244452 libpng16-16-dbgsym_1.6.39-2+deb12u4_armel.deb a32328db398e9b72c81e0b9903d782f79b10db02 78536 libpng16-16-udeb_1.6.39-2+deb12u4_armel.udeb 378229de8bf38b29869c2dd69e44b1f6ba8ccf18 262208 libpng16-16_1.6.39-2+deb12u4_armel.deb Checksums-Sha256: 0f87200badc0564c2da07c3c81bc2504c9c3a19e55f3d01ab0f41dc7976ce421 344504 libpng-dev_1.6.39-2+deb12u4_armel.deb 6f60dbcd44829f6403deded652528902424e9a83ee7ad913f8a8c57a8d8fb458 47612 libpng-tools-dbgsym_1.6.39-2+deb12u4_armel.deb 5374883b10aeab83d5ca0ac1d5a54911cca110e3f79ad87ad987dced281cd937 124968 libpng-tools_1.6.39-2+deb12u4_armel.deb 85ec837e9b4e1f808e289335567e0eb1ef167a8da93af02f4f1a4e4dd4f7c487 7377 libpng1.6_1.6.39-2+deb12u4_armel-buildd.buildinfo 1df78c815d4d797e4cb7f478c90e994e574e7e809672f19f2ab2bbaa28cededd 244452 libpng16-16-dbgsym_1.6.39-2+deb12u4_armel.deb 5f7c760144adb1707b830da34d3d57e3f04f8a447ea8506f451fa7bdf51da2cc 78536 libpng16-16-udeb_1.6.39-2+deb12u4_armel.udeb 3e7bd2dd8ef8c9bb92676c864f65dc1201efdf5c03a9c22de35f63858c182109 262208 libpng16-16_1.6.39-2+deb12u4_armel.deb Files: 2e9d358726d09f87414a3825401ef356 344504 libdevel optional libpng-dev_1.6.39-2+deb12u4_armel.deb 204a9f717671e2ec7da6c5d7188928b2 47612 debug optional libpng-tools-dbgsym_1.6.39-2+deb12u4_armel.deb 17a77116827199a5f45f74cd919739e6 124968 libdevel optional libpng-tools_1.6.39-2+deb12u4_armel.deb 094e5316bdba745b9583d6c063855f84 7377 libs optional libpng1.6_1.6.39-2+deb12u4_armel-buildd.buildinfo 7b85a67e5aa1a4cb39593d05d0c87959 244452 debug optional libpng16-16-dbgsym_1.6.39-2+deb12u4_armel.deb a20be1431c46bb8b96e52cde50f4bec0 78536 debian-installer optional libpng16-16-udeb_1.6.39-2+deb12u4_armel.udeb c7b4c8b1fc016fb7350ffb3eee047680 262208 libs optional libpng16-16_1.6.39-2+deb12u4_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE2kd8oHy+LXk/nybqvzDqKQSGl8UFAmnL+FEACgkQvzDqKQSG l8XMzhAAtXbEpSKT0KM+8lOBQyzPwRA7YP0z7WWfJ+7e03AVIPdft6WDE7K2M/BF VXhrMG700Wh0Ea0vpAsMVRbTmiEdUTMOChl4LaUXR3hLCplXT9G28EiQs9Z9mHXO LrQztB78LHr2v7fRFTln6Niq5dl/8ZEmyWMQxBeN+mYF4c67kdQsJytRPIsHXCtj WleSgBFMGh2kBm8xOX6pqHvyG/cMZjLBuDMYIpi3EYsn+14hD6hDFjevB4QIulPR t6khiXWTKEdsYZ/vFlA5F/ImmGbDLmL4GoD/z/VVFVijGYySwFOTzwBbnLnu965M 7umiLub7JRe6Pe7cCU5VkDVyzJnatsX8zrDak2Nr/1WTVTOp0r2rudOf3yUGM1HC nv4OC5ix+evpAjNvoLyYkdkrehAAv9k5dqkcy36IVlJJNdr+QK81GGvQz+qxa3J4 By4yd0L3Es/vJBd2pyJWOaGpFGBu+veJD1HMQeA/sIIbtlxRjXwjZThC1aAvwFOI +YAgiXAB4x9NMNQhe7x6/M4gHbZ77/K434ff2qc7dAm7u5fuCYP9LcgJKwKr22uU QlYPcp/oH+gtmMAXRLjZzARFTYcKgxqBcNail3SkrWXk2JA+WtICb+VS9PG4Dc1i gf8ywP9HW1fRwLT8KU8lLgc+EQ7FhoudGn8Q5xf8z6Hja11bkSg= =PqqW -----END PGP SIGNATURE-----