-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 30 Mar 2026 20:59:03 +0200 Source: libpng1.6 Binary: libpng-dev libpng-tools libpng-tools-dbgsym libpng16-16 libpng16-16-dbgsym libpng16-16-udeb Architecture: armhf Version: 1.6.39-2+deb12u4 Distribution: bookworm-security Urgency: medium Maintainer: arm Build Daemon (arm-ubc-05) Changed-By: Tobias Frost Description: libpng-dev - PNG library - development (version 1.6) libpng-tools - PNG library - tools (version 1.6) libpng16-16 - PNG library - runtime (version 1.6) libpng16-16-udeb - PNG library - minimal runtime library (version 1.6) (udeb) Closes: 1132012 1132013 Changes: libpng1.6 (1.6.39-2+deb12u4) bookworm-security; urgency=medium . * Security upload targeting bookworm. * Backporting upstream fixes for: - CVE-2026-33416 - Use-after-free (Closes: #1132012) - CVE-2026-33636 - OOB read/write on ARM plattforms (Closes: #1132013) Checksums-Sha1: 4d682e1deaf64f0cdfec798f581542ffa4b7e5e5 343612 libpng-dev_1.6.39-2+deb12u4_armhf.deb 682e4b7a3787c645d0ef4e80b7e53d98b672f6f9 48120 libpng-tools-dbgsym_1.6.39-2+deb12u4_armhf.deb f165b8d0a788194f66ecb32b2e89efb8362e7d31 124784 libpng-tools_1.6.39-2+deb12u4_armhf.deb 21327e78cc8c1852d6d142b62f375dc574fcd394 7379 libpng1.6_1.6.39-2+deb12u4_armhf-buildd.buildinfo 1abb89026c7aac2cf7a5332dd6064e415cab8ba9 247660 libpng16-16-dbgsym_1.6.39-2+deb12u4_armhf.deb fdec3b69fd0b8f966986a60776e63acd893af76f 76644 libpng16-16-udeb_1.6.39-2+deb12u4_armhf.udeb 8cbd85b1491f47c3ca6233193589737572e93455 260276 libpng16-16_1.6.39-2+deb12u4_armhf.deb Checksums-Sha256: 675e8e1b49de9b2991cf147083d9e917244f23e2c758f6b78b19aeddb67202c2 343612 libpng-dev_1.6.39-2+deb12u4_armhf.deb 1da9af1067d286dcedc4a26855895c8409bb2779a8240b374525f853e1b791a7 48120 libpng-tools-dbgsym_1.6.39-2+deb12u4_armhf.deb def17c9f20620e4ff8b4bd4f2d386037d02f283507ef8ecc244a59fe008cf46c 124784 libpng-tools_1.6.39-2+deb12u4_armhf.deb 1257abd757b50d8f07aa891482fd24fbccb9a3dd91a0dc103ea522f08365aede 7379 libpng1.6_1.6.39-2+deb12u4_armhf-buildd.buildinfo b4d3860ccbf1d19b23e763bb59ee91716c2deafad86046df66967a073873f348 247660 libpng16-16-dbgsym_1.6.39-2+deb12u4_armhf.deb 3054de97ecf4b7969e50c5ad6f8fef154ca56a97d96dc743fc66c5656f4af077 76644 libpng16-16-udeb_1.6.39-2+deb12u4_armhf.udeb 0ba485045a179b2abd9cee230042bb920eb50fae3a5783e6a347331754b3ff20 260276 libpng16-16_1.6.39-2+deb12u4_armhf.deb Files: 23ebed195dd131ef1bfbf9dad2a1c85e 343612 libdevel optional libpng-dev_1.6.39-2+deb12u4_armhf.deb ccd275b74bf661165a87ec672b2d3c4a 48120 debug optional libpng-tools-dbgsym_1.6.39-2+deb12u4_armhf.deb 3a6feaae8aaca83c07515c9e1498a6f0 124784 libdevel optional libpng-tools_1.6.39-2+deb12u4_armhf.deb bbca42098ee9736b15fb05c590371b32 7379 libs optional libpng1.6_1.6.39-2+deb12u4_armhf-buildd.buildinfo bc651192b8be14e83dc48873a5976ffa 247660 debug optional libpng16-16-dbgsym_1.6.39-2+deb12u4_armhf.deb 04ddcd47b2c958a57b94a5776fcd335b 76644 debian-installer optional libpng16-16-udeb_1.6.39-2+deb12u4_armhf.udeb b0a5db17c8aed20cf3a00d0cc00d78e2 260276 libs optional libpng16-16_1.6.39-2+deb12u4_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEiIG3Q3DxwDgRKKeyLRECdjCZQkcFAmnL+EAACgkQLRECdjCZ QkebkxAAm5KQv58sLEt53b495H3PkG/yfWhNxyggR57Ca7KWzmkXVPWBFIVd28qT OVXGW1le/4OD3whKtnpkzAfjcF0tRNhMT6gaOGTrJdoDVeCbKRoL3IGucBQiPYAT EEoO+cf/d5IzNYFzej6iRh4fxcAco3LHJNSFQH11VYC93k99RtaVTfAsoymYOZwa KzwQlDiYKorN/pkwrcGXeE+waSUqHJGObaVPu95UpkfOweUKUhu5BIt7fBOZLmkR ghVgh+Y96K+zGQkTiAdTbEGG/ruLvckBzOEBHcxm1uD4TxSscMXYKKeYqGb3Awxb +d/RO1BwWSiQSnKXGrMLGgXhpYmnO5BOVxEayfIO5na+eb+ZLlIIORvjbj+5l8e/ B1kmbYmPpbkg/TTQgOL/CzRhsbO1/SCkPG+tE/n8aehvoKnhvJCT2l5qce8ufknO 8nAo5TCpKpm/womNkMN7OR63q4wcCmL04Sck915PRDI+Gvt/TZRxHV5vDsa1ay5k WK+9aI7Cqj8xv3wC7TuTj7Vy+feAYdNjbxloqATDMgR6LKDH63Q38tOMmYvUVHUe 563KpIAD5u6h06t5IN5bJo/9ke87RyNOYrAYNTNrHYhHZSuoifTmU/idxpdZPS6J jZ/60fA6HMZA5jsx2XE0J5DInAHh3TAjwUNAP39HpOj7POR7k2Q= =AYrg -----END PGP SIGNATURE-----