-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 30 Mar 2026 20:59:03 +0200 Source: libpng1.6 Binary: libpng-dev libpng-tools libpng-tools-dbgsym libpng16-16 libpng16-16-dbgsym libpng16-16-udeb Architecture: i386 Version: 1.6.39-2+deb12u4 Distribution: bookworm-security Urgency: medium Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Tobias Frost Description: libpng-dev - PNG library - development (version 1.6) libpng-tools - PNG library - tools (version 1.6) libpng16-16 - PNG library - runtime (version 1.6) libpng16-16-udeb - PNG library - minimal runtime library (version 1.6) (udeb) Closes: 1132012 1132013 Changes: libpng1.6 (1.6.39-2+deb12u4) bookworm-security; urgency=medium . * Security upload targeting bookworm. * Backporting upstream fixes for: - CVE-2026-33416 - Use-after-free (Closes: #1132012) - CVE-2026-33636 - OOB read/write on ARM plattforms (Closes: #1132013) Checksums-Sha1: 04817de7c3556be340c1de50ed770510b6ba2e1d 368404 libpng-dev_1.6.39-2+deb12u4_i386.deb 15ecee58aebd2416826ed23eeaa60c4fcf227116 49292 libpng-tools-dbgsym_1.6.39-2+deb12u4_i386.deb 73a41145cbc7267ce429944de3b8e8704a2092fa 127500 libpng-tools_1.6.39-2+deb12u4_i386.deb 6c31e6d604363b12a0f5dc066668aebc734c8e1e 7467 libpng1.6_1.6.39-2+deb12u4_i386-buildd.buildinfo ef4581211e39fb3170c5fbf62f5f6021f5352408 214960 libpng16-16-dbgsym_1.6.39-2+deb12u4_i386.deb 322d51ba2f228687a5923f4b355e93db4c330ccb 101308 libpng16-16-udeb_1.6.39-2+deb12u4_i386.udeb 1dc016710b5052c4b10a77b2ae903788a3f20064 284320 libpng16-16_1.6.39-2+deb12u4_i386.deb Checksums-Sha256: b3fd67520a36c05058ef3244ea944d3658be8a08be40e9dc5ee5289a71d80247 368404 libpng-dev_1.6.39-2+deb12u4_i386.deb 5a12c8a6a15ff48fb6dab70f1d58535614f83f34033baabe358078ef07f2825c 49292 libpng-tools-dbgsym_1.6.39-2+deb12u4_i386.deb 119c2a39167d0c533e900dc101bb5dedf33cb6cfac5ee5c627bfa81290255b3f 127500 libpng-tools_1.6.39-2+deb12u4_i386.deb 9ac6a03a0227a1ba690ed39f3421e6628084f2c355f2f4705f121e6771f89941 7467 libpng1.6_1.6.39-2+deb12u4_i386-buildd.buildinfo cbbe5ba793041724f7089dd389b0c6bf7fa8f2bc5085a05cb3ff594a751ee320 214960 libpng16-16-dbgsym_1.6.39-2+deb12u4_i386.deb 5ff5486ad1de08768c4e96ba0f0a9fdfc40a2ea1bd7eaafd816b0076f43ad263 101308 libpng16-16-udeb_1.6.39-2+deb12u4_i386.udeb 0cbe3778535a4d0d183a362e6950ebf6bc4637aede8c589525957968d8f2a47e 284320 libpng16-16_1.6.39-2+deb12u4_i386.deb Files: f179ef37aa079cec15e3d6641b7dbdce 368404 libdevel optional libpng-dev_1.6.39-2+deb12u4_i386.deb 4a39ac9921849cef4cad46367e8a21ca 49292 debug optional libpng-tools-dbgsym_1.6.39-2+deb12u4_i386.deb 58dab4dbe6b486e03fe1fa2cc2d77645 127500 libdevel optional libpng-tools_1.6.39-2+deb12u4_i386.deb 49f504e092af1275c8911cd8aa671988 7467 libs optional libpng1.6_1.6.39-2+deb12u4_i386-buildd.buildinfo 1c01a35f6a14b2efa93075712b1d78c1 214960 debug optional libpng16-16-dbgsym_1.6.39-2+deb12u4_i386.deb 06a3525ef2fc58755b326ee5367a2596 101308 debian-installer optional libpng16-16-udeb_1.6.39-2+deb12u4_i386.udeb 919b6cfb5938ee2354e8f2c473054bf0 284320 libs optional libpng16-16_1.6.39-2+deb12u4_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEPAUaMA0H0rOy6qBWf2INRiCdaWIFAmnL+FEACgkQf2INRiCd aWJo5g/9EX0Q6/hFIlDdWhjaf6iwJM9QXwUzUlFvPsTLmT48Uc9jkhhLEVXt5SnT zCpPDvfiBxC6iJi7yzlZK2FLaP+IrMrVGCpq47pvUOqxjU7Ey/d42q6GfrK2ytxT Hzo3sIdh7PRv2nCvJTHZRPBV4OkjeXDjQmK36kv+s26rJel65siG5tOnd6vXWg0C 9tkcjLt4ncEqG8MyFmxuAbY3g0/yuzGszfjP0uLxLYuGPH8u4Z2QNoPRPZ2wJZ9k bZtoEdFbzcDDotpu0fDtNmStSSnNj8c0TuNNLdOspe3GrSzJ/n1YYAbfhFfjWdp7 GIHWf+fiaqzDCrXZJsFnGEx4ukz+YDl5MTzYv1whuM56nJ+S5T1mRNnL42Te7R0Z g04tfXOEEu/a0P9aHeywhHxgErby/0G4eC24xwUyhjltz0qrnm/e78xDQTxZim0O FH/07/c7oefEslbIm4V88X7XysQtfXZDdZ6CCLjYfdQ4Uoi8ESqbD8R2DpDIzFwF Hv5HNZsuzLIstRtzSm3Vbe2Onmo32mOyLkecNHkAeukAg7UNS3Z1T0BlMLXtTGU0 4x+ly5OWFZl1GemMKffITXLnsEEzkSVmuslZaZZGP0nPKaXTysSje/G404xc3KOP w5doyo0tJGsxumATSnlljM21Ue0gHONCC/YwoBAzh3rIlMy4uoM= =oAvt -----END PGP SIGNATURE-----