-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 08 May 2026 14:30:14 +0200 Source: libpng1.6 Binary: libpng-dev libpng-tools libpng-tools-dbgsym libpng16-16 libpng16-16-dbgsym libpng16-16-udeb Architecture: armel Version: 1.6.39-2+deb12u5 Distribution: bookworm-security Urgency: high Maintainer: armel Build Daemon (arm-conova-02) Changed-By: Tobias Frost Description: libpng-dev - PNG library - development (version 1.6) libpng-tools - PNG library - tools (version 1.6) libpng16-16 - PNG library - runtime (version 1.6) libpng16-16-udeb - PNG library - minimal runtime library (version 1.6) (udeb) Closes: 1133051 Changes: libpng1.6 (1.6.39-2+deb12u5) bookworm-security; urgency=high . * Security upload targeting bookworm. * CVE-2026-34757 - Use after free. (Closes: #1133051) * Cherry-pick upstream regression fix for previously fixed CVE 2026-33416. Checksums-Sha1: 23a0203bc408044bfa4daa49e5f55d520703526b 344880 libpng-dev_1.6.39-2+deb12u5_armel.deb 467db383ef739dee0fca3496bd135374716fa9a3 47612 libpng-tools-dbgsym_1.6.39-2+deb12u5_armel.deb e0ba21b2e036e79326d52f4e1b8b94e1aea0ba28 125088 libpng-tools_1.6.39-2+deb12u5_armel.deb a697b490c9a10ce2c35a7fa6c3fc4908e6f49caa 7393 libpng1.6_1.6.39-2+deb12u5_armel-buildd.buildinfo 5c0e0d255f11189bb5b8abb8e12c59c27da7e16e 245316 libpng16-16-dbgsym_1.6.39-2+deb12u5_armel.deb d526a2d3d4c26a428bae1af92ea085f289a2d58c 78780 libpng16-16-udeb_1.6.39-2+deb12u5_armel.udeb 1e3d9741863147d43ef8ac1d54da24cb4b30a5c0 262488 libpng16-16_1.6.39-2+deb12u5_armel.deb Checksums-Sha256: ae451c30e430f9852791fbb096cea7bd61d223e511722a10876fddce3db60574 344880 libpng-dev_1.6.39-2+deb12u5_armel.deb 3275c9004e8f8fce31b27750e3e1e70898aa712345294df616730d2848d2a512 47612 libpng-tools-dbgsym_1.6.39-2+deb12u5_armel.deb b30eca089eff61ec8e822d66cb829862f9175ed6f3c0273fc9a078163d4da474 125088 libpng-tools_1.6.39-2+deb12u5_armel.deb 68f91a7f1a15f6b6cb54b11ceefe66ee038708705459c9b7e09ef0c23afe638c 7393 libpng1.6_1.6.39-2+deb12u5_armel-buildd.buildinfo c5f68023b24b9ce336a254b20a378031c745c8a424c939a5e40253d866170b93 245316 libpng16-16-dbgsym_1.6.39-2+deb12u5_armel.deb 8205b361fd2a60e3be12db3eb4b42c313bb50744547b9ff3b8382c71e2afbc61 78780 libpng16-16-udeb_1.6.39-2+deb12u5_armel.udeb 7d8b911743750ef41ce0823f14c0ad18a71581de4c74bac7bf1afcd712275f05 262488 libpng16-16_1.6.39-2+deb12u5_armel.deb Files: f2ae549e426a8c068c82bf5b9859492d 344880 libdevel optional libpng-dev_1.6.39-2+deb12u5_armel.deb 8aa1bf0a482f0c193bb0150a7a5a17f1 47612 debug optional libpng-tools-dbgsym_1.6.39-2+deb12u5_armel.deb 0b19a4c0236764721f4963f25b1455fb 125088 libdevel optional libpng-tools_1.6.39-2+deb12u5_armel.deb 2c22f4edb86f3acdda479f661996db60 7393 libs optional libpng1.6_1.6.39-2+deb12u5_armel-buildd.buildinfo 717ad8d32f533cf671d52d827a32a6a2 245316 debug optional libpng16-16-dbgsym_1.6.39-2+deb12u5_armel.deb a57769d1ae7a9e36ef826870c344707f 78780 debian-installer optional libpng16-16-udeb_1.6.39-2+deb12u5_armel.udeb f6083e55e41644beb168f0de10bada5c 262488 libs optional libpng16-16_1.6.39-2+deb12u5_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEWHj9K9pO9l4btbD1OQKMdMnEH5MFAmn+D2sACgkQOQKMdMnE H5O2cRAA5HAZ66M501CowcR7S5dSqfeb78a1o5tjAXUt/njNdKk+S9OPR+wRLIOq JZbPsTzKvywnUEgYnLAf1GU1wmqcJ0Wf28NLkKjHjkbjh2qfNylwKew+du83z8RD zAdYGejrX9v8dTGTIE0YCnMYkEph8HAhh7XjN9NNyb6+XqYW5oMrUbSzHzAYvmGW AAk5dwtNokqrgmW0/Qm+A2omqS4JQcePGnCbIypJcCqE+xVffo78QM8SPoqWUmSr 44UHTsChF9LTMIhg3qXNAnHsRz2f6zV+40nu1HvtRHDcFSW8ikBs/NiXYlRU+fRR H/FCVWqtQPrOOVnudkSt6H68ULsDDCn6M68sdev7H2semLaBhjHixUH3FgxKjFvH WlWLgLibKAC69L68qZOWoq0k9DeuRN84paKJTbhEEMAwFCY62YuNtM/0QWdZzAIQ ABnEjqYnIu2CkWHl/Fk8DLHml0ykh6Rh2J6dOBqHWz2Nsk6TZlAVoJ/ym7YJLWFS HnYcd5wB2hQujZ96pX5tavPuCOZOn28hXDg+jxNgI2lDiRpkJPPPsmlpUIN/IrJW VkZWNA8WtfW6osJVHqbjg9tLR5B06mnxgaiMaEezfLKtsU7EZ2jloY9Ap68xYoKZ n6jnEAd/eM7SBUZgnNTG5O0z0zeixi3IyqZj6cy7FSKo+37HkiQ= =dfWR -----END PGP SIGNATURE-----