-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 08 May 2026 14:30:14 +0200 Source: libpng1.6 Binary: libpng-dev libpng-tools libpng-tools-dbgsym libpng16-16 libpng16-16-dbgsym libpng16-16-udeb Architecture: ppc64el Version: 1.6.39-2+deb12u5 Distribution: bookworm-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-conova-01) Changed-By: Tobias Frost Description: libpng-dev - PNG library - development (version 1.6) libpng-tools - PNG library - tools (version 1.6) libpng16-16 - PNG library - runtime (version 1.6) libpng16-16-udeb - PNG library - minimal runtime library (version 1.6) (udeb) Closes: 1133051 Changes: libpng1.6 (1.6.39-2+deb12u5) bookworm-security; urgency=high . * Security upload targeting bookworm. * CVE-2026-34757 - Use after free. (Closes: #1133051) * Cherry-pick upstream regression fix for previously fixed CVE 2026-33416. Checksums-Sha1: 6a4a89c5599815b30e7fd4479bd7705815bbb497 375412 libpng-dev_1.6.39-2+deb12u5_ppc64el.deb edca4115289172b6da06631ed35d930cbddc2605 50644 libpng-tools-dbgsym_1.6.39-2+deb12u5_ppc64el.deb 226e4820cd33012c907837e58953c5e8aae6b4c1 128580 libpng-tools_1.6.39-2+deb12u5_ppc64el.deb eb094df26ed2f2aa0a4997c95d7cc5735c2adcc3 7575 libpng1.6_1.6.39-2+deb12u5_ppc64el-buildd.buildinfo c1aa1a1bb551b22246a9bd943d3b81da1622f66d 262132 libpng16-16-dbgsym_1.6.39-2+deb12u5_ppc64el.deb e4070e10dad67ea62ec2ea6efece9be19ea29137 107624 libpng16-16-udeb_1.6.39-2+deb12u5_ppc64el.udeb 57b1a38f812f7bbb0bb02147c789c69f4000c5e5 290696 libpng16-16_1.6.39-2+deb12u5_ppc64el.deb Checksums-Sha256: 2cf4ef9ee681e6b0cee37c4586b042ca79ff5b8cc4b6f83f99864f4c4cd177ca 375412 libpng-dev_1.6.39-2+deb12u5_ppc64el.deb 5ae2ec0d0d2efecf8c6ff239f8fe258fa4cc05db7ad3e8a2f0fef73ecc47960c 50644 libpng-tools-dbgsym_1.6.39-2+deb12u5_ppc64el.deb 90a63fccdc4b017923cb7843254bcf53850165093f3cf70cd48ef72517206f7d 128580 libpng-tools_1.6.39-2+deb12u5_ppc64el.deb 9b5886ae918460bdfef30bd27a819ce6c19ec06e987982e5bca3aba87ddfb829 7575 libpng1.6_1.6.39-2+deb12u5_ppc64el-buildd.buildinfo 747ca2b56e5c6acc327b4dfcdea9d3512cd34d09db734e2b40f3815d48c6eba7 262132 libpng16-16-dbgsym_1.6.39-2+deb12u5_ppc64el.deb f0eb971cdea8f5d14ddc3881015b68e6e757c0a40bee89f19b03488601000370 107624 libpng16-16-udeb_1.6.39-2+deb12u5_ppc64el.udeb 0e0b446af700d1a578dac164a0e5f9f955b9cb9f5fc2a6e421bbd612217676c6 290696 libpng16-16_1.6.39-2+deb12u5_ppc64el.deb Files: a245a87ed0602e2c83083cc0a5b65ce3 375412 libdevel optional libpng-dev_1.6.39-2+deb12u5_ppc64el.deb 584abab6f80c5ff3f54887bcfd9c7b02 50644 debug optional libpng-tools-dbgsym_1.6.39-2+deb12u5_ppc64el.deb dccfd34fce2116dee3cd48525b1f1842 128580 libdevel optional libpng-tools_1.6.39-2+deb12u5_ppc64el.deb 57d595b936688a4a556294190bd64024 7575 libs optional libpng1.6_1.6.39-2+deb12u5_ppc64el-buildd.buildinfo 0e9c512c4fa43f0d72ceeea0e8219e03 262132 debug optional libpng16-16-dbgsym_1.6.39-2+deb12u5_ppc64el.deb 7d7503c240f1c07721d51abe57e37781 107624 debian-installer optional libpng16-16-udeb_1.6.39-2+deb12u5_ppc64el.udeb 01091e63bb65d29cc8bc2d14c3855b6a 290696 libs optional libpng16-16_1.6.39-2+deb12u5_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEDoRc43uRWMOoIqIgDNLUPhbmg7MFAmn+Dx8ACgkQDNLUPhbm g7PM+A//fI+7EoZ+UWJojGreAKURYwMKgZI3nGPEdyP7Bt309ZiinjDpn5cyYnQD JElHXD5t69XKzPvl8xIBlgWnqh0T8j5ZZRAhpj8p4s7rab+r1NoY0X2DgFfauwLa fvpb1NpcIZjFk1mg/z8uazU6aQsj9zdMwQPsMh53YF9wAG7NWymVv6oAA7WdyELL JXlFho5rLfmUr8yQLkUGviiN1xv/3VNXZwSHLE5JfLd9eO8wd0buLotKByBrLX5R R4isQPr5zH9Lxq5NntjpVHKxsr03hu52CDT8JNf4b5V5A1yDHxrgb4OU4wc7klz7 rdhHwwrswUpPPDhPlt/e4ePKxfAeSua3zSuIUAcq+kVwzJHgw4DOFayPQLkm2w6b vXgdVJstpDwA1hCwTz/Lhkj1jXqgabGrFacxPhe/mn5DCuG9xvefBbAjvPdn1ccO vhKtgbORUT+GrdRG+xvQSgZc/H43DSqMR29BTvQdFiT6fj+Dnx6SL0yTOdY8wXT+ WOapjJBrN2bH6+RgPWM/SPPIzMl2O34Sz9cdg8c5ZLJjSmFcXjQSelD/GSWqmLGR 2kh+lN8BYdC+S3HXAEwvnI0KD9L5+S+kiQp/4o+wHaggVDPwsyuRJKgehOk6HRTM KE3XSNkSF8F5bvhjXILn357/Mzc2ZZAZuM+5qWB34sD0Its//Sg= =unME -----END PGP SIGNATURE-----