-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 24 Jan 2026 14:15:14 +0100 Source: libpng1.6 Architecture: source Version: 1.6.39-2+deb12u2 Distribution: bookworm Urgency: medium Maintainer: Maintainers of libpng1.6 packages Changed-By: Tobias Frost Closes: 1125443 1125444 Changes: libpng1.6 (1.6.39-2+deb12u2) bookworm; urgency=medium . * Backporting fixes from 1.6.54 for oldstable: - CVE-2026-22801 - Heap buffer over-read (Closes: #1125444 - CVE-2026-22695 - Heap buffer over-read (Closes: #1125443) Checksums-Sha1: 94837b7c64dcccdd356e16a817b3cf13902f038a 2292 libpng1.6_1.6.39-2+deb12u2.dsc d384c4526a84d213f697108258c490adc99b4cdb 1519415 libpng1.6_1.6.39.orig.tar.gz 4284ce1db920f382b975fb7cfa4c229aeef91669 39264 libpng1.6_1.6.39-2+deb12u2.debian.tar.xz 7b30dcfd1325f2061698946367099298e931d143 6414 libpng1.6_1.6.39-2+deb12u2_source.buildinfo Checksums-Sha256: b81c868c9751efc4df4b1616f3003c3e32471f572dbedebd53f9c14816152ca6 2292 libpng1.6_1.6.39-2+deb12u2.dsc a00e9d2f2f664186e4202db9299397f851aea71b36a35e74910b8820e380d441 1519415 libpng1.6_1.6.39.orig.tar.gz 05d884b8ea70371a2e013b290caf793c1d46c2005462b0d29e3e18e7d7aa3e23 39264 libpng1.6_1.6.39-2+deb12u2.debian.tar.xz cb624182a1d16accf65735f5280df89723ee0c9210cd2b31602d04ce13ad0ab5 6414 libpng1.6_1.6.39-2+deb12u2_source.buildinfo Files: f143f5a8d81c15a6cdd79cd5edd2ff38 2292 libs optional libpng1.6_1.6.39-2+deb12u2.dsc a704977d681a40d8223d8b957fd41b29 1519415 libs optional libpng1.6_1.6.39.orig.tar.gz 1ab6982917fdff6f9f28e32a4f52295b 39264 libs optional libpng1.6_1.6.39-2+deb12u2.debian.tar.xz 6b276d0badfe12f72bb6997bcd006515 6414 libs optional libpng1.6_1.6.39-2+deb12u2_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE/d0M/zhkJ3YwohhskWT6HRe9XTYFAml0yq4ACgkQkWT6HRe9 XTb1bxAAg7+JwPxhUS/R5xSH8WbWQ+n6+8Y1xgzsdUarjpOkKkxQr+/wSEm4tveG 34I8xi71dEr06mbgyx18+PXl9DJliIlvBwiCYret+DSauooTSQvlAH0nwNULnviG Olgz92K7WxiIKdA0H/68/ZfFV+kIl9YubaLwOmnQNU7DMuuVQaWTtCLjSbMyueW9 +jVDyHg9GVJ8e2vx608WhRIcToFBujwU0/UsoF99CaWmyfjqbgWWS8PaqnlVL5+v rw05LK9EonvMbwX8sT7SwIcNTjAg6ijhFQFSsns+7BTZGI6s3BGYHGo8VXowuxkG +Z3N3IWV5kV5Y/SdW+XXyUuABrnWq7GKlC+ow1X/PksFghCAJWHvszpzGB6bxeom 5wjQFndRquRtKJjhTHgXSGtcvgK6jeaW5j96C+a1EPnau6mI4DsXr3wXzFeRU08M J2rYj6FVAM4NK2EBulZT1JpDkeLpmgwrlnx3OwdUtxK/GZl1ubJEL4HUANmJOOiC qs3ox3KvOCT3TXbNWyp1l1uNiEz7pgNGbrTXvp1Z6Kl/bebG5SpRrG5F7d4cQA6V 60N34vDvS8eSEcjOjawDEJ3Dv0qpDblB1m2XwNpUpj1vNxM0MysYPcsB2Czffej1 6Iv2LEG8PtoPxddz5QGWtTI5AXvTATBMmDrQ98N94EB48c7fs7I= =o3FD -----END PGP SIGNATURE-----