-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 20 Apr 2026 07:42:42 -0300 Source: libexif Binary: libexif-dev libexif12 libexif12-dbgsym Architecture: arm64 Version: 0.6.24-1+deb12u1 Distribution: bookworm Urgency: medium Maintainer: arm64 Build Daemon (arm-conova-04) Changed-By: Emmanuel Arias Description: libexif-dev - library to parse EXIF files (development files) libexif12 - library to parse EXIF files Closes: 1131116 1133922 1133923 Changes: libexif (0.6.24-1+deb12u1) bookworm; urgency=medium . * Team upload. * d/patches/CVE-2026-40386.patch Add patch for CVE-2026-40386. - An integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs (Closes: #1133923). * d/patches/CVE-2026-40385.patch: Add patch for CVE-2026-40385. - An unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. (Closes: #1133922). * d/patches/CVE-2026-32775.patch: Add patch for CVE-2026-32775.patch. - If the exif_mnote_data_get_value function in MakerNotes gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow (Closes: #1131116). Checksums-Sha1: 51b937c8f3500e7e094ad2069da7e9af2b18db22 100884 libexif-dev_0.6.24-1+deb12u1_arm64.deb 3f770e45a40a334b701f9241ecea9f6e87ebd662 134628 libexif12-dbgsym_0.6.24-1+deb12u1_arm64.deb d10627ce7e9b2872defabd72497cfa74a65c4ea8 392012 libexif12_0.6.24-1+deb12u1_arm64.deb 04b4ad26e855964559d7db2ebcb5df3da087dbcb 8783 libexif_0.6.24-1+deb12u1_arm64-buildd.buildinfo Checksums-Sha256: 184cbeedbccd839202b2f961cf6cc3dbc21f81810ee556fc9bfd2ab0fbd3b0a2 100884 libexif-dev_0.6.24-1+deb12u1_arm64.deb e9546fd823409094752cacd442c311c1430222681d628a433feb88b9bae3733d 134628 libexif12-dbgsym_0.6.24-1+deb12u1_arm64.deb e5e6480ab9419759aeade42bcb3c6c17e4825f109491c52d2ae6411fdf706611 392012 libexif12_0.6.24-1+deb12u1_arm64.deb 01648d2931e86302fd3f90f7c02682a4dd764a2f857c71b5cc9ba5ac74f20fb8 8783 libexif_0.6.24-1+deb12u1_arm64-buildd.buildinfo Files: abd2eff1975ea2d42263bd2d8f6a3f46 100884 libdevel optional libexif-dev_0.6.24-1+deb12u1_arm64.deb dccf36e6eb705903a351e8d5df357e56 134628 debug optional libexif12-dbgsym_0.6.24-1+deb12u1_arm64.deb 436230d3303d1d25184ee16dcdf63ee3 392012 libs optional libexif12_0.6.24-1+deb12u1_arm64.deb 5a679206bdb75caf46822a8f278cff10 8783 libs optional libexif_0.6.24-1+deb12u1_arm64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYxmcRLDHP0tCCM0oScpU3dYulLgFAmn/HboACgkQScpU3dYu lLhYfw//QMKduqiPeS6zF/Pm8CIGWOFH8ISx7yzs9UAzceUcoC28oq+vY/rdVW1I oWIvWh77fpoSxKDHlJWWWo3vLR5MMpz/VH10QGfOjOrTr2wLHteKslsiTnYHLVhZ G0lURtKHuTzpj/6z3GZol5u0xr18semzRYdJ6Ig2fmlJ0jdAQ08UxF2g88di/qWV At5PrCWgyROC0BxyibuuGfHsvfgsUcDQj4QIpjuX4v8b+edy6WuANknvdIw4LCvM 27DFhFxMxfDzJ08P8AIRnYnEB96Dm7W1vNnT9CuTmku6i4Icql4x7rozahGh0tGy 6Zb7vrmx3qFlx7O0Ou+DFZ0trMQd8bI6FHg41gnyvZg3Al13laeule8Sz1uVNqYb nRlAm6valR+WIhYkqTEkl3coNVEsM51OynNZ4vLs35EiXWJMWUFD7aeX51LLjDoh ZxFvm5mFm8L3mmGM3FcqLl3PERLs2uNM/fsV1k4AKZW7fA5hzHjCHKn/fcCrKhaT FqQ4NhTp1uyfuBxFrxmfrjKC6gmkTk9Fd9Z9YpWynL42dz3U7YGpK1JjISmX+DUM tqsej+CG/sXnyoviclNpq7LojrOcPeodPp8Z9IVrXGPptf2ll4RTp/Ukbq0YdKjD zH267ZkgAgrOC1R4fQxXZ2XEeV3orf0mrltW8NGyV2wJS50l2w4= =9juq -----END PGP SIGNATURE-----