-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 20 Apr 2026 07:42:42 -0300 Source: libexif Binary: libexif-dev libexif12 libexif12-dbgsym Architecture: armel Version: 0.6.24-1+deb12u1 Distribution: bookworm Urgency: medium Maintainer: armel Build Daemon (arm-conova-02) Changed-By: Emmanuel Arias Description: libexif-dev - library to parse EXIF files (development files) libexif12 - library to parse EXIF files Closes: 1131116 1133922 1133923 Changes: libexif (0.6.24-1+deb12u1) bookworm; urgency=medium . * Team upload. * d/patches/CVE-2026-40386.patch Add patch for CVE-2026-40386. - An integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs (Closes: #1133923). * d/patches/CVE-2026-40385.patch: Add patch for CVE-2026-40385. - An unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. (Closes: #1133922). * d/patches/CVE-2026-32775.patch: Add patch for CVE-2026-32775.patch. - If the exif_mnote_data_get_value function in MakerNotes gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow (Closes: #1131116). Checksums-Sha1: c60804c29584b62e72ff8a213de6f1b450d8fd1e 93052 libexif-dev_0.6.24-1+deb12u1_armel.deb 3ac8eb2396a9dcfcd0c3a6d521fe64448a4f3c8d 132328 libexif12-dbgsym_0.6.24-1+deb12u1_armel.deb 2b3b38385c5ddee175d6bf54ab9705118c3999fb 384900 libexif12_0.6.24-1+deb12u1_armel.deb 3465c70e4645e2353a7ea44b805490f74c1bc559 8569 libexif_0.6.24-1+deb12u1_armel-buildd.buildinfo Checksums-Sha256: 049084c52934e20a66ec9f333a855d41b7778cf7a076b4f92c78de65e759b0f0 93052 libexif-dev_0.6.24-1+deb12u1_armel.deb 60788ec351059421e3d5bf94811e5afad4066640f4eeee069fac8e6e60ca3f20 132328 libexif12-dbgsym_0.6.24-1+deb12u1_armel.deb 447d9a3bf54ec0550afd68ab4e51c4489ad8b0eaaa07157227b4555a4450e7db 384900 libexif12_0.6.24-1+deb12u1_armel.deb f86c877e333388afb069bb81197bb5bcb4d9474c80cc39a10b80c3b47a8ba8a8 8569 libexif_0.6.24-1+deb12u1_armel-buildd.buildinfo Files: 9d810fa53de458179926a948c1506534 93052 libdevel optional libexif-dev_0.6.24-1+deb12u1_armel.deb b8d5614ed26e1b1a12c852c935c45abd 132328 debug optional libexif12-dbgsym_0.6.24-1+deb12u1_armel.deb 70a18d8844754e449c209647b7eb2611 384900 libs optional libexif12_0.6.24-1+deb12u1_armel.deb c62251a4f2ff7c559f36509fd41eacc1 8569 libs optional libexif_0.6.24-1+deb12u1_armel-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEWHj9K9pO9l4btbD1OQKMdMnEH5MFAmn/HmYACgkQOQKMdMnE H5OBIw/+JZKo9XKe4rXSsh1jEVW40DZbyp+9MXIhErfy4aKib/B7fs+zuJfJXU5u ECQB3qg6/jIRWvr+UO1ij/aLUGaL0hruten5YzSyVpkl6UeauI/IXqbhUO4XDIBV ss8Kay4YguBPToQvN1+Cwc1i3z65B0/EZOiehQuZQT2qa1TGQ1WfPxcIrgN3aTt8 7e9Mmnzutd7tfCtYUXSNSbHYIKgQHwZcPMqZrOpxajTqdOYvBJSQ9LgWFLROaaI0 GNCY3nB+gKLqpAiYwkLLeIGarYVbCHUSrWVOaWAfGAK0v6BWoFQLmuTmGUSdT4ii Kv5Jq4UJ3Hbv3kVKA0pCCGp4/JLjbfKR1ttMdS3OtlA1PC1pI3ck4Ezvz2NKsZeR tiyR3juyLNOD0vSJbTsM+Y+s0hkGuYtxD06OLOBuXQ3LJ0rksruY69XznS4M41MD 7T2e2ZOqafI1qGCyyAEvXz5rsA5ik/s+sdtvIiqMA7wv9zkvrvWti0nUdxfty0VT LtQCNegfQbp+g9R4STswyFlP4LNEJi65mYWh/FRnPRrYVoe8kxpfzAI5fJi0W9a5 BFsZ/1EUYir4K39wNKvvZVG25P8Tc60Y4YWI7gpqYwOOuEJCkplRsujWcbmN8HRe jrCaNBeerRNdiJom9P5NJpU2jFYd+o98yafPBa+POfsxlbS6/oc= =nUH0 -----END PGP SIGNATURE-----