-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 20 Apr 2026 07:42:42 -0300 Source: libexif Binary: libexif-dev libexif12 libexif12-dbgsym Architecture: s390x Version: 0.6.24-1+deb12u1 Distribution: bookworm Urgency: medium Maintainer: s390x Build Daemon (ziehrer) Changed-By: Emmanuel Arias Description: libexif-dev - library to parse EXIF files (development files) libexif12 - library to parse EXIF files Closes: 1131116 1133922 1133923 Changes: libexif (0.6.24-1+deb12u1) bookworm; urgency=medium . * Team upload. * d/patches/CVE-2026-40386.patch Add patch for CVE-2026-40386. - An integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs (Closes: #1133923). * d/patches/CVE-2026-40385.patch: Add patch for CVE-2026-40385. - An unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. (Closes: #1133922). * d/patches/CVE-2026-32775.patch: Add patch for CVE-2026-32775.patch. - If the exif_mnote_data_get_value function in MakerNotes gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow (Closes: #1131116). Checksums-Sha1: 0733489df3b04e506efbdfa2008ad28fbaedd315 95684 libexif-dev_0.6.24-1+deb12u1_s390x.deb 24c19b5ebd3df9d73799ee898d32b19b9197b5ca 131408 libexif12-dbgsym_0.6.24-1+deb12u1_s390x.deb f07a760baea2edab9155e5c4b2148b7e3ca5e1f8 390000 libexif12_0.6.24-1+deb12u1_s390x.deb 4a0a07cd5f1c2b457d6f7c3081b0490d5cddf497 8602 libexif_0.6.24-1+deb12u1_s390x-buildd.buildinfo Checksums-Sha256: 9d3ec36e00e5ca8c9a211fef0477b3f3c310ee5a71c23367a63fd8a632f20a93 95684 libexif-dev_0.6.24-1+deb12u1_s390x.deb 3ed34f63fcbb14b6de3549d1dfd9c493533d713d90862d6b13711dab302773fb 131408 libexif12-dbgsym_0.6.24-1+deb12u1_s390x.deb cb54a8b1aa7ba03c51f7700e4933b661db6c3c12456e95c22df08dae6d8418bd 390000 libexif12_0.6.24-1+deb12u1_s390x.deb 11d564807b381b9cf648d5ba459951c76a7b5f2f5a3fd55669f981ed65c5bfda 8602 libexif_0.6.24-1+deb12u1_s390x-buildd.buildinfo Files: 5b79cbae21f03d91fbfe5cd1658c201a 95684 libdevel optional libexif-dev_0.6.24-1+deb12u1_s390x.deb 9a2d4a552c1d9ab4a627ac2f34246618 131408 debug optional libexif12-dbgsym_0.6.24-1+deb12u1_s390x.deb 09dd1d0c698ee751de13f7ce8901ead5 390000 libs optional libexif12_0.6.24-1+deb12u1_s390x.deb 8a878670e6422840f8d278a235a77e0f 8602 libs optional libexif_0.6.24-1+deb12u1_s390x-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEl0BM/nR+Oj597wRWMWUFebkHnoQFAmn/HiQACgkQMWUFebkH noRzRQ/9GPPi7Yq6vA2sva2LJI8doRlNgy+W/ob3nu/7Z6Fzy6zrU1RBeNgnjTZG SRtdsuyfPELfGNap6BEVx98wVxl+k1g8LT2vGQ3ZNKOBiM6HrIkm4rA9nHPmcDw/ qeBrT42lwS37Jest50x5pc5KIGZ9wzLGL3O1wr3xuvq04B5UKQ1agl5N7JxUXf/5 mPgcDMUwKurrFGgFxGQyxDcBGc2cKKs5M4LRVCKYblRVXHKbZj8/K7FJYqpWgZgL PYRP6RHJ6OqAPWISdmwCodKjSqhjuq7cFuOapSltbskHAYMkF+51/DiMuc7gzm3o 45RNgOw378lVpjEYoToYHKimuQcFrdT9i+PYj4E1W7Qyoi1FKDunF9D8/+3lUd+m sxlUsNjN1UJPDBSeQ2dGpLtnzgddtP1/xcj7TpGE0FUCAshxHwS1YeaQmpQvN1c4 QFND4lpllV1hOC96YX12ku/IH28Y+JTUvTxXsg0ifg4gOwSBzu/A7LjSMfhrhls0 fBZrxXUDidBVMBg794HJ5mbIh4+H/ZF8+TUER7oO9cSdsqbgg8Y6rhobwibRfh4e xAjLpBwJwLnF4SL9yAJBqEaTkwALG3TffJ9fugidOMfU9rz0GfOPqK3eeXSDMnJ7 dibfPh07g4niRQW+bhYYS4mlTutI8Y/VwpECDf5LetlMtZH4OEc= =7ZPe -----END PGP SIGNATURE-----