-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 20 Apr 2026 07:42:42 -0300 Source: libexif Binary: libexif-dev libexif12 libexif12-dbgsym Architecture: armhf Version: 0.6.24-1+deb12u1 Distribution: bookworm Urgency: medium Maintainer: armhf Build Daemon (arm-ubc-05) Changed-By: Emmanuel Arias Description: libexif-dev - library to parse EXIF files (development files) libexif12 - library to parse EXIF files Closes: 1131116 1133922 1133923 Changes: libexif (0.6.24-1+deb12u1) bookworm; urgency=medium . * Team upload. * d/patches/CVE-2026-40386.patch Add patch for CVE-2026-40386. - An integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs (Closes: #1133923). * d/patches/CVE-2026-40385.patch: Add patch for CVE-2026-40385. - An unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. (Closes: #1133922). * d/patches/CVE-2026-32775.patch: Add patch for CVE-2026-32775.patch. - If the exif_mnote_data_get_value function in MakerNotes gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow (Closes: #1131116). Checksums-Sha1: cafc0d02dc2f60099afadc54ab733d7cdcc3dd4e 93528 libexif-dev_0.6.24-1+deb12u1_armhf.deb 45471f11da9cdf30ff0ad5064dd9d83911a1c5dc 134004 libexif12-dbgsym_0.6.24-1+deb12u1_armhf.deb dbd5a79dc1d62ab85c9f2ee34c6b649bb0035f69 383820 libexif12_0.6.24-1+deb12u1_armhf.deb d1bb7655d33656be824615823116dbf67396650b 8571 libexif_0.6.24-1+deb12u1_armhf-buildd.buildinfo Checksums-Sha256: ddd5c913407beaf50913e32395b08e4d7850cd6b96a173ad91f9f604bf08637b 93528 libexif-dev_0.6.24-1+deb12u1_armhf.deb 9cc1e669e23d147068e8efb9eff7ac4dddcafe78cca82b62fa617ddccdb910eb 134004 libexif12-dbgsym_0.6.24-1+deb12u1_armhf.deb e2bb32d2a7abe3c703ae0368ab37296b1c8e88fa852efb535be813ab270a42b1 383820 libexif12_0.6.24-1+deb12u1_armhf.deb 76fc0eaa83246ed46e5b46f115b7c8f57b215cca7428e266f6bd4cd541e9b5b6 8571 libexif_0.6.24-1+deb12u1_armhf-buildd.buildinfo Files: 7211c3e40e6eefe18b869d87759e43ae 93528 libdevel optional libexif-dev_0.6.24-1+deb12u1_armhf.deb 95b217ccb46af6f0b3341cc3bd3a0c85 134004 debug optional libexif12-dbgsym_0.6.24-1+deb12u1_armhf.deb 5e5ac999341049c264bd065eb2978017 383820 libs optional libexif12_0.6.24-1+deb12u1_armhf.deb f0b45e741cf294f2e34d8c5f3ef0987e 8571 libs optional libexif_0.6.24-1+deb12u1_armhf-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7rv+l3KtZdQea77lnwznazfjXToFAmn/HawACgkQnwznazfj XTrXhhAApQAJDrzaugoLocjHXISAkEd5mgvHIiiVS7S2ua1uz0o08i3rs+0MuQeX 155ZTNZh6hV56l3UYDp+zS4JERm4oCD4OU1z8+tswDI4Q9YAUIvGgvhp5/RsDx9M fAG4D3mXySalqlUSE0gNIouH53VmfWdOkBLwvF1slTokYt3FH4ramP0QI0nLbPwc hdXqSOkBL+IZGCfQ2E71H2WQVt1oKeRoAiFWFZ5+preotPcd5oNNIR6d5W+jqtJ7 X5KoM7GlJKs2qROdXazpbELG2Xiut13eT0cAekN+I3PFr8hCqnl59RWKcCuOPCCG lKi5jLu6bCS4C4Ytgm+PekD3OvQ5cWilr3EChUq0f7nF5Fw2QcKl1My5sefBlDfe GWj2xmQo0v1j3GpqdOHWRB1t5YcRSto2jnPNqqHnpSNs5uRGpEUSR8FkWayPxeFB oMPsKkahq7clyFHDZXjyZYeB1L0pEODVd63IJ0BHvzNpDBnWHZoNCLcXihAf5aUu zmu1Tz41quU8+I1NnEhn8mJb6TtCqtCqpfw8scfZ9o374ndA/g0HBWeXYhz4NV9W M7z/KkXpVHq/nw47PT6dKuR+Mw7Sticnb0VM6yS0UNgLZw/hhooy6yHpNyadxldp 0/2fyHe6WWPK6Bz+THfejX9C8njoru0KuDC6IpJwr370c1EYbu4= =vwoE -----END PGP SIGNATURE-----