-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 17 Apr 2026 07:48:04 -0300 Source: libexif Binary: libexif-dev libexif12 libexif12-dbgsym Architecture: amd64 Version: 0.6.25-1+deb13u1 Distribution: trixie Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-grnet-03) Changed-By: Emmanuel Arias Description: libexif-dev - library to parse EXIF files (development files) libexif12 - library to parse EXIF files Closes: 1131116 1133922 1133923 Changes: libexif (0.6.25-1+deb13u1) trixie; urgency=medium . * Team upload. * d/patches/CVE-2026-40386.patch Add patch for CVE-2026-40386. - An integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs (Closes: #1133923). * d/patches/CVE-2026-40385.patch: Add patch for CVE-2026-40385. - An unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. (Closes: #1133922). * d/patches/CVE-2026-32775.patch: Add patch for CVE-2026-32775.patch. - If the exif_mnote_data_get_value function in MakerNotes gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow (Closes: #1131116). Checksums-Sha1: f1a20a4305fafe24b27e14f11d0d0651064ae854 101732 libexif-dev_0.6.25-1+deb13u1_amd64.deb 66c4fedf4541b89712bc6794128d9f511ee35bfa 134384 libexif12-dbgsym_0.6.25-1+deb13u1_amd64.deb 54665acedf969415aa2443e8226852e6597bb104 422668 libexif12_0.6.25-1+deb13u1_amd64.deb f5056fc7d014a0c051884c7e4789bca83c3ca851 8409 libexif_0.6.25-1+deb13u1_amd64-buildd.buildinfo Checksums-Sha256: 4097a3f38a3ebd65c141ff5ff5e09d5c909a67976c8734251b616fb3fc847777 101732 libexif-dev_0.6.25-1+deb13u1_amd64.deb 518e08281c54f76eff0bb0160ddaf175796b7354d9ebc2d5c9aa656fb6dae7de 134384 libexif12-dbgsym_0.6.25-1+deb13u1_amd64.deb 74ff427590c93278da9125363e60b532b5cfca0eb6d649b75712dc5e2325c1db 422668 libexif12_0.6.25-1+deb13u1_amd64.deb 2363c5a8c96b23da26cd672f47f2e90642a1955a00add92d58d3c653e0e123dc 8409 libexif_0.6.25-1+deb13u1_amd64-buildd.buildinfo Files: ed777d8a6c668ebc843ff79e9a0d88ae 101732 libdevel optional libexif-dev_0.6.25-1+deb13u1_amd64.deb 4bb059bbbf20c8be5cc1cb99bbbcbabc 134384 debug optional libexif12-dbgsym_0.6.25-1+deb13u1_amd64.deb 5e6406159d31517908bce286ba94e554 422668 libs optional libexif12_0.6.25-1+deb13u1_amd64.deb 57279b4759b5ae1fe6a826cf39722113 8409 libs optional libexif_0.6.25-1+deb13u1_amd64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5ZI1lXv5WjhHIVjsN8Ugyu9dQiQFAmn/IeYACgkQN8Ugyu9d QiSfpA//ddkTz33NYWQg/jWR3NxQU5tHVsAhHMYmHbRNGKNZ0Wh8Qb0sX/hZEVY4 50gNx9ThudY37hY83CxypzGXsEzIorhPBp4GEf1wsmBLuTXk3/wF+m8X0fKqBAjt dqufEym1VWScDJRJ8l7X2MrOIc5pSXMP5IjIMWazq36zqz1Eaf84TBF7W9kC02ot RdkbR9wT4OFoK66YkkRhLtxf1hL4y/Ccis7dK614nFDJY8O+Nw5O9GxEQp/8OVZY YRZjOgtKohEXdgI+DSCnMNWsqr5aGtE4h5O6qiJTSFP68fgCYU0feqoXzQ2I93kz jC+OPe0f1DhOEs5M2g2gyIVK6WzAHW+ELpGcu5LvmCzpH55G3CAVcYQFrPbbilKD nq0h9t4WwH8ie1b8UWChSt06m81awReVFGmuPBqkp7gI0mdxmCHq7ViTAJQx3REw Aox07LJ2gplwPJGrac10YaZeiaMgJtgyrD2qndE8yMzY5GMUc3R0ugw0QRNeyfE8 L89YBmhCzXi+itNyT3SIC3Nhy6D5xP6sRokbvF/jeKoIbxbfzmwx25RMlRwkbnzM GfwenCe9cvTet1BHP4vbQUlASUhELc2gmI2ZwRexSbbI0nmOS7gBL7wVuqX+1BYO 0g7/7f/2isLLSAusHCFqFFSPajhk3Rpmawpl2C6z6RWCEmi9to0= =GKZB -----END PGP SIGNATURE-----