-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 26 Jun 2026 13:13:13 +0000 Source: xz-utils Binary: liblzma-dev liblzma5 liblzma5-dbgsym xz-utils xz-utils-dbgsym xzdec xzdec-dbgsym Architecture: armhf Version: 5.4.1-1+deb12u1 Distribution: bookworm Urgency: medium Maintainer: armhf Build Daemon (arm-ubc-05) Changed-By: Otto Kekäläinen Description: liblzma-dev - XZ-format compression library - development files liblzma5 - XZ-format compression library xz-utils - XZ-format compression utilities xzdec - XZ-format compression utilities - tiny decompressors Closes: 1132497 Changes: xz-utils (5.4.1-1+deb12u1) bookworm; urgency=medium . * Backport upstream security fix for CVE-2026-34743, for which upstream states it's likely that this bug cannot be triggered in any real-world application, see https://tukaani.org/xz/index-append-overflow.html (Closes: #1132497) * Additionally backport related fix in xz to prevent an integer overflow in --files and --files0 * Add myself as uploader and prepare gbp.conf and salsa-ci.yml for easier maintenance of this package in Bookworm (and later potentially in LTS) Checksums-Sha1: 3f27d6a3662b2c99b58e07ab0fb6836cc53d90b8 248652 liblzma-dev_5.4.1-1+deb12u1_armhf.deb c0caeb3b26f7bf22be20a31669b7ca6e29ecd462 251108 liblzma5-dbgsym_5.4.1-1+deb12u1_armhf.deb 5b26055442f46507fba7ff9fbae3fd5032d2ca97 193216 liblzma5_5.4.1-1+deb12u1_armhf.deb 9ea1b059855f2ec4c61f2774d8fd77e57d63edf4 88656 xz-utils-dbgsym_5.4.1-1+deb12u1_armhf.deb 37e3bbf01dc849e022bd83e26719e95575cc7c19 7806 xz-utils_5.4.1-1+deb12u1_armhf-buildd.buildinfo 173578f3e85cbff8787168b31f03ec51be569fbd 469176 xz-utils_5.4.1-1+deb12u1_armhf.deb dea203658dd6040246898be287b955322cd1ebfe 108728 xzdec-dbgsym_5.4.1-1+deb12u1_armhf.deb e748c8facd6aa015f67e5c62900cd6b3e17377e7 153700 xzdec_5.4.1-1+deb12u1_armhf.deb Checksums-Sha256: 33680b21c5a648c47e27f310d4c8df0c15ad658704e58df44d21438fb6fbbb46 248652 liblzma-dev_5.4.1-1+deb12u1_armhf.deb ed229023cafce51db1cb12746c7f3b84afa3e3ba34dc4fdd62faed79b82ef227 251108 liblzma5-dbgsym_5.4.1-1+deb12u1_armhf.deb bfbb78b257213e3d66a8c5940c1f5e922dc3bad5c427c9077324657a5eb78e00 193216 liblzma5_5.4.1-1+deb12u1_armhf.deb a5a00676b3166c2ee0fbacdfdb33c5d16741e281556204e3932c1b404d04d4b2 88656 xz-utils-dbgsym_5.4.1-1+deb12u1_armhf.deb 416597c01d59e685a92b978f9681480f5f19b44323adf672cb78d3b621ce3d14 7806 xz-utils_5.4.1-1+deb12u1_armhf-buildd.buildinfo 0cb8256ed903157c803073bb49e2b20adc2d52290662133440714d02e91595f1 469176 xz-utils_5.4.1-1+deb12u1_armhf.deb d3ad1898bf312a9d0541a532d4bce46e796764eeda60452506d85c8d7d88af00 108728 xzdec-dbgsym_5.4.1-1+deb12u1_armhf.deb 4c5035811ca07b4d6b56b5d463989d2309a36cd9f7c3b97daeccc951d24ff0cc 153700 xzdec_5.4.1-1+deb12u1_armhf.deb Files: 88852ecff3795a5d12041ab63cc49ceb 248652 libdevel optional liblzma-dev_5.4.1-1+deb12u1_armhf.deb d79a75dbd08257745e9b73104e1a79f4 251108 debug optional liblzma5-dbgsym_5.4.1-1+deb12u1_armhf.deb 591ab2d47b588ffe45acd3c176d1fb03 193216 libs optional liblzma5_5.4.1-1+deb12u1_armhf.deb e940e6320d29d01cdec1a282f8708445 88656 debug optional xz-utils-dbgsym_5.4.1-1+deb12u1_armhf.deb 2e622c4599c050143c42e60a80e5fef1 7806 utils optional xz-utils_5.4.1-1+deb12u1_armhf-buildd.buildinfo a51c80f7a3100fb0aa31e9b78c31a100 469176 utils standard xz-utils_5.4.1-1+deb12u1_armhf.deb 9747ec8f69d7d815eb363b1a8a025794 108728 debug optional xzdec-dbgsym_5.4.1-1+deb12u1_armhf.deb 5d20365380e36f0a9281ae175ddf290a 153700 utils optional xzdec_5.4.1-1+deb12u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7rv+l3KtZdQea77lnwznazfjXToFAmpJEHYACgkQnwznazfj XTrnZA/8DscHl+igxNRrCRbVdAZwgaOnjpUboZ4Xd5lfYrr7sQ9NlL84l0ipjkNl ihkHH4NCXCWDFuvGGUS6klRVpkRRpNAAri6WswREZRcKNlOcsKxJvo5mBj/wFS7u XDf9UmJ7yacLYsk+t/MW9oeV6anJHyLSdDH5L0rJAzRFKotTg0lj3LBZdao73txf HyTt5vahkWDlrn93oNXh2uNIHwRP0NGhE464wgj7sKQIv4GvYvoj9kzYxVQhgUQu oGB6+la0kPq9eGCXYh8A7DUci0QDGCxrK0arv8hwJpsyQO9ZxlSDePeND/PXnob9 zm6hIenfktxAbvMnbWYGy9mBGbiucwxqWE3AbaAvJErMD9tZFOCiijw5CJtpx/Ry yfLYxX0s47+Dka9VCgwdXpoycja+D0nGnB/GYysgjXCpostrW5tjQ3KOpAOKcGVT qVe/LfpQ64hgUJ0LXFYN8i839r0Ebj7KLxcZ/O2qXzYChIbyAUZNKNbwc7Tv4iio +wZ61qcFkeB2Wz3q3ucrfGm1JU2nDUEQD2lE4BYB7vIKmtRQJxJACQySqZlkRuKS JJfTfcEAH1S8bbJl7v3CBvsU0E9hLTR7aG/tBxMR2oNzLiaT3URoHe8678itbtIr KCy2iSt6guX5Nk3xlm5n8m9PVCB0gHOF/9xAoGA2NUCX5PZoIBM= =YKB/ -----END PGP SIGNATURE-----