-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 26 Jun 2026 13:13:13 +0000 Source: xz-utils Binary: liblzma-dev liblzma5 liblzma5-dbgsym xz-utils xz-utils-dbgsym xzdec xzdec-dbgsym Architecture: i386 Version: 5.4.1-1+deb12u1 Distribution: bookworm Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Otto Kekäläinen Description: liblzma-dev - XZ-format compression library - development files liblzma5 - XZ-format compression library xz-utils - XZ-format compression utilities xzdec - XZ-format compression utilities - tiny decompressors Closes: 1132497 Changes: xz-utils (5.4.1-1+deb12u1) bookworm; urgency=medium . * Backport upstream security fix for CVE-2026-34743, for which upstream states it's likely that this bug cannot be triggered in any real-world application, see https://tukaani.org/xz/index-append-overflow.html (Closes: #1132497) * Additionally backport related fix in xz to prevent an integer overflow in --files and --files0 * Add myself as uploader and prepare gbp.conf and salsa-ci.yml for easier maintenance of this package in Bookworm (and later potentially in LTS) Checksums-Sha1: f2e3e4b17bbeccbb9cf0a0b86ecc58d12ed6b931 272748 liblzma-dev_5.4.1-1+deb12u1_i386.deb ec15362a920e42d3521cbadd7861084760e2b1a5 242424 liblzma5-dbgsym_5.4.1-1+deb12u1_i386.deb 6e52a7a40625429bf2485e81fb5f13629fe571b3 214868 liblzma5_5.4.1-1+deb12u1_i386.deb d9c9a265e7635d2259bd4190d98cbe608d471eb9 81544 xz-utils-dbgsym_5.4.1-1+deb12u1_i386.deb 78df1b89c5aa2f0d8da66ac23faaa094e0d5b9b0 7856 xz-utils_5.4.1-1+deb12u1_i386-buildd.buildinfo 3db1570006e54a7529ec39919f964d5298374e2d 475584 xz-utils_5.4.1-1+deb12u1_i386.deb df7467e4a1fd6045927b810ab7cb88d39136fd26 114724 xzdec-dbgsym_5.4.1-1+deb12u1_i386.deb 9ed74e530a7f4d36fc30209beffc42adf09389d5 162284 xzdec_5.4.1-1+deb12u1_i386.deb Checksums-Sha256: 5c539d13cc86737752aeadfc784cec1da223f67ce08d2d9b7c120632f07c987b 272748 liblzma-dev_5.4.1-1+deb12u1_i386.deb becb84bf4ca1f0c1395a9318938a0b8d9b1383ff710aa3735707a9ce218fdf96 242424 liblzma5-dbgsym_5.4.1-1+deb12u1_i386.deb 5b3fb8a53da0f5b1ec1181be94d39a8508db02465ec4421df12ad4c0d76924f3 214868 liblzma5_5.4.1-1+deb12u1_i386.deb 3e9f3ea004464c463488572d1031e2440bf7d4b8fb8e0a47e5cc120b9b4ba915 81544 xz-utils-dbgsym_5.4.1-1+deb12u1_i386.deb e7715c309c3d03446d57be11c13703e139155367620cc131b5f63aa23d6875c7 7856 xz-utils_5.4.1-1+deb12u1_i386-buildd.buildinfo ac44fac4977468d8807a6264f14e970ec8b8f27f03704d683e9e22225b2f4f23 475584 xz-utils_5.4.1-1+deb12u1_i386.deb ba80cfbe5bfa9268b4c243f5c87969f4203c985753e5b34f2cff9f6202fe6765 114724 xzdec-dbgsym_5.4.1-1+deb12u1_i386.deb cb6cea369a79fd450bb50051b254efd3ce25240fd21af10ef2e790a33754fc31 162284 xzdec_5.4.1-1+deb12u1_i386.deb Files: 713ffce825d87c82f14d37dbfafe0138 272748 libdevel optional liblzma-dev_5.4.1-1+deb12u1_i386.deb 7284482e548f419c0fbc3f2f06fb92dc 242424 debug optional liblzma5-dbgsym_5.4.1-1+deb12u1_i386.deb b2b9e4f3f1530c2345fd268ab8758faf 214868 libs optional liblzma5_5.4.1-1+deb12u1_i386.deb 07c1bed1865046cf4b2e0e8bb8ccdacb 81544 debug optional xz-utils-dbgsym_5.4.1-1+deb12u1_i386.deb 13f5925986e16984e1a34f80f5d73c9b 7856 utils optional xz-utils_5.4.1-1+deb12u1_i386-buildd.buildinfo d66d12bc4bf86ef4989696e18b844b61 475584 utils standard xz-utils_5.4.1-1+deb12u1_i386.deb 0172730d02bd604c285b6ea52c274512 114724 debug optional xzdec-dbgsym_5.4.1-1+deb12u1_i386.deb 247c55da4e47d6be709d794f54646e17 162284 utils optional xzdec_5.4.1-1+deb12u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmtr4KUMaso2EQ6NrTwt/65ON6zcFAmpJEHAACgkQTwt/65ON 6zdXUA//cs+PWNXB1ogyVlNMcnSxmXW2U4b4YJ9arAX0Ol9Pf5sPzCsnnEEJcqDe kU8DoQG+rNM8H5ztHhyNyHQ6LBrEm5Ap14LjQOS0ZGYqqLwVFIP2QVaLNZNE1rfB vjdLK/XyZZqNaFxnPImRGUQIGb+zEDh4YP3jSqu4wLkDn5/zXeB29RVp35coTZlj r6t4QEQdk2tjFgEQAGy5jCaWCaZfRVrr9A+fNetnyxANaMZTdBlDlmR4xQM2FkWY X0CNcVlSrNkWn92AH/4H5ptci/Qbi8QXNw+QXWtEyf8KRmkwiz9vB6V8gdz8x+wo JTepPpAj8VTUO7dQxSe+pK4pdEds88nYroX0JB+VGoqG71ZVU9+zX0m/7a+JvEpN cvXSB34/e3UrWxGtCKCqm/TawiMYdi3WSX617+fgnOFUT7i9oQCjgupXBGB+VPTS 9Dpd90urSmRor6U4eI2CGVfJCmFUdiKu6WvLj2p+8C/VallKCY8qvwBfO7mWjiig 2R+lJM3Axp+Y1hSNxgCvM3JuICnv5OoSYEP2mC2y0MSe+CqD0aQiQnneCLO9/uyN 4p2xr1pP7IH+xBImJr7LwLRwLZgdm+54j7GZsF93dte3p8QbRugXa5dR5G4ULixm hIl6iyOxvfzGJK6Az0SFQdfMqWqmyTzHz4gn0sA5BgiCthMz/Gw= =pL+0 -----END PGP SIGNATURE-----