-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 27 Nov 2025 21:29:04 -0300 Source: rsync Binary: rsync rsync-dbgsym Architecture: armhf Version: 3.4.1+ds1-5+deb13u1 Distribution: trixie Urgency: medium Maintainer: arm Build Daemon (arm-ubc-05) Changed-By: Matheus Polkorny Description: rsync - fast, versatile, remote (and local) file-copying tool Changes: rsync (3.4.1+ds1-5+deb13u1) trixie; urgency=medium . * Team upload. * d/p/CVE-2025-10158.patch: Import upstream patch to fix CVE-2025-10158 . A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. Checksums-Sha1: a3b0c4811c0834a4d0b88fda463678e43376cd7b 531188 rsync-dbgsym_3.4.1+ds1-5+deb13u1_armhf.deb f079964a313861ff1b92603420cc02f35be653ac 6530 rsync_3.4.1+ds1-5+deb13u1_armhf-buildd.buildinfo ab2b35b4c4dffcba0ee2a9d0d36d08b282a20486 405256 rsync_3.4.1+ds1-5+deb13u1_armhf.deb Checksums-Sha256: cc68b8c095721cdd606b3b7b5abe80982b345ce8e5a1680bbc61dd6a387a7d01 531188 rsync-dbgsym_3.4.1+ds1-5+deb13u1_armhf.deb f1aca0d161808ec37bbde2ad1f3578374e1e6437173cf77b29b3713a85690e2b 6530 rsync_3.4.1+ds1-5+deb13u1_armhf-buildd.buildinfo 88a6156f9e286dfe270289bb9d210a4cbfcba22f94c6608361a035a112124982 405256 rsync_3.4.1+ds1-5+deb13u1_armhf.deb Files: a33f1ba2a6e23a069bcd21d339377392 531188 debug optional rsync-dbgsym_3.4.1+ds1-5+deb13u1_armhf.deb 34bc57e13e6931d8119d0e0d135c729a 6530 net optional rsync_3.4.1+ds1-5+deb13u1_armhf-buildd.buildinfo ccf1fa9ebad2360c7aa98009a8f01d3d 405256 net optional rsync_3.4.1+ds1-5+deb13u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEiIG3Q3DxwDgRKKeyLRECdjCZQkcFAmlJr4cACgkQLRECdjCZ Qkdizg/+M94jv7ZSrUvP37dEdSwTKrHWc9D05bTlq2w7TyCWG836vCEINlpNu2iJ ZGEgSyRsmBUZ5E3nOpGP5rjBkptPavBIhBLBOCIojsF4qsskv2NgZ10dJ9di98Dr xnFPLJ1F5HmCOnAAAva3UJS6t4z6wEPPyburaLxfWwFjU4C0cWcigj2RkrNytg3Q d/8F/9Tod2zCOY+5gq4oAIkNsAvQL4L/ncwEoK3wPW7HKgVq99Qek5hwFZ5AlzCw 1AAXb64tRI8yxIzfLAjTukwa8xaSr4SeWaRGbW70Xwv9iPVqT/4ORdo2IeUcTKYB uhABDB7JG8c5JdjwdkNj10fhWwHTZzAD4FEHS309sdJXExP035ps4bmx2AwRH2Mv fIEAxOsvinmgOr3JTBvIR+lj7YDDedxsPihF3Yxk1Hqp7E1GeuK4Xfy8SBhQK0+j 7QurUFJE/cWfnYHeB5Z84uBdG/iqbHxRGsEj73uoXeFDKm8yW0m7814vIzSaj/ej 27AG3f7XtcBqs8k0U8oZqHGC1aFZ2wej5u4AmdZydpJHe86TfKfAXCc5t7AwGgP9 R24X13XzDGGWTZBJ9fYX9PmaVNRNSVJLoBnSTH/PzN5ob+7GBptBa62htu0bEtz8 1m9WGY8Pp1UV8Qgo+luIHLaGCbMY5sHPBbjZuh1la2WDvCPEbNs= =039S -----END PGP SIGNATURE-----