-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 26 Jun 2026 13:13:13 +0000 Source: xz-utils Binary: liblzma-dev liblzma5 liblzma5-dbgsym xz-utils xz-utils-dbgsym xzdec xzdec-dbgsym Architecture: ppc64el Version: 5.4.1-1+deb12u1 Distribution: bookworm Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-osuosl-02) Changed-By: Otto Kekäläinen Description: liblzma-dev - XZ-format compression library - development files liblzma5 - XZ-format compression library xz-utils - XZ-format compression utilities xzdec - XZ-format compression utilities - tiny decompressors Closes: 1132497 Changes: xz-utils (5.4.1-1+deb12u1) bookworm; urgency=medium . * Backport upstream security fix for CVE-2026-34743, for which upstream states it's likely that this bug cannot be triggered in any real-world application, see https://tukaani.org/xz/index-append-overflow.html (Closes: #1132497) * Additionally backport related fix in xz to prevent an integer overflow in --files and --files0 * Add myself as uploader and prepare gbp.conf and salsa-ci.yml for easier maintenance of this package in Bookworm (and later potentially in LTS) Checksums-Sha1: 1ed25cb673d843936d1b41725ace29c1feb95e1e 270508 liblzma-dev_5.4.1-1+deb12u1_ppc64el.deb f8095d2706efa626a40dbd36cf16cf564132a1fe 258464 liblzma5-dbgsym_5.4.1-1+deb12u1_ppc64el.deb 1779e12e75145dee6e57211816c755a29897943b 213568 liblzma5_5.4.1-1+deb12u1_ppc64el.deb 35f19cdce457dabf4715305e85d119b08f82f452 91392 xz-utils-dbgsym_5.4.1-1+deb12u1_ppc64el.deb 5e5bdcb2869587cb082f7e251c7a09604a9b4387 7989 xz-utils_5.4.1-1+deb12u1_ppc64el-buildd.buildinfo b5ca5456842d3a14a2561a893d168907a8575e78 473640 xz-utils_5.4.1-1+deb12u1_ppc64el.deb b97ce31dc99a4971b41126bf0d64eea2f9cdc0d0 110784 xzdec-dbgsym_5.4.1-1+deb12u1_ppc64el.deb 24b5eb813a4810613ccaed2a5a578dccd239493a 161700 xzdec_5.4.1-1+deb12u1_ppc64el.deb Checksums-Sha256: d12ee12637bbd95266ad5ade6d17ac2a717f6a96a787628410f7241d4ab53479 270508 liblzma-dev_5.4.1-1+deb12u1_ppc64el.deb db80c9df5b2c0f4028553ef5d2d3b9e4302a23238a46ab3983e1baa3d042ce7a 258464 liblzma5-dbgsym_5.4.1-1+deb12u1_ppc64el.deb 363a40e5433b084989ecce473af3bd2eaebe4be53e078aac2f77ddd4c56421a0 213568 liblzma5_5.4.1-1+deb12u1_ppc64el.deb f5ef96c5b746da934e1478d59ee08da8f1856daa3af0e2cde00d06fb91f4bddb 91392 xz-utils-dbgsym_5.4.1-1+deb12u1_ppc64el.deb 2d7dc876afd072d9a9855d4e75904330ee27a10a72e0ad19f597d6bdff4e305b 7989 xz-utils_5.4.1-1+deb12u1_ppc64el-buildd.buildinfo 3ed7d62ceed58085eff10f03266ee20abc3c675632c3b8b6bcf2a45fe838bc0b 473640 xz-utils_5.4.1-1+deb12u1_ppc64el.deb bb32dc46f73cea91ff79e3c7a53d005e9c7bd0bec9e7a7f96decb25556b168ab 110784 xzdec-dbgsym_5.4.1-1+deb12u1_ppc64el.deb d4f0630bf52a2e45b1ba485caafd67f4f96b6e3a3413bcd1749574a4e7997ee0 161700 xzdec_5.4.1-1+deb12u1_ppc64el.deb Files: c529e3543670dc16ced156cf714d2c1a 270508 libdevel optional liblzma-dev_5.4.1-1+deb12u1_ppc64el.deb 820668070a7a3162ebbd005bef789be3 258464 debug optional liblzma5-dbgsym_5.4.1-1+deb12u1_ppc64el.deb f9e22c320c44d87d86fcb28f13af4260 213568 libs optional liblzma5_5.4.1-1+deb12u1_ppc64el.deb 973dbd87f6a0a9a421039e01b616f44c 91392 debug optional xz-utils-dbgsym_5.4.1-1+deb12u1_ppc64el.deb b5ec2eb1cd44ad276bc6c3ce5fc84946 7989 utils optional xz-utils_5.4.1-1+deb12u1_ppc64el-buildd.buildinfo bfc78168713700a8d14745a1e73dffdd 473640 utils standard xz-utils_5.4.1-1+deb12u1_ppc64el.deb 7e66bb94c68f3851d4ad1232a0151387 110784 debug optional xzdec-dbgsym_5.4.1-1+deb12u1_ppc64el.deb fe0ce8a2f7c4c30802336e52894055ff 161700 utils optional xzdec_5.4.1-1+deb12u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE9ibmwdV9gdKNbK7oV8ucRsMTpuMFAmpJEHIACgkQV8ucRsMT puPfqhAAhuxvNp3W9sKSa2Wkg3OQZbfUZUwJa2tQjVFRwikLYRnDHHY03l7a25sz gZVW5t7F7ZTRZG55K3BAu4/OVbAEX0Z1kd2bI7CcVpfb+bcAjZhiyqOHlURB7W04 LZTHYUytrdXe/wxoL1GR8Vs2LAoDILa2bC7uuudieLCSCBnrgc+b3FXbo475auh9 cTk5KdGDO/Mj3R3RpTela5zQan3/akLXRJbGb4mk96vpZzy004Ced+3AxwwZaP4Q ZmeGFLfB9/wgSmbbonBiFx26bQvMbJagaU2KOjkFlgMqunGGHvPDAEMu+JFTOO36 ZdYY40/F18M0pesGmn7vCOK0/VNFWFyakv37Ftn7U4MrEy2y3JFlo/nbA7lWFHwV aE3TX3l51/MFpUA6Gu8IeLkBJZSdNgXbbyw0Ayo9PjnR6AEtvE/JorI4qCZlbZYl ym0Yl7IhB/XuMOOjEbbOkjLOKvbGXCSV20F2Vh5QTj4J1hMxAfCA78R/B/VIy8hR L0doD2y7uGUdxF9K1PUOiXnjjEnQszC2Ze0/oSiTjorV5r6mvw5pCryvCLZKpDAM qAl9+mh6k8mzmVpvDMrSii5T2sjT1hsuDClJ+a2aDXgJX89qRyUyCAFNtZx87Eb6 /OxtpGqZ8+szp1qAaRb+nJvCa6PqOlK9Yji+E5W6z5EqoFszJec= =2CUQ -----END PGP SIGNATURE-----