-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 26 Jun 2026 13:13:13 +0000 Source: xz-utils Binary: liblzma-dev liblzma5 liblzma5-dbgsym xz-utils xz-utils-dbgsym xzdec xzdec-dbgsym Architecture: amd64 Version: 5.4.1-1+deb12u1 Distribution: bookworm Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-grnet-03) Changed-By: Otto Kekäläinen Description: liblzma-dev - XZ-format compression library - development files liblzma5 - XZ-format compression library xz-utils - XZ-format compression utilities xzdec - XZ-format compression utilities - tiny decompressors Closes: 1132497 Changes: xz-utils (5.4.1-1+deb12u1) bookworm; urgency=medium . * Backport upstream security fix for CVE-2026-34743, for which upstream states it's likely that this bug cannot be triggered in any real-world application, see https://tukaani.org/xz/index-append-overflow.html (Closes: #1132497) * Additionally backport related fix in xz to prevent an integer overflow in --files and --files0 * Add myself as uploader and prepare gbp.conf and salsa-ci.yml for easier maintenance of this package in Bookworm (and later potentially in LTS) Checksums-Sha1: fd8f0dd51f18daadd4a59f5babf77b467e78482d 260236 liblzma-dev_5.4.1-1+deb12u1_amd64.deb 20ce71c04cb434b88bc2f647281b13242c7e4515 267772 liblzma5-dbgsym_5.4.1-1+deb12u1_amd64.deb 548827be6ff861c63704929d7c6d772f65eec8f2 205732 liblzma5_5.4.1-1+deb12u1_amd64.deb 8f7d050c61f0713766bf70a1823d1da2f17ea198 90060 xz-utils-dbgsym_5.4.1-1+deb12u1_amd64.deb 9a668a916d84a852578fa13f7b8a9137bf7e8b17 7947 xz-utils_5.4.1-1+deb12u1_amd64-buildd.buildinfo cde9e39c8c93267a5f616a5308d72768f39ab1f6 471212 xz-utils_5.4.1-1+deb12u1_amd64.deb b2d06d22aea797d3cd8a67f57afb2fa7530960a1 124232 xzdec-dbgsym_5.4.1-1+deb12u1_amd64.deb 6f2e9ef1915775238ca00e77f84c6211b9f0afef 158432 xzdec_5.4.1-1+deb12u1_amd64.deb Checksums-Sha256: 0f30921b4b7ce6baa8565f2b83145158267fb77c654aa431a6fea1e239019e1f 260236 liblzma-dev_5.4.1-1+deb12u1_amd64.deb e35c842ecd328da02c032ee60fd36d453af069f4f985d815b09b2b288baf91d3 267772 liblzma5-dbgsym_5.4.1-1+deb12u1_amd64.deb f96d8876b53ec89d76a992bc199679b818cf518225a768954d9451fb556a4eb7 205732 liblzma5_5.4.1-1+deb12u1_amd64.deb dd13ba29f15bc94ef57afdbb331adc1fbb6de4dc7bec50db154bd8e39749795a 90060 xz-utils-dbgsym_5.4.1-1+deb12u1_amd64.deb e4b28953ae1547b2c674fc29e1ccb79aa4daf0f65557144ef2d92a30686a4cf2 7947 xz-utils_5.4.1-1+deb12u1_amd64-buildd.buildinfo cc6dc501e0c06be3f89e9a7f8dfd7a97f92aadfd9daa60fad19b90d6a5558b80 471212 xz-utils_5.4.1-1+deb12u1_amd64.deb db9eddc4a1997278100f91041cfd8db921085efb59b725d5a09fb06bf8d889ea 124232 xzdec-dbgsym_5.4.1-1+deb12u1_amd64.deb 6219d8a0a4cee796f594ac134c042dd7c6aac27db969913607965b89acc0e892 158432 xzdec_5.4.1-1+deb12u1_amd64.deb Files: ea05aa625930a5ead7e374dd6efd0e3b 260236 libdevel optional liblzma-dev_5.4.1-1+deb12u1_amd64.deb 7d2d5459f0a12b104c6885f5f8c723d8 267772 debug optional liblzma5-dbgsym_5.4.1-1+deb12u1_amd64.deb e27683a2dcc96c39edab4ae11a21d5d2 205732 libs optional liblzma5_5.4.1-1+deb12u1_amd64.deb ee27654a1e1a510450b5d848cef13c52 90060 debug optional xz-utils-dbgsym_5.4.1-1+deb12u1_amd64.deb e57f2a0ddae91eed41701994d0171ed9 7947 utils optional xz-utils_5.4.1-1+deb12u1_amd64-buildd.buildinfo b30c9c676f9d9ddc78322c8dfa945c8b 471212 utils standard xz-utils_5.4.1-1+deb12u1_amd64.deb ad3c007176d9bda240ddb1637f2e413b 124232 debug optional xzdec-dbgsym_5.4.1-1+deb12u1_amd64.deb b320e0726f954f822b0d6986ea869828 158432 utils optional xzdec_5.4.1-1+deb12u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5ZI1lXv5WjhHIVjsN8Ugyu9dQiQFAmpJEFkACgkQN8Ugyu9d QiQmCBAAsooOZ1m+Ozqbeu2L6Za9xgCVLo3yETnM28yAS7U8qh3tjpEX3m9dfAAA 45EH4nqXiaFDp0D+DrPI/n9OJv8w7cDFy4xppZgGDvcngM343J+MgS8ye65BXfy/ OfL1EljarOrNDY76geSiClowkmIK9/qt2uAKKOf7zZDy5qE3ICXq2UUpmrC2yLqQ 99eG5Y8BfzalH/dH1FuxeZEWrt5oSThzDis163VPdxFD0ty4yawoX8xVnu72UXyf Nhj+SbWeAgpY+KaCAaNqoKjhp/pdDmRIPahdD56F56iDCBjj+bNT4PZWEr9JTO3r 4gIAol/l/MejkZohdOHFAFsVsCYXdtvKML+aSN/w0qXkJHhS8WD+Vf1lvo7S5rJs tV55kJuofBC96kIEZYCP3M3sSNZB1SQrY2F7sZg5kJi2/IlP64AokW7FuAXs9RQd KuVkx33p/HYnYpudypC1Ocm3HZ6aIDD2DcLofdKzM/NqA/d2OuCGBJS03Usc253y xL5WqU5cyc6PaR3mCn/+OJnLGTZNyHqwIYelGmCzW1BecCipcAZDkxBJCHxTMwgO 16vftRhPuB+qwvTylGzBVhywQnQ9Q+SyNQ39Zcf6nUFbVR7Sy9/wLD8B/7HXiIRl C4D+XpJvQue0A5HnUNmAAUpKK7knYmmo6lmj+aw5c3Dk7uCLIYo= =l6Jt -----END PGP SIGNATURE-----