-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 03 Apr 2025 21:55:39 +0200 Source: xz-utils Binary: liblzma-dev liblzma5 liblzma5-dbgsym xz-utils xz-utils-dbgsym xzdec xzdec-dbgsym Architecture: amd64 Version: 5.4.1-1 Distribution: bookworm-security Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-csail-01) Changed-By: Sebastian Andrzej Siewior Description: liblzma-dev - XZ-format compression library - development files liblzma5 - XZ-format compression library xz-utils - XZ-format compression utilities xzdec - XZ-format compression utilities - tiny decompressors Changes: xz-utils (5.4.1-1) bookworm-security; urgency=medium . * Add fix from upstream when the threaded decompresses frees memory too early on invalid input (CVE-2025-31115). Checksums-Sha1: a4f29501fea21f1427dcec42e0e84ee65a5cc27e 259896 liblzma-dev_5.4.1-1_amd64.deb b2d16f9a55de39c753afeacf3d5381eb1758011e 267716 liblzma5-dbgsym_5.4.1-1_amd64.deb 338d5e520e02b93d12089de3badaae28f79fbdc9 205420 liblzma5_5.4.1-1_amd64.deb efc3558c5d272bd167cfc281e225b69a9a60e82d 89992 xz-utils-dbgsym_5.4.1-1_amd64.deb e393c3f10e72bd65232631e27bf543736d603c00 7595 xz-utils_5.4.1-1_amd64-buildd.buildinfo 3517d92d3a8437fb3b14a4546816095a9d5cdbf1 470868 xz-utils_5.4.1-1_amd64.deb 49b9e94f008b99ebfa1170eded7da5caaa2bf594 124232 xzdec-dbgsym_5.4.1-1_amd64.deb b0bc6d06fd1e1d3c2e35f45191cd516497e43f33 158096 xzdec_5.4.1-1_amd64.deb Checksums-Sha256: 2b6ae3713083ac9346a95a031ae1a7df31344344a5242561792d994fc0ee8b9f 259896 liblzma-dev_5.4.1-1_amd64.deb 29c45a5c76bfeaace91b6dd4e4baab3cf0f486b7224f83927de3db944dc37021 267716 liblzma5-dbgsym_5.4.1-1_amd64.deb d321b9502b16aac534e1c691afbe3dc5e125e5091aa35bea026c59b25ebe82e7 205420 liblzma5_5.4.1-1_amd64.deb 6d01492162fdb160c3d0947eea56fea088fbf01768bc0adda2c0bfc041f65a21 89992 xz-utils-dbgsym_5.4.1-1_amd64.deb e1c555d6fe4ad5a99907647052ccc7977263378ec7a6934b18100f30441c5c8c 7595 xz-utils_5.4.1-1_amd64-buildd.buildinfo ca9c0fa95174175ebf60c046eeb3fdfb5059bb135a505532f27681bdb9290dbb 470868 xz-utils_5.4.1-1_amd64.deb 5b830202597efff1f04e760a9089f4871f21e88a01a9bad2029f30d18b5222c6 124232 xzdec-dbgsym_5.4.1-1_amd64.deb 31b3534eae906adaba201444a5cc1e8b621d29fa42b8355240a023c1200e8e43 158096 xzdec_5.4.1-1_amd64.deb Files: 60684dafb88ff9596866e0e184059567 259896 libdevel optional liblzma-dev_5.4.1-1_amd64.deb 956e60330fcd111d53d3170dbc057c0d 267716 debug optional liblzma5-dbgsym_5.4.1-1_amd64.deb a8e1bf8835b44f49e288e3a0e8bb469c 205420 libs optional liblzma5_5.4.1-1_amd64.deb cda338336b1c9ee4ba9ac5c07b2bb093 89992 debug optional xz-utils-dbgsym_5.4.1-1_amd64.deb d1dad10a0d9a259504550782b2b217b9 7595 utils optional xz-utils_5.4.1-1_amd64-buildd.buildinfo 6234a06c1b22e60928825d90f7a68169 470868 utils standard xz-utils_5.4.1-1_amd64.deb 73ef4274c8e0c52b6372b607cce4d06a 124232 debug optional xzdec-dbgsym_5.4.1-1_amd64.deb bde261117427a4ae757e7c6d41b9b35f 158096 utils optional xzdec_5.4.1-1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXNeYFUF3FbHcrtSeIy3Pg040HrAFAmfu+1kACgkQIy3Pg040 HrDxEg//SCSJVOvwZvRSkY7MJA7o8i38LIK6/i2jb+/qRhyzM7z9/gpKxZbrxXNX 4rCAmc0ZqS5MARgAQ1ruIx65fhkRZtJsqIDjZBzBW8PK3gBhDbcQewU2lCImyG2T eWQwPOu2dqbS+RWAUSbYfHu3B6Uw12N+Q/KjkEE/IU4eQvw+loSblN4+WNOJKuG9 EN3tgi74ogxtVTk4vOQPZkDJjWQrsTOqxaSaXYI8OY0svsBjNWaIWAQ9vmtg1RKX 3K3mzLSrJrhjO/ur/uptJAb6E5nZ+3nPea/SsvDx+uZcPPrNL06HL98cgGUNG/QO Vp8Lv9Z58mt1lvJ1Ud1gVZGcd3tWV0YS9HjPSdTeAsvK7Rlt0LDjYdsCzrDhQBLE 1E41noMZO5L/6jKfM+nbrKtrvuPC31PeoX/aMP/WSxsSUBhLd8Mq3tmcVojMQYjd 4naMe1ki56A3MDEVcB5DFuJuCmlRfCUiT7h8NG/OeROmmjTrODUl+m126HOwhuHl 4ksqPe1Q8COydYai0iaQMyb9l3ipKLo8GK2gpq7DOiGwCsqfBnlunWzLOtw6WeEd BF2juqJc3R9dLh7tqLuvIMaYjvfnBhg0wRTEFn7qqnUdubNTIeb8bqTH6CV3qbFY ETeheD7zhos/nuR18EaSoO458pAarQI4xhLLlzJH4rN4GsQ/dPo= =22Fj -----END PGP SIGNATURE-----