-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 03 Apr 2025 21:55:39 +0200 Source: xz-utils Binary: liblzma-dev liblzma5 liblzma5-dbgsym xz-utils xz-utils-dbgsym xzdec xzdec-dbgsym Architecture: i386 Version: 5.4.1-1 Distribution: bookworm-security Urgency: medium Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Sebastian Andrzej Siewior Description: liblzma-dev - XZ-format compression library - development files liblzma5 - XZ-format compression library xz-utils - XZ-format compression utilities xzdec - XZ-format compression utilities - tiny decompressors Changes: xz-utils (5.4.1-1) bookworm-security; urgency=medium . * Add fix from upstream when the threaded decompresses frees memory too early on invalid input (CVE-2025-31115). Checksums-Sha1: 6208216396d1ff6810e3458bcfb2e80f8f9131dc 272420 liblzma-dev_5.4.1-1_i386.deb 0846050b8ec610fb0eb94a971f63e12378fe0c7e 242376 liblzma5-dbgsym_5.4.1-1_i386.deb af174b2aacdf3ea2088298acd30eb55b43eb817f 214520 liblzma5_5.4.1-1_i386.deb 63bff184cfc78a8ee9901320e21ba98959009488 81488 xz-utils-dbgsym_5.4.1-1_i386.deb 28de2e49f5c50dbd331878346d68734ca24fb4d9 7536 xz-utils_5.4.1-1_i386-buildd.buildinfo 4239560c5e9264ca7b5b782a8ed3cc5540b58878 475412 xz-utils_5.4.1-1_i386.deb c39d1320947df8c99c80910585973f535442aad5 114764 xzdec-dbgsym_5.4.1-1_i386.deb 9a5e1c975e443f87e19f7a99896cec25ddcd7843 161980 xzdec_5.4.1-1_i386.deb Checksums-Sha256: bf16023fb5507d504c7212f21d4f0742f5b6557018e8fbe8f945a9b6262d7cea 272420 liblzma-dev_5.4.1-1_i386.deb 1bbc3296031932a810b31f64c894121190c6da5732aa9ddc3a8ddc723a4d9b1b 242376 liblzma5-dbgsym_5.4.1-1_i386.deb beb15a6116bc404a0c3db7c978e08a32c988717d84b6c48db6ac16afbbb9ff92 214520 liblzma5_5.4.1-1_i386.deb ad17e6aade7efe319fa6f67e53c57c5ca2f8c956b2524449efa079103c8d44bf 81488 xz-utils-dbgsym_5.4.1-1_i386.deb 70b962ab311c432e8d635494eef65a56a0af57d7cf16b5a22d003e036e935b23 7536 xz-utils_5.4.1-1_i386-buildd.buildinfo ab6f2957a59046f2ad3de23f795017c152f78193aa305c8b55899e4166726ebe 475412 xz-utils_5.4.1-1_i386.deb d636704a7ec1e372a6a5c30a6756865b15b1cb0eab1de5cbc5cf30312334283b 114764 xzdec-dbgsym_5.4.1-1_i386.deb 0cc9a3e1403062297122e65273633b6edcae5e6bc0a27fc91ffadf5e89d7b328 161980 xzdec_5.4.1-1_i386.deb Files: 3194614222fd4099c836f79cbe1fd346 272420 libdevel optional liblzma-dev_5.4.1-1_i386.deb a6135362a295047844f087cab7cf4439 242376 debug optional liblzma5-dbgsym_5.4.1-1_i386.deb c3b6351ab0e5a2a7a2adf21ce6da1ea1 214520 libs optional liblzma5_5.4.1-1_i386.deb c2c1e0d7617079d67d4fd75145f7bb50 81488 debug optional xz-utils-dbgsym_5.4.1-1_i386.deb 8ae5be3c07a5be5106f70276d7ce0d38 7536 utils optional xz-utils_5.4.1-1_i386-buildd.buildinfo 4d513838454579012c020d37ea779c63 475412 utils standard xz-utils_5.4.1-1_i386.deb 126f4f20a53e45924ac3a7e134c9f860 114764 debug optional xzdec-dbgsym_5.4.1-1_i386.deb a4504f9f64f58c0a33241e9a492001eb 161980 utils optional xzdec_5.4.1-1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEv2qEY4xQXyY/2dWIvGw9w6VrLCcFAmfu+0wACgkQvGw9w6Vr LCfaJg/9FOL59FgbJOM/Snr+uCN7CfzwozJ8TwjN7pwn4gilZsWtdeLCbSAS7B1h FkYptupPbqcF1Jeh1KpqMbq3nV6k/3wvSQfFpJLXahkLYahYmYURWrEMqAtsG9vY 4JB4nNQCvaLS8tpfyeca9cTtE02MB04iRy+rqulHQP0p7ly6V369V6n9PybAnyBy GLe0UhVUIkXw7cSHsnZuXDSbPqH9P8vkE589vW7lHaX9UB5ctRlyCeKSGnsl4pn9 nzXffMIdsEUpiprFwy7R1GoMlSqbNCl6sp3+GD1H3NUK8+9t756JBU79qWKQMNEB cWjYMgu7diUDu8gi00twBgxrIgc0yOIuOBcnm+71B3Nm2rLMiwspZrnah90hGWCQ N6K3VVG74uXJ9JDNQsivfJIBvHhiAbYa/6SWPrkAfYq3zozZd6plWhALCKxTnTBv lPRQFfB7gueka16338Tqhb2De4Pxw7dCsBQPlq/g9EW3oyDUoxuiI+PDKhPHZKUN RoT6AwYp1Ldy5/tH3uEoPxBoSJUkHvGXxbmN37xUH12/QFYE4IYYbg9XRkivstk/ Fi2wXGcA4ggauHO0OuNFUiKzlM3TrwWscwD+7u1ie2tNkLOU2I/ryEfAMjYylz3k xBW+HAzf/cPO11r0Ea5u+Mu275wqJhGZ1yP+60oLqjvf4XSrXKE= =ltkg -----END PGP SIGNATURE-----