-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 10 Apr 2026 19:59:22 +0100 Source: libsdl3-image Architecture: source Version: 3.4.2+ds-1 Distribution: unstable Urgency: medium Maintainer: Debian SDL packages maintainers <pkg-sdl-maintainers@lists.alioth.debian.org> Changed-By: Simon McVittie <smcv@debian.org> Closes: 1133011 Changes: libsdl3-image (3.4.2+ds-1) unstable; urgency=medium . * New upstream stable release - Fixes an out of bounds read in the XCF image loader (CVE-2026-35444) (Closes: #1133011) * d/patches: Add more fixes for malformed image files, from upstream * Normalize formatting (debputy reformat) * d/control: Use substvars to reduce duplication in Description * d/source/lintian-overrides: Remove. This should no longer be needed: the Lintian bug has been fixed. * Standards-Version: 4.7.4 (no changes required) Checksums-Sha1: b3569daef9245bbbcf096df4314b46e8cfad037f 2993 libsdl3-image_3.4.2+ds-1.dsc 74de5e5b7d8a6dd085ce35966bb2d9a61dad232d 305276 libsdl3-image_3.4.2+ds.orig.tar.xz b3fd4779c5051d18d6275f8f6a10f2a19201b454 18692 libsdl3-image_3.4.2+ds-1.debian.tar.xz 032abb1e754762746d960a307d479ca76707b81b 11931 libsdl3-image_3.4.2+ds-1_source.buildinfo Checksums-Sha256: ac8bc06f5f76d55766c144f63fd3c1763b5f919f4c6fc7e20023784fcd4e985f 2993 libsdl3-image_3.4.2+ds-1.dsc 6a3df14cbdce7303a8165bfc3caccccc64df9e726a56204d502172571a3cd78f 305276 libsdl3-image_3.4.2+ds.orig.tar.xz b46b35a2e093697133c4c1c39ed9cc1c4a271be7cc07801565e99572b86f9a59 18692 libsdl3-image_3.4.2+ds-1.debian.tar.xz af987da7331387294968c492f9975b86f93817d7bb55b5d6f4c177c715c56e52 11931 libsdl3-image_3.4.2+ds-1_source.buildinfo Files: 93c91636c82965067383bd93109ef4da 2993 libs optional libsdl3-image_3.4.2+ds-1.dsc 94bfb1fdaea8e315aebfa36736b50e1e 305276 libs optional libsdl3-image_3.4.2+ds.orig.tar.xz f44f1e5876574dc1974deced9d27a43e 18692 libs optional libsdl3-image_3.4.2+ds-1.debian.tar.xz c1d8af287ffc03b501072540f5b24e41 11931 libs optional libsdl3-image_3.4.2+ds-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEegc60a5pT6Jb/2LlI1wJnT6zMHYFAmnZSkIACgkQI1wJnT6z MHZVyg/+JE6YH6L/+MbZtvsUKhkYKQiUTIcZ0gAfdlJCRgFcFSJDVnxjwsyKE03P qom/F8qam37WtasOr44u/jQW4ohZLQ3jeVb23c/lvFcv/r0tCNJPtajE2qiGGr3F wFY1lJEH5MJ/fz/DsETKhf504yrL4wQo5bWcmzRFMSAMeBHJGjZGT/KuG7v2JDxa tBC9UKP/AG1/ZpXjz6K0Z0Gv1FlCmUUIMsPY5Pc8B8YtwMLXnIbdX8AipFrkcfTH bpNdSI+jx8ZWhM8qFHaDP5oWxFgGlyck9fRfElo2SMhyubKc8AnoP7J6GEzc8ALE 2kMsuX/T6QRojlrA6Sm1laYLMkTfHfW3zYa8VORE862jdbaKZhpQTpEMXzjEgbBI dIVzFuCnCBi36rGHByzgwtw8WaNNy7PwA9jhJSrBtfKlc0OFkmHXKpLOazm4dgQ0 djfUm93Sur2NRQV05wGoChqpH7+byiUlFvT5juuLf/gVMSriQRpiPnRBU5yQP/Ml tElawxIYK5ZPVFawYs1nk83stIPOebS+HKdzC61CDSVs8bcPOaEJajDSR4efRC19 RIiMyo/tBTxhsl4t5c/SiZeJii8i0Q1Rjhu2OgsRJTZVXrgn3O0rZckmeAGoZ5Tg UlUbAmrKt6fy4b8QpO8hrUpzKoaHehBruDkKZG6xalN9OvVR0zI= =SAQA -----END PGP SIGNATURE-----