-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 10 Apr 2026 19:59:26 +0100 Source: libsdl2-image Architecture: source Version: 2.8.10+dfsg-1 Distribution: unstable Urgency: medium Maintainer: Debian SDL packages maintainers <pkg-sdl-maintainers@lists.alioth.debian.org> Changed-By: Simon McVittie <smcv@debian.org> Closes: 1133010 Changes: libsdl2-image (2.8.10+dfsg-1) unstable; urgency=medium . * New upstream release - Fixes an out of bounds read in the XCF image loader (CVE-2026-35444) (Closes: #1133010) * d/patches: Add more fixes for malformed image files, from upstream * d/control: Remove Priority field, no longer needed * d/control: Standards-Version: 4.7.4 (no changes required) Checksums-Sha1: 0388e9b699221733b4671dc132415997f9af2af6 2599 libsdl2-image_2.8.10+dfsg-1.dsc 1531a1be596298a44d6be0536797da16e6530c4c 344378 libsdl2-image_2.8.10+dfsg.orig.tar.gz c479ccb213d85d623692152bbec94689f438b40d 16756 libsdl2-image_2.8.10+dfsg-1.debian.tar.xz 2e3f2b402451ec1d5d4491ca5b3a8cac5030976e 11035 libsdl2-image_2.8.10+dfsg-1_source.buildinfo Checksums-Sha256: 871b4b876f419122d5e3ffa2057bf55934507cf243c83c26beb7116d380b751f 2599 libsdl2-image_2.8.10+dfsg-1.dsc 43645892f93ff140f2d2f1fa3b14c66dd06509d3598a30cd2974ed047ff7bb33 344378 libsdl2-image_2.8.10+dfsg.orig.tar.gz ad68b9729ed9b0b1c0a957a7f186bcd3534c65970e445c29a5d0db98f385b068 16756 libsdl2-image_2.8.10+dfsg-1.debian.tar.xz c06a3899abfab6536d0d80ea8a27668a762d2b1b0cadcb2b71ebe8597034eeaa 11035 libsdl2-image_2.8.10+dfsg-1_source.buildinfo Files: 4966410d333b4eed47067d694dcab0d1 2599 libs optional libsdl2-image_2.8.10+dfsg-1.dsc c478a76fc63bd61df3c0f5dc23081266 344378 libs optional libsdl2-image_2.8.10+dfsg.orig.tar.gz 1f29375dd1dcab0fcb9ae31e57fe1666 16756 libs optional libsdl2-image_2.8.10+dfsg-1.debian.tar.xz 950350dc1862bad8e372ce8975375ddc 11035 libs optional libsdl2-image_2.8.10+dfsg-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEegc60a5pT6Jb/2LlI1wJnT6zMHYFAmnZSmcACgkQI1wJnT6z MHYbwg/+JiuP/LkdtxI7DL1NFgO3SmqEPMerciNArJfDhHHbGlbVMbHVONYfAVBz OTEW2r0r1ehftw6LCO8VP3ZWKCQv7+Z8HBmc3k8WZ03Mqt5FGqs8Od+hXcgF/9lE Ix6p+bxRfLWZSWEAX+/jlXV8XdgRKWxCivqHEWvnbcXIsNrxBpqKEw09pVYca1wP V31UCYyiYaPIhOIca6yWoiOBynOZvzh1Tr1/7ggMjjUBLPa7SLjW6ommWDYXNHmL LJAMr/htrGmGSP1GUbj37M45AtTsCW23nHoUWzDKW6rH7cjsCZgXExbj8VBrJ/EB TtN+vn9I/WD42U4kBng6iu2GJXBEWga/xXaZNqHdEAyByzIQpfj5iyOAezsCijft nxjCD/Vz+Pwjx0yFnNMmFBLLKyAAbXdmxbRsUyRvujTbM2EQdeeLr8aClMUGz64h CVmA7oJZe6HaK6jSDd31PZXOC/QuRaWJnMj6NxoliGeRQN8I6HvV+g/V3SjRXBB6 IiylsHjhZJynwp4iF2FADKJmFs34I+Lf/4jArkAwWmmVyJFxFZ+7VvbWqB1FU/n3 K1yl41wLxt/qVmcwcAN3A25tUewzB8wh+dvU7mcmtxF5GnVNhzGDW1Bk+kDBW6UD F3iiSxQQWvJnv+Jtm/i2hr8IoIcPUF7gwDJNToNoN02z8wiJgvI= =dyuX -----END PGP SIGNATURE-----