From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Thu, 15 Jan 2026 21:12:39 +0100 Received: from metis.whiteo.stw.pengutronix.de ([2a0a:edc0:2:b01:1d::104]) by lore.white.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1vgThv-001iFD-2e for lore@lore.pengutronix.de; Thu, 15 Jan 2026 21:12:39 +0100 Received: from localhost ([127.0.0.1] helo=metis.whiteo.stw.pengutronix.de) by metis.whiteo.stw.pengutronix.de with esmtp (Exim 4.92) (envelope-from ) id 1vgThv-0007r3-6e; Thu, 15 Jan 2026 21:12:39 +0100 Received: from mail-northeuropeazon11022111.outbound.protection.outlook.com ([52.101.66.111] helo=DUZPR83CU001.outbound.protection.outlook.com) by metis.whiteo.stw.pengutronix.de with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1vgThb-0007qu-Gx for ptxdist@pengutronix.de; Thu, 15 Jan 2026 21:12:20 +0100 ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=VLXR4bfCECPsokApaeKT/mxI7H6hn3ayCfloY8XLKNt6GDT/QV0YSKyndFYqOhZk7JjzWAIBXj5XqWhngNovAlgfvsiFOVSNzuYYoXsI2VMZ8exRHkZnnoosVEuqjKwqxZprsFVlzydixo4nXhUe30cSne+TBToj1PEEYJUV8bTOrpYQSj5zkAdJJMmv4TjYwXL6EBz6qFWxmG6sTrg4VaEyVyEUmVAOlFTzWxyaD2tGQ9dSt8op+2MTXGoLJRQIVqtV6VRy6vu5n7DoyyJ6OOUYXypm3q5JnamYNODazbA9nPpcESv0daDnKlTbLZfYhPTyeBmuB8Xbrn0xLjMjXw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=lAldevdZ7MjXnejggfGxGdeo+Wdhc70VDLSwPJ5P/lc=; b=e/udgH5wRFkWhAXDdZap9vBPygkmr8PduALBLGDiGIw73yWH4QhlwNClSMLhXmkRyl4lZlr1jWO7o5b6LpTCTRpghkMFpkGMdcDIpF0SR4LuF+CzehCg1VLhaufht3/a2KSi0RfnA+Xj2oKZLN4Ak0oyb7Ea57Cn+u0CWukSgsMF09aB+tXQyRHhm3+d1sGjS9onGGMd4gBDodnCNpXnWLset+mQfZcpylxJPnymDUZ7x6sttwVF60wxJTCbCXw5cAR+Q9wrAbZK5FrCXtxdVKeFCHesvfrh1UvO4UrKJuPDHvs2qG8mzHQlx6uUyvwhSq69NLlToIiYDmIWLQtiMA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=t2data.com; dmarc=pass action=none header.from=t2data.com; dkim=pass header.d=t2data.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=t2datacom.onmicrosoft.com; s=selector1-t2datacom-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=lAldevdZ7MjXnejggfGxGdeo+Wdhc70VDLSwPJ5P/lc=; b=ByEmOfk4qnqTkiQdAJvJ2WEPQ3sAYtBVQy8K/0TCoswyPg9bgOsGhktGByF8ybdJmwoOwGjToxbZhewmNyq/6pQZwbEKlCsRMGVnr4FrXrkMeI/jgEc6eWNp+SPq0u8DVUZecHkbZsdZxNfNXaTgNHiOvcxvVaD39I2egxKg1EU= Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=t2data.com; Received: from DB9P251MB0618.EURP251.PROD.OUTLOOK.COM (2603:10a6:10:334::22) by DB9P251MB0276.EURP251.PROD.OUTLOOK.COM (2603:10a6:10:2c2::5) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9520.4; Thu, 15 Jan 2026 20:12:17 +0000 Received: from DB9P251MB0618.EURP251.PROD.OUTLOOK.COM ([fe80::a4b2:58d7:8549:4b19]) by DB9P251MB0618.EURP251.PROD.OUTLOOK.COM ([fe80::a4b2:58d7:8549:4b19%6]) with mapi id 15.20.9520.005; Thu, 15 Jan 2026 20:12:17 +0000 From: Christian Melki To: ptxdist@pengutronix.de Date: Thu, 15 Jan 2026 21:12:03 +0100 Message-ID: <20260115201203.1824095-1-christian.melki@t2data.com> X-Mailer: git-send-email 2.43.0 Content-Transfer-Encoding: 8bit Content-Type: text/plain X-ClientProxiedBy: GVZP280CA0088.SWEP280.PROD.OUTLOOK.COM (2603:10a6:150:275::15) To DB9P251MB0618.EURP251.PROD.OUTLOOK.COM (2603:10a6:10:334::22) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DB9P251MB0618:EE_|DB9P251MB0276:EE_ X-MS-Office365-Filtering-Correlation-Id: b544793c-7fc2-4c62-1c1b-08de54726145 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; ARA:13230040|1800799024|366016|376014|52116014|7142099003|38350700014; X-Microsoft-Antispam-Message-Info: =?us-ascii?Q?9Cb49U1E2XzlfMezKod5zzpmNAUDq2Ylwn0n7PWTQbA9TFCxjYbo6GSYLEN/?= =?us-ascii?Q?leeiu889LN8erJw7D+v/z6f8OZHbQ4SHmIw+Ez7yFS0kLKy7CqZMH9Yeedeu?= =?us-ascii?Q?aSTI1Avy87h3LJ50TqNEA4R3D5JOTvk1nUzb7oH/glyMWV2VQLpVjSbWYTvR?= =?us-ascii?Q?H4NZRAM7Cy+tbjBDDBrXsetxtUjHGerYrFTjHQZvkD6VQMwQE0VJySzmveZH?= =?us-ascii?Q?BOT2rbMDD5IOaLenzMZaSiprPcnlz1mUAzS9JAkh9oAh2N4tHKTeLJkJ8RFd?= =?us-ascii?Q?re+xMX3Tb9lcvskEl+dSus0Ech++jH0VjqhdIuyOKepeO4xM3poCTyYKWVid?= =?us-ascii?Q?64FP4yz/3s6dsggcMQHssYjacqtc2PFls91CkajKsPxQ+uToIz42e5gcPeW4?= =?us-ascii?Q?ZfJSbFFdirpFq4p4rHeiJ6Tv7chM0CxVx6ZrDTdLGaTCWmtmhp95YVwt3TCB?= =?us-ascii?Q?iEgSxE9qw49qk/bD/pZXon3WsEWNbKoIuglxO5mz9OjceBlYtgqJhZ7g5+dB?= =?us-ascii?Q?Qw1bq4cI7rMIUX8NHPUh319/L/zr+HDbR2rlW/NnAGb7B15nmxj6fkyPA+jT?= =?us-ascii?Q?HZurgdeMENDwIsCs1pC2UcdQnyoyXnNZwF+evx/J+G7vqXkrHH6ZqQTsLPi6?= =?us-ascii?Q?LLcvwVaDgsd+3s9v4mZ2Zp5lYhqB3JSR7GlT4N4vsMv8NErSrXwfmCGJ1QYU?= =?us-ascii?Q?gt3luES36rP/2a5+Wjn+zVQYV18IKES8XYT+RImzLKIGBoGr/m/Iwqzosj3P?= =?us-ascii?Q?I2aaFK4XHeTOrh5cRYnrMDSmlnFO8o3fBy7VEpx+bLSQLdBVrqysBtbJOFc4?= =?us-ascii?Q?tBxrhahuEcdtWaaBvQcDmo6enjQLQOfJ62SMhyF5V5BUcvbSPSAQMOl7NEl8?= =?us-ascii?Q?I/MVcGjb8AsNZyjQu3iSEdb95Zu0jXAk2aELlFDfwRO+Qy+u0KjnH9az1HaR?= =?us-ascii?Q?UuhgPwz+AvKpZYwvvYnD2w7XR56s4+PTBSHc4HKYRclN5/xHsVKQ0A8ys2zm?= =?us-ascii?Q?a8FWjnNHNn5G+D7/DgdwZrAx3RIs6cEU4KcAXMuOMRm+2EJqXw2GNO4Pv63U?= =?us-ascii?Q?tBK6RUaeLOCtDJ/Ngch/r6Zc3G+foER66GS/PzolgdKGKOFDX3Gf0L9XzgZY?= =?us-ascii?Q?Mptqg5EsSP2+8ZMNg1Fe4cNlPDk38/uuydUbzAgkiyLZQbt93TLg4Fc319A9?= =?us-ascii?Q?z5s96+nTusICzLlXubbp0cT7PAyuu+7YpiSRwCbS5tyt8eztyayqgoigOmfN?= =?us-ascii?Q?gOxy69U2q9VxqoAhgowpSQ3sgh0Om06lUltdpGGCb3ZBELv44amSGmbNU3AV?= =?us-ascii?Q?cZWVK5aCjbyNI7HHVr7yHOwWJJ3whks6qiT5GvAxlgy1rYHyByfN21Umexth?= =?us-ascii?Q?4siodCTmNlD3lInLxnlKQaIN2YlzdqARCzMbBPdA7i6tz62pueHmA0ALZZ4K?= =?us-ascii?Q?DK8g49xDCw1PHCQT17zeUzpiRdKMGF0IO3ndchYSGx6RgtBerLJwq1IWzmY8?= =?us-ascii?Q?wCPcCdM/jdgZiusiOxyTRLN8mSpS9qYhyq7c0PN0/08387GM0XyGcbP5CZ+h?= =?us-ascii?Q?A4vKwpIHd8lWTFKwW75LiVwLmuOwK7zkWTdDY9yMMh0EPpN+KpEf6+wMo10S?= =?us-ascii?Q?e41IkV+iefDnp6zLXkbeteg=3D?= X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB9P251MB0618.EURP251.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230040)(1800799024)(366016)(376014)(52116014)(7142099003)(38350700014); DIR:OUT; SFP:1102; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?NtVj7+zScO0vGSkNfhx+tRA+cFmbpzvcVz2broeXazZ8SydQwBQN/oXSeCxL?= =?us-ascii?Q?tYC3Lm81FKyKP1asxu02TpsNSVVstZ3PbyulV1GijX/0WRZs8016tjMu+Iaj?= =?us-ascii?Q?IFvm2KayXRQvTjaqPoL3SWtecRryVDk7UNHESw2gO5CzbnUX025AKz2HocyH?= =?us-ascii?Q?Gywn133FWY+08D25j+rvLEvLncj+05FhdMYyZXWNIFI6Tf29/lTu1bxo///I?= =?us-ascii?Q?rAwYhRgNGYWuG355BvJwCTVxFryOhhngSFP/PMKFd9Y+6vErA/VTRt/UaUzR?= =?us-ascii?Q?teDJHmRvnajeVyTtn8iKKQm6WwnqakPcj46G4y+yhSCrprasomF6N/o3JTe2?= =?us-ascii?Q?Rsc1zluqBYxXl61S/WN08QIQUgwjkxIvGjCKDXys1aHW57QgUNeGf3Qa1Jps?= =?us-ascii?Q?48zP9XgoWWsw2AnWRw7DLTemJiWVIk63aa2whGc1QMk7dBwzCXNBK3jJLt82?= =?us-ascii?Q?zK2Dr+/lIZ3Ls//BDyFBPwvH4LUhg1tR7ZfT0Clja3Q11ckEM5/XeLpqanCa?= =?us-ascii?Q?XP1LpP2VCOIsd20u8qEa/M+0tk4kbdPFHNGt+yJUqcs3wQWY8egfoXWVdYVf?= =?us-ascii?Q?vjZ3HgItHDYW39TBTB7gJy6S0PD4uk4FNVjjbKgG2J+WefYX8r78PuPTy0WG?= =?us-ascii?Q?zKTooCHsnqZOhHPLxe4s+pW9p0cqAku8ZpImZTowT0C7xGPQGyiqgjFK6zyV?= =?us-ascii?Q?jL4329sIkYjiZuUwPs7lIkCyGCgjwnsqcwCd4bXtWF2AsQe/Vl0td69fIL4O?= =?us-ascii?Q?kENcpX0YiJnNV5WNKJ6T3veP2fM4ye2mkSP+/pkSrIMfvt0oBUMniM5E4sz2?= =?us-ascii?Q?zs1xdVb5H8ZgycLYE32t9GbvSvEkFRsBNu8t5+3/UF31wd4yYBwxcJXw/2uX?= =?us-ascii?Q?oD1JpLg2d6xd4TQv75iMBL0xckwOZm2MvtwsohP2RKzXKtZ0PGU6D38sU3tl?= =?us-ascii?Q?5OhJfmBJA/kwf4D5AYjzUAR94aER9YNQyNAVCracVBxBYO9Z1QxGi4rxLObZ?= =?us-ascii?Q?lYZ6GiU2bb75qzeEGpVojfICKk0+iGDxK5vcM+WXULbcFCaXJm+P4CiZmkXf?= =?us-ascii?Q?5VIA8mMsW+Rw8EThA7zK9e599o7uQ+JmWly+Zr180KNpkRrA+vrXxPFOcwMG?= =?us-ascii?Q?u7hW1zs5Z0kvQ1CFUJXkES59dnEaIZW2Dihql/BrSB9InOhWsMaova8+cGVg?= =?us-ascii?Q?UqGIUdapCgKLZh7VneBbtPIYuFyu7f/0rxrmH6LdESjlv4sDoO9mwHzwlZJT?= =?us-ascii?Q?evnvaOGGTRwQw7+E9dKyQYmm8OoieIP1GMsK05C8Jro1SCSnnP2IQRfwwmsd?= =?us-ascii?Q?3KvjZNOb+0s0td2Un8BB2//f1xEj9PXAvXHW4yMt1uBi2K20DJBYLjlnMn3c?= =?us-ascii?Q?L5HwGZ5Uu1dcRd5v8tiHTDKxS6zI/8e7YkJshzrPpRYnUJ6Jnof3eAcAH2iL?= =?us-ascii?Q?RHxL4nF+x5hfXbYZV45YuyMpmE9bU0umnueiJmOQcuulA6RZIKpID/hRRQEp?= =?us-ascii?Q?liuz9zFX+vlm7d4zeFmowhTPHj7XlqaWSp86anDOruezI+d/ruwGm4Jq+sW0?= =?us-ascii?Q?zRJDWc5sdCKIExUYZ0I/HhWznaDzQbjUC++54X88/Qcv9rWq4pRZu1zgXVzE?= =?us-ascii?Q?pGpknPgJYIGVr+fGikkdcksnzEtXjUUs8TQVIu/ZlhZbFIF3l+2WOX4ScMsa?= =?us-ascii?Q?wO1ptlKgDMjItvajI4b9O0bz66fwCHW9ZCZ5ULSpIlZA3qGmCv8Eeb55lp7F?= =?us-ascii?Q?7FsAxglwhJoiRiXHcnUcEyhT3vSUzos=3D?= X-OriginatorOrg: t2data.com X-MS-Exchange-CrossTenant-Network-Message-Id: b544793c-7fc2-4c62-1c1b-08de54726145 X-MS-Exchange-CrossTenant-AuthSource: DB9P251MB0618.EURP251.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 15 Jan 2026 20:12:17.0439 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 27928da5-aacd-4ba1-9566-c748a6863e6c X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: XFW2TJhflOS5HI8S+8cG60KpPPb17y7nDa3SdEbEyPjZ3ymx85goBy/DosbcywsolqZVdo+7P2LPkHKXF/L6CexcR+ATdnahdwMbQmZAU9A= X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB9P251MB0276 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on metis.whiteo.stw.pengutronix.de X-Spam-Level: X-Spam-Status: No, score=-2.1 required=4.0 tests=AWL,BAYES_00,DKIM_SIGNED, DKIM_VALID,RCVD_IN_DNSWL_NONE,RCVD_IN_MSPIKE_H2, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED,RCVD_IN_VALIDITY_RPBL_BLOCKED, SPF_HELO_PASS,SPF_PASS autolearn=ham autolearn_force=no version=3.4.2 Subject: [ptxdist] [PATCH] libpng: Version bump. 1.6.53 -> 1.6.54 X-BeenThere: ptxdist@pengutronix.de X-Mailman-Version: 2.1.29 Precedence: list List-Id: PTXdist Development Mailing List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: ptxdist@pengutronix.de Sender: "ptxdist" X-SA-Exim-Connect-IP: 127.0.0.1 X-SA-Exim-Mail-From: ptxdist-bounces@pengutronix.de X-SA-Exim-Scanned: No (on metis.whiteo.stw.pengutronix.de); SAEximRunCond expanded to false Security fixes. https://sourceforge.net/p/libpng/code/ci/libpng16/tree/CHANGES Plugs CVEs: CVE-2026-22695: Heap buffer over-read in png_image_read_direct_scaled. CVE-2026-22801: Integer truncation causing heap buffer over-read in png_image_write_* * License hash changed, copyright year updates. Signed-off-by: Christian Melki --- rules/libpng.make | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/rules/libpng.make b/rules/libpng.make index 7bd6d2376..f69de3e08 100644 --- a/rules/libpng.make +++ b/rules/libpng.make @@ -16,8 +16,8 @@ PACKAGES-$(PTXCONF_LIBPNG) += libpng # # Paths and names # -LIBPNG_VERSION := 1.6.53 -LIBPNG_MD5 := 0d95e8af31991e976811bbf55f693d2d +LIBPNG_VERSION := 1.6.54 +LIBPNG_MD5 := ba9e86853c794d111398b66a42bfa0dc LIBPNG := libpng-$(LIBPNG_VERSION) LIBPNG_SUFFIX := tar.xz LIBPNG_URL := $(call ptx/mirror, SF, libpng/$(LIBPNG).$(LIBPNG_SUFFIX)) @@ -25,7 +25,7 @@ LIBPNG_SOURCE := $(SRCDIR)/$(LIBPNG).$(LIBPNG_SUFFIX) LIBPNG_DIR := $(BUILDDIR)/$(LIBPNG) LIBPNG_LICENSE := libpng-2.0 LIBPNG_LICENSE_FILES := \ - file://LICENSE;md5=5516d77a3cf75f55a0d37254e3e65a20 + file://LICENSE;md5=9dc350edbbbee660c7d9af79487168f2 # ---------------------------------------------------------------------------- # Prepare -- 2.43.0