-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 27 Nov 2025 21:49:27 -0300 Source: rsync Binary: rsync rsync-dbgsym Architecture: ppc64el Version: 3.2.7-1+deb12u4 Distribution: bookworm Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-osuosl-01) Changed-By: Matheus Polkorny Description: rsync - fast, versatile, remote (and local) file-copying tool Changes: rsync (3.2.7-1+deb12u4) bookworm; urgency=medium . * Team upload. * d/p/CVE-2025-10158.patch: Import upstream patch to fix CVE-2025-10158 . A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. Checksums-Sha1: 753f392d28c1d62eec7d8e918ae57aca7fc78946 529456 rsync-dbgsym_3.2.7-1+deb12u4_ppc64el.deb 1671ef285bee14b257360e5bbaff2bf63a2454f5 7086 rsync_3.2.7-1+deb12u4_ppc64el-buildd.buildinfo 6f438fce108aa436100e8b67cbfd743c06096ccf 427976 rsync_3.2.7-1+deb12u4_ppc64el.deb Checksums-Sha256: 331f1de24c6c03b41b5bb9bc79aeb9fe7d06e4c18610f85e0e6a1718910bf346 529456 rsync-dbgsym_3.2.7-1+deb12u4_ppc64el.deb 789fcb871fe52d8ad488f4e525269b3acbdd1809f46b286bf18dae416f57b1ab 7086 rsync_3.2.7-1+deb12u4_ppc64el-buildd.buildinfo 880eb2ad375815a64d1c17ff6bbb6ebf746ac3a519c660629d62833008899767 427976 rsync_3.2.7-1+deb12u4_ppc64el.deb Files: 7a98c9dfa1b1e0496c1daa61804917a4 529456 debug optional rsync-dbgsym_3.2.7-1+deb12u4_ppc64el.deb 36b9532b17b0007f7796bc7a3286738d 7086 net optional rsync_3.2.7-1+deb12u4_ppc64el-buildd.buildinfo c261372d04f3796a4e8d38b200189843 427976 net optional rsync_3.2.7-1+deb12u4_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEGHWM+bJZRznwgySGOrVShFbIMGEFAmlQTa4ACgkQOrVShFbI MGHHLw//Uy3wDj8MDCbiVwso01sFVKhRfUMguqGCTSFRdIQ3nMeLyIMUYPgLXMIC MBcPfhZRGW1XqF0cEbnpvX3UY8UsEl5k9QB2S6jGPKj3vI6sNsJIryCG/WZbznUQ 8ext7tl188C3QF03rAV5atS6NAZL9M+Yf/xkf/yPuQPELJBKsdBsI7sjT40YLIs8 qsPaSvyfgKjAX+RMBTRaTqv0eb/J+0PgOmouAF1gOSJG30b6+Pi2fMuO/EezV4Fg Hlqb6ucQLUgHpfYo3obZB0UUrGHXeSzTlU+L4xJHK626mOz53oiu1BgG6ckTHU6l SoRximedY3yUXIDdYhw8+OvTNnnj9wxe4wtXOm3UxvOR2TFhdTRwNVb2uTmM+FXF iKlcM8gqe2MXsZNGIWg1ueckiGj+3KClA+Clb/948wakw37kaiSljDHpaPn/oeHo qAd+9cMSVkvhNUTNuF1tPKKGQBagSnnc64eBRL6B5CcUOi1T1HvDVBqPnlJKcg3c xc4oHU3Oab6pECJdW/NBXQFMZ01RYL5M1MfGgEyqSf8xvY0XkMybJVuWz83X9xlk nNEL+k/9g5lkpUio8QmTE5yYeVBvd1KfRn9McUxi3tOGBZ6wMl2emIJZfnkpDSK1 mInvlij2HbOKAFPS+CxcehWSl3SkceHaoObQe2iDqB/ahYJ0CJU= =2xtf -----END PGP SIGNATURE-----