-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 27 Nov 2025 21:49:27 -0300 Source: rsync Architecture: source Version: 3.2.7-1+deb12u4 Distribution: bookworm Urgency: medium Maintainer: Paul Slootman Changed-By: Matheus Polkorny Changes: rsync (3.2.7-1+deb12u4) bookworm; urgency=medium . * Team upload. * d/p/CVE-2025-10158.patch: Import upstream patch to fix CVE-2025-10158 . A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. Checksums-Sha1: ce840cbf8420caeebba7ce7d123e7572c4dfd107 2401 rsync_3.2.7-1+deb12u4.dsc 2cad41d1795db6ea34406ec1b2cee99cde1fed0f 38792 rsync_3.2.7-1+deb12u4.debian.tar.xz 5fd537189d90f1d24d37c5f89d2f5f67a3e0501b 7490 rsync_3.2.7-1+deb12u4_amd64.buildinfo Checksums-Sha256: 7cbce0ace45ce5911d6ba0626d26832a472c30ba0b2a1d78af29dd9f27a5480e 2401 rsync_3.2.7-1+deb12u4.dsc 0b478dd1666ad113f1c551bda83d5dba92b1f732eafd71b7aabd617bdd6b3128 38792 rsync_3.2.7-1+deb12u4.debian.tar.xz 3632a105d2573d8abc9b6ab7f5587bc9a73fac9325177a17818e75f1855ba946 7490 rsync_3.2.7-1+deb12u4_amd64.buildinfo Files: 5a6c3b8a8a92c49896ca7e05199a679c 2401 net optional rsync_3.2.7-1+deb12u4.dsc 84beff306717cba657fb188213d23008 38792 net optional rsync_3.2.7-1+deb12u4.debian.tar.xz 72203e29e2d93e364e5dddb438fe0474 7490 net optional rsync_3.2.7-1+deb12u4_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEBdtqg34QX0sdAsVfu6n6rcz7RwcFAmlPUaUACgkQu6n6rcz7 RweHnw//fyfijYRdci+Fk8vQMYtMX6gHphGbv6Mcjz1dEiZGQXILOs5DRjcIz22x YIorDqmKXepIOFgaZiu2aXy4UhrKE+uX72K9XBfaO04tcI6AOUdFIkdpEMjM/ZZe Lnvix8IPPOAxnbckwnmQ7xcYhcXSmWe2KqaQHKHqdSzt5iWPg9EevWmhL61TKLJR IKjBSt+dcr9rV8jsFiOD6CUcqPeZp7LuHyA/ooxSeKcsSIjkw1eCvJj1l5bQHy6U 7iTAtgilhIx/5mb6mJ7PSCQxZ25QWDc689V7BhrudPRP0dbKE4tynjM6pTKtTZZh tDjXvC6oSoRf3foGMM5xneOu2FMa8DrahrnByGF+Jm3wndyol5yRRurX2DtonqnD e5RwxA8+JDD7i6McHZM22Z/dkg/fEyqJeJut9cccGYgOdTviy+G0LguIR2xQ3CCw 1wV/pGWDnESjgNC7+rkKsITeSYWlKECPVcpj78D+nmZLQOUSepl/RuodJaHPxMHE RYzmKVki4+wNhZfIJHE/1ulAruZW+0KeS+Y4MzI4qNrk3yesI6c4TlMvGBb8RuBJ 4oFz7lfnVPHcdyf+Vv5h0sIASAgiCsze61czyh10YSZ4FrXwFBDUMyRdMAoL0j7v LTcl0CKOukXIwhcgKlzJhGWT7ZszebC4gdTnJlvRStVcuKKdcqY= =Mfaf -----END PGP SIGNATURE-----