-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 01 Oct 2025 02:06:28 +0200 Source: u-boot Binary: u-boot-qemu Architecture: all Version: 2023.01+dfsg-2+deb12u2 Distribution: bookworm Urgency: medium Maintainer: all Build Daemon (x86-grnet-02) Changed-By: Daniel Leidert Description: u-boot-qemu - A boot loader for qemu Closes: 1098254 Changes: u-boot (2023.01+dfsg-2+deb12u2) bookworm; urgency=medium . * Non-maintainer upload by the Debian LTS team. * d/patches/CVE-2024-57254.patch: Add patch to fix CVE-2024-57254. - Fix an integer overflow in sqfs_inode_size (closes: 1098254). * d/patches/CVE-2024-57255.patch: Add patch to fix CVE-2024-57255. - Fix an integer overflow in sqfs_resolve_symlink (closes: #1098254). * d/patches/CVE-2024-57256.patch: Add patch to fix CVE-2024-57256. - Fix an integer overflow in ext4fs_read_symlink (closes: #1098254). * d/patches/CVE-2024-57257.patch: Add patch to fix CVE-2024-57257. - Fix a stack consumption issue in sqfs_size possible with deep symlink nesting (closes: #1098254). * d/patches/CVE-2024-57258-1.patch, d/patches/CVE-2024-57258-2.patch, d/patches/CVE-2024-57258-3.patch: Add patches to fx CVE-2024-57258. - Fix multiple integer overflows (closes: #1098254). * d/patches/CVE-2024-57259.patch: Add patch to fix CVE-2024-57259. - Fix an off-by-one error resulting in a heap memory corruption in sqfs_search_dir (closes: #1098254). Checksums-Sha1: 664428f00fa2d30f533c10128631258c27715e99 1831564 u-boot-qemu_2023.01+dfsg-2+deb12u2_all.deb 834cab0ec6ad0dc2b24a95403808f7ccf21fd2c4 11344 u-boot_2023.01+dfsg-2+deb12u2_all-buildd.buildinfo Checksums-Sha256: 910420a6704ab00f2fd848b51872c4c1e4574637b892470faad35ecff4515fc7 1831564 u-boot-qemu_2023.01+dfsg-2+deb12u2_all.deb 0acbcc59f0989a8b9b6a56cd0b76670bd8bd518fbb4b69f02861a908d2463368 11344 u-boot_2023.01+dfsg-2+deb12u2_all-buildd.buildinfo Files: d3e9908b59d3c38ad7865b15caa58476 1831564 admin optional u-boot-qemu_2023.01+dfsg-2+deb12u2_all.deb 8e54aa1c0f6b78e9a8a79f80065e149d 11344 admin optional u-boot_2023.01+dfsg-2+deb12u2_all-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEj4Fym5GgeZdPqKhrJm69HxMTN+oFAmk1vEkACgkQJm69HxMT N+qmFw//ReSVNidEksj6Pp/TIERPRpNXwqCxtFMVtvC53HysW2t1mK0GZNGBCsAP MxHCzFHeyDFS5cUfzZYvEQD4axfUMuzc0p8gb83XY6AcR3XLe0JVllcxvs+CmUlW 7xLtJo09fe1UNe3HoWVc9DOymF9Gq0sfXPk7h4eLpNiMmqSludkBFrNwlGPZSpQq ivPk7DafMCLvJkuICN2kRDssYKRq5AlbOh1H5N/DJy9+ORFWBdf+7uoevtq+upzw YPXnf+ii45mOPXRcUiX/OhS6qj2WPFctWODkqqyTTZ7uolGGSJfvV8SRblGqIDWY 7j+F2LPYhBVbCljusgqOMZwQoU9KKxKsZIcRxycEvREf4uZIn7fWbmt8uGhQltTt vdBSykGirN4B3kDvXhfyZnQzLOzNekchK8TLkdmaBoEZyf3f8/W457fbqHMEeeH1 NYUykOvoN2xAhkLrXZY6GyltOCuPBhrqZrzBSb2a2u5Z4a7O5wsURTHHM1pT3o+3 nsRiZFRNpaqCTQ71jMeItG74pVvrPCQWCGTDZOic+MHP3h5NGAy7DwIn6jDbHXHD jkgWZNAzeIQ6FjH3CLr6NFJJPDFm2neD3yDxnfxiHhQ4iNQc/QV26Z1RBmp2byBE s7qsaxgcl818Z1Ml8yE7wApZLWq0N91fQcqsUlsHeeVXYM84bCU= =gLp2 -----END PGP SIGNATURE-----