-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 27 Nov 2025 21:49:27 -0300 Source: rsync Binary: rsync rsync-dbgsym Architecture: mips64el Version: 3.2.7-1+deb12u4 Distribution: bookworm Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-03) Changed-By: Matheus Polkorny Description: rsync - fast, versatile, remote (and local) file-copying tool Changes: rsync (3.2.7-1+deb12u4) bookworm; urgency=medium . * Team upload. * d/p/CVE-2025-10158.patch: Import upstream patch to fix CVE-2025-10158 . A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. Checksums-Sha1: b4f0af693958eb1d38d63cd4842375e99a380f9e 541436 rsync-dbgsym_3.2.7-1+deb12u4_mips64el.deb d11b71932a1619584b9f15bccb7aed74a5249953 6878 rsync_3.2.7-1+deb12u4_mips64el-buildd.buildinfo 682ec391a1a134f1c34a746d9175080ace237521 405164 rsync_3.2.7-1+deb12u4_mips64el.deb Checksums-Sha256: c709b78a23f1dadc8db146e3d5c794adb738362f7946995e3837009c722cc260 541436 rsync-dbgsym_3.2.7-1+deb12u4_mips64el.deb 144ac22ceaea6c6dbed6a7ef4cc8a369d9a645a80010c59eea50bb7870a01ea5 6878 rsync_3.2.7-1+deb12u4_mips64el-buildd.buildinfo 0f012f839be54f5fa90bc97a2bbd51e3412f52667a234db117138d68a7b33fb6 405164 rsync_3.2.7-1+deb12u4_mips64el.deb Files: da0c1c3c54a3c9f76fe40f6be11b1dee 541436 debug optional rsync-dbgsym_3.2.7-1+deb12u4_mips64el.deb 6d74b67677e4c22dbf3422e7e6692221 6878 net optional rsync_3.2.7-1+deb12u4_mips64el-buildd.buildinfo 673bf7d8f0cfc05a4547ede5a567f341 405164 net optional rsync_3.2.7-1+deb12u4_mips64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEesE3YcWKZXIkRPMemf85J+x5/aoFAmlQTgMACgkQmf85J+x5 /aoBiQ//dbK2aZ+Ou1Feu6Tpdi4avFQ5a/ynTfJOSgY2zAPFAx6PAxyyvd90oI1A L/KXqLzsxE/QaNoOEqRpnxfNSYxNldddIBYingeTXFs9QE8HELjtFelxOHqjxXkZ wqn8jDvQXfbVirlJoZUT4JsKOcjoLCzcBJ62NnsDd3pBrtmGO7ZvK4Jo+E2QLW/g Ng3Z1JBBs9ow7fim+vMLdAbMDNs6cB9+EtyOWNhyKihDt4A4Gqy05qE4jT6xtkuH dej0sbtL+qMjNPUVy2QsHddsVWkmt3ZwYx0bubd2xTcRZ8i2ETtXof8JFA0J6yay BZpZLtSXH8itmcDOs0neveF/a9Ih7JHNuFH1pOwk/tjduikasldfaejhzs8hEKAx xHNQOzFBbY4bLN3cwIwdmUOL3paewHBz4YGaJi8qhdE40/1UQUglZ6BCYtDTts4L SWQPUdPKbfFtpK1NqcoJkf6n93NytjXe6F+ULzryFoIAhY4UgFgp1zsXbr/Bldfc 3kxmqPjomPE18qqVdeYIwjecaPMJcRxlv2C7CGlNPA/3o1kbb+pfkGE342H7pryV Ru7N25zIcXlVaorHgsWR4ukDze6aoqEjkXXt88QVf9jfhK72JT2NJblRUBUNWoV9 No5gd8QJrEpyZK48YRBKLIjSsFo+p01ev0bJ1m/BEUFFV8W6nqs= =6bDd -----END PGP SIGNATURE-----