SECURITY UPDATE: memory corruption and denial-of-service via malicious SIXEL
images
debian/patches/CVE-2026-25970.patch: Correct misspelled position variables
and adjust variable types; fix out-of-bounds write caused by incorrect
bounds checks and signed/unsigned type misuse.