Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package libraw for openSUSE:Factory checked 
in at 2026-09-30 16:22:03
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/libraw (Old)
 and      /work/SRC/openSUSE:Factory/.libraw.new.1465845 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "libraw"

Wed Sep 30 16:22:03 2026 rev:72 rq:1381326 version:0.22.2

Changes:
--------
--- /work/SRC/openSUSE:Factory/libraw/libraw.changes    2026-08-04 
21:28:41.376172480 +0200
+++ /work/SRC/openSUSE:Factory/.libraw.new.1465845/libraw.changes       
2026-09-30 16:22:58.834170794 +0200
@@ -1,0 +2,7 @@
+Tue Sep 29 07:46:51 UTC 2026 - Petr Gajdos <[email protected]>
+
+- added patches
+  CVE-2026-88387:  incorrect numeric conversion in `LibRaw::parse_tiff_ifd()` 
when processing TIFF tag `0x00fe` can lead to undefined behavior and a process 
crash when a specially crafted file is processed [bsc#1282783]
+  * libraw-CVE-2026-88387.patch
+
+-------------------------------------------------------------------

New:
----
  libraw-CVE-2026-88387.patch

----------(New B)----------
  New:  CVE-2026-88387:  incorrect numeric conversion in 
`LibRaw::parse_tiff_ifd()` when processing TIFF tag `0x00fe` can lead to 
undefined behavior and a process crash when a specially crafted file is 
processed [bsc#1282783]
  * libraw-CVE-2026-88387.patch
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ libraw.spec ++++++
--- /var/tmp/diff_new_pack.vaNY91/_old  2026-09-30 16:22:59.517199357 +0200
+++ /var/tmp/diff_new_pack.vaNY91/_new  2026-09-30 16:22:59.518199398 +0200
@@ -32,6 +32,8 @@
 #Git-Clone:    git://github.com/LibRaw/LibRaw
 Source0:        https://www.libraw.org/data/%tar_name-%version.tar.gz
 Source1:        baselibs.conf
+# CVE-2026-88387:  incorrect numeric conversion in `LibRaw::parse_tiff_ifd()` 
when processing TIFF tag `0x00fe` can lead to undefined behavior and a process 
crash when a specially crafted file is processed [bsc#1282783]
+Patch0:         libraw-CVE-2026-88387.patch
 BuildRequires:  autoconf
 BuildRequires:  automake
 BuildRequires:  fdupes

++++++ libraw-CVE-2026-88387.patch ++++++
>From b41cbbd61951783e0440590dae55411a16185bdf Mon Sep 17 00:00:00 2001
From: Alex Tutubalin <[email protected]>
Date: Sat, 5 Sep 2026 09:36:40 +0300
Subject: [PATCH] check TIFF tag type for NewSubfileType

---
 src/metadata/tiff.cpp | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/src/metadata/tiff.cpp b/src/metadata/tiff.cpp
index bad65053..e7168394 100644
--- a/src/metadata/tiff.cpp
+++ b/src/metadata/tiff.cpp
@@ -569,7 +569,8 @@ int LibRaw::parse_tiff_ifd(INT64 base)
       parse_tiff_ifd(base);
       break;
     case 0x00fe: /* NewSubfileType */
-      tiff_ifd[ifd].newsubfiletype = int(getreal(type));
+               if((type != LIBRAW_EXIFTAG_TYPE_FLOAT) && (type != 
LIBRAW_EXIFTAG_TYPE_DOUBLE))
+                       tiff_ifd[ifd].newsubfiletype = int(getreal(type));
       break;
     case 0x0100: /* 256, ImageWidth */
     case 0xf001: /* 61441, Fuji RAF RawImageFullWidth */

Reply via email to