-------------------------------------------------------------------------
Debian LTS Advisory DLA-4704-1                [email protected]
https://www.debian.org/lts/security/                       Guilhem Moulin
July 29, 2026                                 https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package        : libraw
Version        : 0.20.2-1+deb11u3 0.20.2-2.1+deb12u2
CVE ID         : CVE-2026-5342 CVE-2026-20884 CVE-2026-20889 CVE-2026-21413 
                 CVE-2026-24660
Debian Bug     : 1132655 1133845

Multiple vulnerabilities were found in libraw, a raw image decoder
library, which could lead to application crash, information disclosure
or data corruption.

CVE-2026-5342

    Biniam F. Demissie discovered an out-of-bounds read in the decoder
    routine for RAW image files from Nikon digital cameras.

CVE-2026-20884

    Francesco Benvenuto discovered an integer overflow vulnerability
    in the decoder routine for deflate-compressed floating-point DNG
    RAW files, which may lead to heap buffer overflow via specially
    crafted input file.

CVE-2026-20889

    Francesco Benvenuto discovered a heap-based buffer overflow
    vulnerability in the thumbnail extraction routine for RAW image
    files from Sigma/Foveon X3F digital cameras.

CVE-2026-21413

    Francesco Benvenuto discovered a heap-based buffer overflow
    vulnerability in the lossless JPEG decoder used for processing
    compressed RAW data from various camera formats.

CVE-2026-24660

    Francesco Benvenuto discovered a heap-based buffer overflow
    vulnerability in the Huffman decompression routine for RAW image
    files from Sigma/Foveon X3F digital cameras.

For Debian 11 bullseye, these problems have been fixed in version
0.20.2-1+deb11u3.

For Debian 12 bookworm, these problems have been fixed in version
0.20.2-2.1+deb12u2.

We recommend that you upgrade your libraw packages.

For the detailed security status of libraw please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libraw

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Attachment: signature.asc
Description: PGP signature

Reply via email to