[ubuntu/resolute-security] libraw 0.21.5b-1ubuntu1.1 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Thu Jul 9 12:38:56 UTC 2026


libraw (0.21.5b-1ubuntu1.1) resolute-security; urgency=medium

  * SECURITY UPDATE: OOB read via load_flags/raw_width argument
    - debian/patches/CVE-2026-5342.patch: Nikon padded/12bit: no need to
      calculate padded row size before final raw_width adjustment in
      src/decoders/decoders_libraw.cpp, src/metadata/tiff.cpp.
    - CVE-2026-5342
  * SECURITY UPDATE: integer overflow in deflate_dng_load_raw
    - debian/patches/CVE-2026-20884-pre1.patch: implemented RAW size limit check
      and allocation result check for 4-shot pentax loaded and FP-dng loader in
      src/decoders/decoders_libraw.cpp, src/decoders/fp_dng.cpp.
    - debian/patches/CVE-2026-20884-pre2.patch: FP DNG data limit: perform
      calculations in 64 bit in src/decoders/fp_dng.cpp.
    - debian/patches/CVE-2026-20884.patch: Fix for data size calculation integer
      overflow in float/deflated DNG loader; Check for read results in
      src/decoders/fp_dng.cpp.
    - CVE-2026-20884
  * SECURITY UPDATE: heap overflow in x3f_thumb_loader
    - debian/patches/CVE-2026-20889.patch: Add checks in
      src/decoders/unpack_thumb.cpp, src/x3f/x3f_parse_process.cpp,
      src/x3f/x3f_utils_patched.cpp.
    - CVE-2026-20889
  * SECURITY UPDATE: heap overflow in lossless_jpeg_load_raw functionality
    - debian/patches/CVE-2026-21413.patch: check raw_width in
      src/decoders/decoders_dcraw.cpp.
    - CVE-2026-21413
  * SECURITY UPDATE: integer overflow in uncompressed_fp_dng_load_raw
    - debian/patches/CVE-2026-24450.patch: avoid integer overflow in allocation
      size calculation. Also: check for EOF in read loop in
      src/decoders/fp_dng.cpp.
    - CVE-2026-24450
  * SECURITY UPDATE: heap overflow in x3f_load_huffman
    - debian/patches/CVE-2026-24660.patch: X3F decoder: implemented hard single
      allocation limit via LIBRAW_X3F_ALLOC_LIMIT_MB define; allocation size
      calculation converted to 64 bit arithm in libraw/libraw_const.h,
      src/x3f/x3f_utils_patched.cpp.
    - CVE-2026-24660

Date: 2026-07-07 17:15:11.771084+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/libraw/0.21.5b-1ubuntu1.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list