Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:13284

Опубликовано: 06 мая 2026
Источник: rocky
Оценка: Important

Описание

Important: LibRaw security update

LibRaw is a library for reading RAW files obtained from digital photo cameras (CRW/CR2, NEF, RAF, DNG, and others).

Security Fix(es):

  • LibRaw: LibRaw: Memory Corruption via Malicious File Processing (CVE-2026-24660)

  • LibRaw: LibRaw: Arbitrary code execution via heap-based buffer overflow in lossless JPEG loading (CVE-2026-21413)

  • LibRaw: LibRaw: Arbitrary code execution via specially crafted image file (CVE-2026-20889)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
LibRawi6866.el8_10LibRaw-0.19.5-6.el8_10.i686.rpm
LibRawx86_646.el8_10LibRaw-0.19.5-6.el8_10.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
3 месяца назад

ELSA-2026-13284: LibRaw security update (IMPORTANT)

suse-cvrf
3 месяца назад

Security update for libraw

suse-cvrf
3 месяца назад

Security update for libraw

suse-cvrf
3 месяца назад

Security update for libraw

CVSS3: 9.8
ubuntu
4 месяца назад

A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.