Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:1438-1

Опубликовано: 17 апр. 2026
Источник: suse-cvrf

Описание

Security update for libraw

This update for libraw fixes the following issues:

  • CVE-2026-20911: heap-based buffer overflow in HuffTable::initval(bsc#1261673).
  • CVE-2026-21413: heap-based buffer overflow in lossless_jpeg_load_raw (bsc#1261674).
  • CVE-2026-24660: heap-based buffer overflow in x3f_load_huffman (bsc#1261676).

Список пакетов

SUSE Linux Enterprise Workstation Extension 15 SP7
libraw16-0.18.9-150000.3.33.1

Описание

A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.


Затронутые продукты
SUSE Linux Enterprise Workstation Extension 15 SP7:libraw16-0.18.9-150000.3.33.1

Ссылки

Описание

A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.


Затронутые продукты
SUSE Linux Enterprise Workstation Extension 15 SP7:libraw16-0.18.9-150000.3.33.1

Ссылки

Описание

A heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.


Затронутые продукты
SUSE Linux Enterprise Workstation Extension 15 SP7:libraw16-0.18.9-150000.3.33.1

Ссылки