Описание
Security update for libraw
This update for libraw fixes the following issues:
- CVE-2026-20911: heap-based buffer overflow in
HuffTable::initval(bsc#1261673). - CVE-2026-21413: heap-based buffer overflow in
lossless_jpeg_load_raw(bsc#1261674). - CVE-2026-24660: heap-based buffer overflow in
x3f_load_huffman(bsc#1261676).
Список пакетов
SUSE Linux Enterprise Workstation Extension 15 SP7
Ссылки
- Link for SUSE-SU-2026:1438-1
- E-Mail link for SUSE-SU-2026:1438-1
- SUSE Security Ratings
- SUSE Bug 1261673
- SUSE Bug 1261674
- SUSE Bug 1261676
- SUSE CVE CVE-2026-20911 page
- SUSE CVE CVE-2026-21413 page
- SUSE CVE CVE-2026-24660 page
Описание
A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Затронутые продукты
Ссылки
- CVE-2026-20911
- SUSE Bug 1261673
Описание
A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Затронутые продукты
Ссылки
- CVE-2026-21413
- SUSE Bug 1261674
Описание
A heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Затронутые продукты
Ссылки
- CVE-2026-24660
- SUSE Bug 1261676