Описание
Security update for libraw
This update for libraw fixes the following issues:
- CVE-2026-5342: out-of-bounds read via
LibRaw::nikon_load_padded_packed_raw(bsc#1261499). - CVE-2026-20884: integer overflow and heap buffer overflow via
deflate_dng_load_raw(bsc#1261671). - CVE-2026-20889: heap-based buffer overflow in
x3f_thumb_loader(bsc#1261672). - CVE-2026-20911: heap-based buffer overflow in
HuffTable::initval(bsc#1261673). - CVE-2026-21413: heap-based buffer overflow in
lossless_jpeg_load_raw(bsc#1261674). - CVE-2026-24660: heap-based buffer overflow in
x3f_load_huffman(bsc#1261676).
Список пакетов
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
SUSE Linux Enterprise Server 15 SP4-LTSS
SUSE Linux Enterprise Server 15 SP5-LTSS
SUSE Linux Enterprise Server for SAP Applications 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15 SP5
Ссылки
- Link for SUSE-SU-2026:1556-1
- E-Mail link for SUSE-SU-2026:1556-1
- SUSE Security Ratings
- SUSE Bug 1261499
- SUSE Bug 1261671
- SUSE Bug 1261672
- SUSE Bug 1261673
- SUSE Bug 1261674
- SUSE Bug 1261676
- SUSE CVE CVE-2026-20884 page
- SUSE CVE CVE-2026-20889 page
- SUSE CVE CVE-2026-20911 page
- SUSE CVE CVE-2026-21413 page
- SUSE CVE CVE-2026-24660 page
- SUSE CVE CVE-2026-5342 page
Описание
An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Затронутые продукты
Ссылки
- CVE-2026-20884
- SUSE Bug 1261671
Описание
A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Затронутые продукты
Ссылки
- CVE-2026-20889
- SUSE Bug 1261672
Описание
A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Затронутые продукты
Ссылки
- CVE-2026-20911
- SUSE Bug 1261673
Описание
A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Затронутые продукты
Ссылки
- CVE-2026-21413
- SUSE Bug 1261674
Описание
A heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Затронутые продукты
Ссылки
- CVE-2026-24660
- SUSE Bug 1261676
Описание
A flaw has been found in LibRaw up to 0.22.0. This affects the function LibRaw::nikon_load_padded_packed_raw of the file src/decoders/decoders_libraw.cpp of the component TIFF/NEF. Executing a manipulation of the argument load_flags/raw_width can lead to out-of-bounds read. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 0.22.1 mitigates this issue. This patch is called b8397cd45657b84e88bd1202528d1764265f185c. It is advisable to upgrade the affected component.
Затронутые продукты
Ссылки
- CVE-2026-5342
- SUSE Bug 1261499