Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 499
Alerts This Week
Warning Icon 1 499

openSUSE 2026 libraw Important Patch CVE 2026-20884 Buffer Overflow

opensuse
Calendar Grey April 23, 2026
Scroller Opensuse
An important security advisory for openSUSE fixing multiple libraw vulnerabilities with a crucial patch recommendation.
An update that solves six vulnerabilities can now be installed.

Description

This update for libraw fixes the following issues:

* CVE-2026-5342: out-of-bounds read via `LibRaw::nikon_load_padded_packed_raw`

(bsc#1261499).

* CVE-2026-20884: integer overflow and heap buffer overflow via

`deflate_dng_load_raw` (bsc#1261671).

* CVE-2026-20889: heap-based buffer overflow in

`x3f_thumb_loader`(bsc#1261672).

* CVE-2026-20911: heap-based buffer overflow in

`HuffTable::initval`(bsc#1261673).

* CVE-2026-21413: heap-based buffer overflow in `lossless_jpeg_load_raw`

(bsc#1261674).

* CVE-2026-24660: heap-based buffer overflow in `x3f_load_huffman`

(bsc#1261676).

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.4

zypper in -t patch SUSE-2026-1556=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4

zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1556=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4

zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1556=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5

zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1556=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5

zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1556=1

* SUSE Linux Enterprise Server 15 SP4 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1556=1

* SUSE Linux Enterprise Server 15 SP5 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-1556=1

* SUSE Linux Enterprise...

Read the Full Advisory

Package List

* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586)

* libraw-devel-static-0.20.2-150400.3.21.1

* libraw-tools-debuginfo-0.20.2-150400.3.21.1

* libraw20-0.20.2-150400.3.21.1

* libraw-debugsource-0.20.2-150400.3.21.1

* libraw-devel-0.20.2-150400.3.21.1

* libraw-tools-0.20.2-150400.3.21.1

* libraw20-debuginfo-0.20.2-150400.3.21.1

* openSUSE Leap 15.4 (x86_64)

* libraw20-32bit-debuginfo-0.20.2-150400.3.21.1

* libraw20-32bit-0.20.2-150400.3.21.1

* openSUSE Leap 15.4 (aarch64_ilp32)

* libraw20-64bit-0.20.2-150400.3.21.1

* libraw20-64bit-debuginfo-0.20.2-150400.3.21.1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64

x86_64)

* libraw20-0.20.2-150400.3.21.1

* libraw20-debuginfo-0.20.2-150400.3.21.1

* libraw-debugsource-0.20.2-150400.3.21.1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64

x86_64)

* libraw20-0.20.2-150400.3.21.1

* libraw20-debuginfo-0.20.2-150400.3.21.1

* libraw-debugsource-0.20.2-150400.3.21.1

* SUSE Linux Enterprise High Performance Computing ESPOS...

Read the Full Advisory

References

* bsc#1261499

* bsc#1261671

* bsc#1261672

* bsc#1261673

* bsc#1261674

* bsc#1261676

## References:

* https://www.suse.com/security/cve/CVE-2026-20884.html

* https://www.suse.com/security/cve/CVE-2026-20889.html

* https://www.suse.com/security/cve/CVE-2026-20911.html

* https://www.suse.com/security/cve/CVE-2026-21413.html

* https://www.suse.com/security/cve/CVE-2026-24660.html

* https://www.suse.com/security/cve/CVE-2026-5342.html

* https://bugzilla.suse.com/show_bug.cgi?id=1261499

* https://bugzilla.suse.com/show_bug.cgi?id=1261671

* https://bugzilla.suse.com/show_bug.cgi?id=1261672

* https://bugzilla.suse.com/show_bug.cgi?id=1261673

* https://bugzilla.suse.com/show_bug.cgi?id=1261674

* https://bugzilla.suse.com/show_bug.cgi?id=1261676

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:1556-1
Release Date: 2026-04-22T16:24:03Z
Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.