Explore top 10 tips to secure your open-source projects now. Read More
×Several security issues were fixed in LibRaw.. ========================================================================== Ubuntu Security Notice USN-8522-1 July 09, 2026 libraw vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in LibRaw. Software Description: - libraw: raw image decoder library Details: It was discovered that LibRaw incorrectly handled certain Nikon RAW image files. An attacker could possibly use this issue to cause LibRaw to crash, resulting in a denial of service. (CVE-2026-5342) It was discovered that LibRaw had an integer overflow in its DNG image loader. An attacker could possibly use this issue to cause LibRaw to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-20884) It was discovered that LibRaw incorrectly handled certain X3F thumbnail data. An attacker could possibly use this issue to cause LibRaw to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-20889) It was discovered that LibRaw had a heap-based buffer overflow in its lossless JPEG image loader. An attacker could possibly use this issue to cause LibRaw to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-21413) It was discovered that LibRaw had an integer overflow in its uncompressed floating-point DNG image loader. An attacker could possibly use this issue to cause LibRaw to crash, resulting in a denial of service, or execute arbitrary code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 25.04. (CVE-2026-24450) It was discovered that LibRaw had a heap-based buffer overflow in its X3F Huffman decoder. An attacker could possibly use this issue to cause LibRaw to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-24660) Update instructions: The problem can be corrected by updating yoursystem to the following package versions: Ubuntu 26.04 LTS libraw-bin 0.21.5b-1ubuntu1.1 libraw23t64 0.21.5b-1ubuntu1.1 Ubuntu 24.04 LTS libraw-bin 0.21.2-2.1ubuntu0.24.04.2 libraw23t64 0.21.2-2.1ubuntu0.24.04.2 Ubuntu 22.04 LTS libraw-bin 0.20.2-2ubuntu2.22.04.3 libraw20 0.20.2-2ubuntu2.22.04.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8522-1 CVE-2026-20884, CVE-2026-20889, CVE-2026-21413, CVE-2026-24450, CVE-2026-24660, CVE-2026-5342 Package Information: https://launchpad.net/ubuntu/+source/libraw/0.21.5b-1ubuntu1.1 https://launchpad.net/ubuntu/+source/libraw/0.21.2-2.1ubuntu0.24.04.2 https://launchpad.net/ubuntu/+source/libraw/0.20.2-2ubuntu2.22.04.3 . Multiple security risks resolved in LibRaw across several Ubuntu releases, addressing potential denial of service and code execution flaws.. LibRaw Security Fix, Ubuntu Security Notice, Denial of Service Vulnerability. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-13284 http://linux.oracle.com/errata/ELSA-2026-13284.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: LibRaw-0.19.5-6.el8_10.i686.rpm LibRaw-0.19.5-6.el8_10.x86_64.rpm LibRaw-devel-0.19.5-6.el8_10.i686.rpm LibRaw-devel-0.19.5-6.el8_10.x86_64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/LibRaw-0.19.5-6.el8_10.src.rpm Related CVEs: CVE-2026-20889 CVE-2026-21413 CVE-2026-24660 Description of changes: [0.19.5-6] - Backport fix for CVE-2026-24660 from upstream Resolves: RHEL-165412 [0.19.5-5] - Backport fixes for CVE-2026-20889 and CVE-2026-21413 from upstream - Migrate to SPDX license Resolves: RHEL-165404, RHEL-165408 _______________________________________________ El-errata mailing list
Important: LibRaw security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:13284", "synopsis": "Important: LibRaw security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for LibRaw.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "LibRaw is a library for reading RAW files obtained from digital photo cameras (CRW/CR2, NEF, RAF, DNG, and others).\n\nSecurity Fix(es):\n\n* LibRaw: LibRaw: Memory Corruption via Malicious File Processing (CVE-2026-24660)\n\n* LibRaw: LibRaw: Arbitrary code execution via heap-based buffer overflow in lossless JPEG loading (CVE-2026-21413)\n\n* LibRaw: LibRaw: Arbitrary code execution via specially crafted image file (CVE-2026-20889)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2455926", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2455926", "description": ""}, {"ticket": "2455929", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2455929", "description": ""}, {"ticket": "2455942", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2455942", "description": ""}], "cves": [{"name": "CVE-2026-20889", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-20889", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-120"}, {"name": "CVE-2026-21413", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21413", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-787"}, {"name":"CVE-2026-24660", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-24660", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-120"}], "references": [], "publishedAt": "2026-05-06T06:00:55.617468Z", "rpms": {"Rocky Linux 8": {"nvras": ["LibRaw-0:0.19.5-6.el8_10.i686.rpm", "LibRaw-0:0.19.5-6.el8_10.src.rpm", "LibRaw-0:0.19.5-6.el8_10.x86_64.rpm", "LibRaw-debuginfo-0:0.19.5-6.el8_10.i686.rpm", "LibRaw-debuginfo-0:0.19.5-6.el8_10.x86_64.rpm", "LibRaw-debugsource-0:0.19.5-6.el8_10.i686.rpm", "LibRaw-debugsource-0:0.19.5-6.el8_10.x86_64.rpm", "LibRaw-devel-0:0.19.5-6.el8_10.i686.rpm", "LibRaw-devel-0:0.19.5-6.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. LibRaw security update in Rocky Linux addresses critical memory corruption and code execution issues related to RAW file processing.. Rocky Linux Update, LibRaw Security, Memory Corruption Fix, Code Execution Vulnerability. . Severity: Important. LinuxSecurity.com Team
Important: LibRaw security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:11360", "synopsis": "Important: LibRaw security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for LibRaw.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "LibRaw is a library for reading RAW files obtained from digital photo cameras (CRW/CR2, NEF, RAF, DNG, and others).\n\nSecurity Fix(es):\n\n* LibRaw: LibRaw: Arbitrary code execution via a specially crafted malicious file (CVE-2026-24450)\n\n* LibRaw: LibRaw: Arbitrary code execution via heap-based buffer overflow in lossless JPEG loading (CVE-2026-21413)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2455925", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2455925", "description": ""}, {"ticket": "2455929", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2455929", "description": ""}], "cves": [{"name": "CVE-2026-21413", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21413", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-787"}, {"name": "CVE-2026-24450", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-24450", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-190"}], "references": [], "publishedAt": "2026-04-29T18:03:33.664574Z", "rpms": {"Rocky Linux 9": {"nvras": ["LibRaw-0:0.21.1-2.el9_7.aarch64.rpm", "LibRaw-0:0.21.1-2.el9_7.i686.rpm", "LibRaw-0:0.21.1-2.el9_7.ppc64le.rpm","LibRaw-0:0.21.1-2.el9_7.s390x.rpm", "LibRaw-0:0.21.1-2.el9_7.src.rpm", "LibRaw-0:0.21.1-2.el9_7.x86_64.rpm", "LibRaw-debuginfo-0:0.21.1-2.el9_7.aarch64.rpm", "LibRaw-debuginfo-0:0.21.1-2.el9_7.i686.rpm", "LibRaw-debuginfo-0:0.21.1-2.el9_7.ppc64le.rpm", "LibRaw-debuginfo-0:0.21.1-2.el9_7.s390x.rpm", "LibRaw-debuginfo-0:0.21.1-2.el9_7.x86_64.rpm", "LibRaw-debugsource-0:0.21.1-2.el9_7.aarch64.rpm", "LibRaw-debugsource-0:0.21.1-2.el9_7.i686.rpm", "LibRaw-debugsource-0:0.21.1-2.el9_7.ppc64le.rpm", "LibRaw-debugsource-0:0.21.1-2.el9_7.s390x.rpm", "LibRaw-debugsource-0:0.21.1-2.el9_7.x86_64.rpm", "LibRaw-devel-0:0.21.1-2.el9_7.i686.rpm", "LibRaw-devel-0:0.21.1-2.el9_7.ppc64le.rpm", "LibRaw-devel-0:0.21.1-2.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important LibRaw security update addressing risks like arbitrary code execution in Rocky Linux. Immediate action advised.. LibRaw security update, Rocky Linux important fix, arbitrary code execution. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-11360 http://linux.oracle.com/errata/ELSA-2026-11360.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: LibRaw-0.21.1-2.el9_7.i686.rpm LibRaw-0.21.1-2.el9_7.x86_64.rpm LibRaw-devel-0.21.1-2.el9_7.i686.rpm LibRaw-devel-0.21.1-2.el9_7.x86_64.rpm aarch64: LibRaw-0.21.1-2.el9_7.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/LibRaw-0.21.1-2.el9_7.src.rpm Related CVEs: CVE-2026-21413 CVE-2026-24450 Description of changes: [0.21.1-2] - Fix CVE-2026-21413 and CVE-2026-24450 Resolves: RHEL-165373, RHEL-165456 _______________________________________________ El-errata mailing list
An update that solves seven vulnerabilities can now be installed.. # Security update for libraw Announcement ID: SUSE-SU-2026:21360-1 Release Date: 2026-04-20T15:30:10Z Rating: important References: * bsc#1261499 * bsc#1261671 * bsc#1261672 * bsc#1261673 * bsc#1261674 * bsc#1261675 * bsc#1261676 Cross-References: * CVE-2026-20884 * CVE-2026-20889 * CVE-2026-20911 * CVE-2026-21413 * CVE-2026-24450 * CVE-2026-24660 * CVE-2026-5342 CVSS scores: * CVE-2026-20884 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-20884 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-20884 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-20884 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-20889 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-20889 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-20889 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-20911 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-20911 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-20911 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-21413 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-21413 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-21413 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-24450 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-24450 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-24450 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-24450 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-24660 ( SUSE ): 7.5 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-24660 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-24660 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-24660 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-5342 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-5342 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-5342 ( NVD ): 5.5 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-5342 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves seven vulnerabilities can now be installed. ## Description: This update for libraw fixes the following issues: * CVE-2026-5342: crafted TIFF/NEF file can cause an out-of-bounds read (bsc#1261499). * CVE-2026-20884: integer overflow vulnerability in the deflate_dng_load_raw (bsc#1261671). * CVE-2026-20889: heap-based buffer overflow vulnerability in the x3f_thumb_loader (bsc#1261672). * CVE-2026-20911: heap-based buffer overflow vulnerability in the HuffTable: initval (bsc#1261673). * CVE-2026-21413: heap-based buffer overflow vulnerability in the lossless_jpeg_load_raw (bsc#1261674). * CVE-2026-24450: integer overflow vulnerability in uncompressed_fp_dng_load_raw (bsc#1261675). * CVE-2026-24660: heap-based buffer overflow vulnerability in the x3f_load_huffman (bsc#1261676). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patchSUSE-SLES-16.0-599=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-599=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libraw-debugsource-0.21.4-160000.3.1 * libraw23-debuginfo-0.21.4-160000.3.1 * libraw23-0.21.4-160000.3.1 * libraw-tools-debuginfo-0.21.4-160000.3.1 * libraw-tools-0.21.4-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libraw-debugsource-0.21.4-160000.3.1 * libraw23-debuginfo-0.21.4-160000.3.1 * libraw23-0.21.4-160000.3.1 * libraw-tools-debuginfo-0.21.4-160000.3.1 * libraw-tools-0.21.4-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20884.html * https://www.suse.com/security/cve/CVE-2026-20889.html * https://www.suse.com/security/cve/CVE-2026-20911.html * https://www.suse.com/security/cve/CVE-2026-21413.html * https://www.suse.com/security/cve/CVE-2026-24450.html * https://www.suse.com/security/cve/CVE-2026-24660.html * https://www.suse.com/security/cve/CVE-2026-5342.html * https://bugzilla.suse.com/show_bug.cgi?id=1261499 * https://bugzilla.suse.com/show_bug.cgi?id=1261671 * https://bugzilla.suse.com/show_bug.cgi?id=1261672 * https://bugzilla.suse.com/show_bug.cgi?id=1261673 * https://bugzilla.suse.com/show_bug.cgi?id=1261674 * https://bugzilla.suse.com/show_bug.cgi?id=1261675 * https://bugzilla.suse.com/show_bug.cgi?id=1261676 . The latest SUSE advisory details fixes for important vulnerabilities in libraw affecting SUSE Linux Enterprise Server.. SUSE Linux, libraw update, important security fixes, buffer overflow, integer overflow. . Severity: Important. LinuxSecurity.com Team
Update to libraw-0.22.1. Backport fixes for CVE-2026-5318 and CVE-2026-5342.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-a436c41faf 2026-04-25 01:21:36.172181+00:00 -------------------------------------------------------------------------------- Name : mingw-LibRaw Product : Fedora 44 Version : 0.22.1 Release : 1.fc44 URL : http://www.libraw.org Summary : Library for reading RAW files obtained from digital photo cameras Description : MinGW Windows LibRaw library. -------------------------------------------------------------------------------- Update Information: Update to libraw-0.22.1. Backport fixes for CVE-2026-5318 and CVE-2026-5342. -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 7 2026 Sandro Mani - 0.22.1-1 - Update to 0.22.1 * Thu Apr 2 2026 Sandro Mani - 0.22.0-3 - Backport fix for CVE-2026-5342 * Thu Apr 2 2026 Sandro Mani - 0.22.0-2 - Backport fix for CVE-2026-5318 * Sat Feb 21 2026 Sandro Mani - 0.22.0-1 - Update to 0.22.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2454228 - CVE-2026-5318 mingw-LibRaw: LibRaw: Denial of Service via out-of-bounds write in JPEG DHT Parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454228 [ 2 ] Bug #2454457 - CVE-2026-5342 mingw-LibRaw: LibRaw: Out-of-bounds read via `load_flags/raw_width` argument manipulation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454457 [ 3 ] Bug #2456236 - CVE-2026-20911 mingw-LibRaw: LibRaw: Arbitrary Code Execution via specially crafted file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2456236 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a436c41faf' atthe command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves seven vulnerabilities can now be installed.. # Security update for libraw Announcement ID: SUSE-SU-2026:1555-1 Release Date: 2026-04-22T16:23:21Z Rating: important References: * bsc#1261499 * bsc#1261671 * bsc#1261672 * bsc#1261673 * bsc#1261674 * bsc#1261675 * bsc#1261676 Cross-References: * CVE-2026-20884 * CVE-2026-20889 * CVE-2026-20911 * CVE-2026-21413 * CVE-2026-24450 * CVE-2026-24660 * CVE-2026-5342 CVSS scores: * CVE-2026-20884 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-20884 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-20884 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-20884 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-20889 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-20889 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-20889 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-20911 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-20911 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-20911 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-21413 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-21413 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-21413 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-24450 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-24450 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-24450 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-24450 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-24660 ( SUSE ): 7.5 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-24660 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-24660 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-24660 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-5342 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-5342 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-5342 ( NVD ): 5.5 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-5342 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves seven vulnerabilities can now be installed. ## Description: This update for libraw fixes the following issues: * CVE-2026-5342: out-of-bounds read via `LibRaw::nikon_load_padded_packed_raw` (bsc#1261499). * CVE-2026-20884: integer overflow and heap buffer overflow via `deflate_dng_load_raw` (bsc#1261671). * CVE-2026-20889: heap-based buffer overflow in `x3f_thumb_loader`(bsc#1261672). * CVE-2026-20911: heap-based buffer overflow in `HuffTable::initval`(bsc#1261673). * CVE-2026-21413: heap-based buffer overflow in `lossless_jpeg_load_raw` (bsc#1261674). * CVE-2026-24450: integer overflow and heap buffer overflow via `uncompressed_fp_dng_load_raw` (bsc#1261675). * CVE-2026-24660: heap-based bufferoverflow in `x3f_load_huffman` (bsc#1261676). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-1555=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1555=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-1555=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1555=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1555=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-1555=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * libraw-debugsource-0.21.1-150600.3.10.1 * libraw-tools-0.21.1-150600.3.10.1 * libraw-devel-0.21.1-150600.3.10.1 * libraw23-0.21.1-150600.3.10.1 * libraw23-debuginfo-0.21.1-150600.3.10.1 * libraw-tools-debuginfo-0.21.1-150600.3.10.1 * libraw-devel-static-0.21.1-150600.3.10.1 * openSUSE Leap 15.6 (x86_64) * libraw23-32bit-0.21.1-150600.3.10.1 * libraw23-32bit-debuginfo-0.21.1-150600.3.10.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libraw23-64bit-0.21.1-150600.3.10.1 * libraw23-64bit-debuginfo-0.21.1-150600.3.10.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libraw-debugsource-0.21.1-150600.3.10.1 * libraw23-debuginfo-0.21.1-150600.3.10.1 * libraw23-0.21.1-150600.3.10.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x) * libraw-debugsource-0.21.1-150600.3.10.1 * libraw-tools-0.21.1-150600.3.10.1 * libraw-devel-0.21.1-150600.3.10.1 * libraw-tools-debuginfo-0.21.1-150600.3.10.1 * libraw-devel-static-0.21.1-150600.3.10.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libraw-debugsource-0.21.1-150600.3.10.1 * libraw23-debuginfo-0.21.1-150600.3.10.1 * libraw23-0.21.1-150600.3.10.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libraw-debugsource-0.21.1-150600.3.10.1 * libraw23-debuginfo-0.21.1-150600.3.10.1 * libraw23-0.21.1-150600.3.10.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * libraw-debugsource-0.21.1-150600.3.10.1 * libraw-devel-0.21.1-150600.3.10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20884.html * https://www.suse.com/security/cve/CVE-2026-20889.html * https://www.suse.com/security/cve/CVE-2026-20911.html * https://www.suse.com/security/cve/CVE-2026-21413.html * https://www.suse.com/security/cve/CVE-2026-24450.html * https://www.suse.com/security/cve/CVE-2026-24660.html * https://www.suse.com/security/cve/CVE-2026-5342.html * https://bugzilla.suse.com/show_bug.cgi?id=1261499 * https://bugzilla.suse.com/show_bug.cgi?id=1261671 * https://bugzilla.suse.com/show_bug.cgi?id=1261672 * https://bugzilla.suse.com/show_bug.cgi?id=1261673 * https://bugzilla.suse.com/show_bug.cgi?id=1261674 * https://bugzilla.suse.com/show_bug.cgi?id=1261675 * https://bugzilla.suse.com/show_bug.cgi?id=1261676 . Libraw receives a critical security update to address multiple buffer overflow issues and enhance platform integrity.. libraw security patch, openSUSE vulnerabilities, buffer overflow fix, important libraw update. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.