SUSE-SU-2026:21360-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202621360-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21360-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:21360-1
Upstream
CVE (7)
Related
Published
2026-04-20T15:26:23Z
Modified
2026-04-29T18:23:58Z
Summary
Security update for libraw
Details

This update for libraw fixes the following issues:

  • CVE-2026-5342: crafted TIFF/NEF file can cause an out-of-bounds read (bsc#1261499).
  • CVE-2026-20884: integer overflow vulnerability in the deflate_dng_load_raw (bsc#1261671).
  • CVE-2026-20889: heap-based buffer overflow vulnerability in the x3f_thumb_loader (bsc#1261672).
  • CVE-2026-20911: heap-based buffer overflow vulnerability in the HuffTable: initval (bsc#1261673).
  • CVE-2026-21413: heap-based buffer overflow vulnerability in the lossless_jpeg_load_raw (bsc#1261674).
  • CVE-2026-24450: integer overflow vulnerability in uncompressed_fp_dng_load_raw (bsc#1261675).
  • CVE-2026-24660: heap-based buffer overflow vulnerability in the x3f_load_huffman (bsc#1261676).
References

Affected packages