Fix for data size calculation integer overflow in float/deflated DNG loader (TALOS...
authorAlex Tutubalin <lexa@lexa.ru>
Fri, 13 Mar 2026 14:43:47 +0000 (17:43 +0300)
committerGuilhem Moulin <guilhem@debian.org>
Wed, 29 Jul 2026 01:53:35 +0000 (03:53 +0200)
commit21190e1371340eae0e11bda8b02449af72fb35a0
tree7409629b97fecbd5a5a6dbc4e9fa3138c8699e2c
parentce9d06bd3d868f49ceac1ec9bfb1bf4c761b1c7c
Fix for data size calculation integer overflow in float/deflated DNG loader (TALOS-2026-2364); Check for read results

Origin: https://github.com/LibRaw/LibRaw/commit/aa4458eb511daeae90676c1ce5c587106e4aaec1
Bug: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2364
Bug-Debian: https://bugs.debian.org/1133845
Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2026-20884

Gbp-Pq: Topic CVE-2026-20884
Gbp-Pq: Name 03-aa4458eb5.patch
src/decoders/fp_dng.cpp