libraw (0.21.4-2+deb13u1) trixie; urgency=high
authorGuilhem Moulin <guilhem@debian.org>
Wed, 29 Jul 2026 01:53:35 +0000 (03:53 +0200)
committerGuilhem Moulin <guilhem@debian.org>
Wed, 29 Jul 2026 01:53:35 +0000 (03:53 +0200)
commit5af1f56077816dd98c97c6670e111a4550b4f83e
tree11b24320a307d58c958762c57fc4befc5c1a6bd4
parent286eff3a36e959afcb46cec65c7556f284e5f9a1
parent117cd512e457d4c6af66ef92d42d10769ffb5ba4
libraw (0.21.4-2+deb13u1) trixie; urgency=high

  * Non-maintainer upload.
  * Fix CVE-2026-5342: nikon_load_padded_packed_raw() out-of-bounds read
    due to missing buffer and dimension validation (closes: #1132655).
  * Fix CVE-2026-20884: deflate_dng_load_raw() integer overflow vulnerability
    (closes: #1133845).
  * Fix CVE-2026-20889: x3f_thumb_loader() heap-based buffer overflow
    vulnerability (closes: #1133845).
  * Fix CVE-2026-21413: lossless_jpeg_load_raw() heap-based buffer overflow
    vulnerability (closes: #1133845).
  * Fix CVE-2026-24450: uncompressed_fp_dng_load_raw() integer overflow
    vulnerability (closes: #1133845).
  * Fix CVE-2026-24660: x3f_load_huffman() heap-based buffer overflow
    vulnerability (closes: #1133845).
  * Add d/salsa-ci.yml for Salsa CI.

[dgit import unpatched libraw 0.21.4-2+deb13u1]
27 files changed:
debian/NEWS
debian/changelog
debian/control
debian/copyright
debian/libraw-bin.install
debian/libraw-dev.install
debian/libraw-doc.doc-base
debian/libraw-doc.docs
debian/libraw23t64.install
debian/libraw23t64.lintian-overrides
debian/libraw23t64.symbols
debian/patches/CVE-2026-20884/01-afba34ec3.patch
debian/patches/CVE-2026-20884/02-dae685a19.patch
debian/patches/CVE-2026-20884/03-aa4458eb5.patch
debian/patches/CVE-2026-20889.patch
debian/patches/CVE-2026-21413.patch
debian/patches/CVE-2026-24450.patch
debian/patches/CVE-2026-24660.patch
debian/patches/CVE-2026-5342.patch
debian/patches/series
debian/rules
debian/salsa-ci.yml
debian/source/format
debian/tests/control
debian/tests/smoketest
debian/upstream/metadata
debian/watch