Merge version 0.21.4-2+rpi1 and 0.21.4-2+deb13u1 to produce 0.21.4-2+rpi1+deb13u1 trixie-staging archive/raspbian/0.21.4-2+rpi1+deb13u1 raspbian/0.21.4-2+rpi1+deb13u1
authorRaspbian automatic forward porter <root@raspbian.org>
Mon, 14 Sep 2026 03:05:05 +0000 (04:05 +0100)
committerRaspbian automatic forward porter <root@raspbian.org>
Mon, 14 Sep 2026 03:05:05 +0000 (04:05 +0100)
1  2 
debian/changelog

index e6cc2cbb1b3b9df7b76b8fb3f00529c8ad144f5c,8efa39cb7acceb98c0c25a8e4def471b3ad56df3..d394f9b5ead575d3d8876e17f4577292226d4b9a
@@@ -1,9 -1,21 +1,28 @@@
- libraw (0.21.4-2+rpi1) trixie-staging; urgency=medium
++libraw (0.21.4-2+rpi1+deb13u1) trixie-staging; urgency=medium
 +
 +  [changes brought forward from 0.21.1-7+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Sat, 21 Oct 2023 22:45:40 +0000]
 +  * Update symbols file for raspbian.
 +
-  -- Raspbian forward porter <root@raspbian.org>  Sun, 11 May 2025 04:16:41 +0000
++ -- Raspbian forward porter <root@raspbian.org>  Mon, 14 Sep 2026 03:05:05 +0000
++
+ libraw (0.21.4-2+deb13u1) trixie; urgency=high
+   * Non-maintainer upload.
+   * Fix CVE-2026-5342: nikon_load_padded_packed_raw() out-of-bounds read
+     due to missing buffer and dimension validation (closes: #1132655).
+   * Fix CVE-2026-20884: deflate_dng_load_raw() integer overflow vulnerability
+     (closes: #1133845).
+   * Fix CVE-2026-20889: x3f_thumb_loader() heap-based buffer overflow
+     vulnerability (closes: #1133845).
+   * Fix CVE-2026-21413: lossless_jpeg_load_raw() heap-based buffer overflow
+     vulnerability (closes: #1133845).
+   * Fix CVE-2026-24450: uncompressed_fp_dng_load_raw() integer overflow
+     vulnerability (closes: #1133845).
+   * Fix CVE-2026-24660: x3f_load_huffman() heap-based buffer overflow
+     vulnerability (closes: #1133845).
+   * Add d/salsa-ci.yml for Salsa CI.
+  -- Guilhem Moulin <guilhem@debian.org>  Wed, 29 Jul 2026 03:53:35 +0200
  
  libraw (0.21.4-2) unstable; urgency=medium