libraw.git
7 weeks agoFix for TALOS-2026-2331
Alex Tutubalin [Sat, 28 Feb 2026 15:26:53 +0000 (18:26 +0300)]
Fix for TALOS-2026-2331

Origin: https://github.com/LibRaw/LibRaw/commit/75ed2c12a35b765b3b6ad695cc1f044f19efe644
Bug: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2331
Bug-Debian: https://bugs.debian.org/1133845
Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2026-21413

Gbp-Pq: Name CVE-2026-21413.patch

7 weeks agolibraw (0.21.4-2+deb13u1) trixie; urgency=high
Guilhem Moulin [Wed, 29 Jul 2026 01:53:35 +0000 (03:53 +0200)]
libraw (0.21.4-2+deb13u1) trixie; urgency=high

  * Non-maintainer upload.
  * Fix CVE-2026-5342: nikon_load_padded_packed_raw() out-of-bounds read
    due to missing buffer and dimension validation (closes: #1132655).
  * Fix CVE-2026-20884: deflate_dng_load_raw() integer overflow vulnerability
    (closes: #1133845).
  * Fix CVE-2026-20889: x3f_thumb_loader() heap-based buffer overflow
    vulnerability (closes: #1133845).
  * Fix CVE-2026-21413: lossless_jpeg_load_raw() heap-based buffer overflow
    vulnerability (closes: #1133845).
  * Fix CVE-2026-24450: uncompressed_fp_dng_load_raw() integer overflow
    vulnerability (closes: #1133845).
  * Fix CVE-2026-24660: x3f_load_huffman() heap-based buffer overflow
    vulnerability (closes: #1133845).
  * Add d/salsa-ci.yml for Salsa CI.

[dgit import unpatched libraw 0.21.4-2+deb13u1]

7 weeks agoImport libraw_0.21.4-2+deb13u1.debian.tar.xz
Guilhem Moulin [Wed, 29 Jul 2026 01:53:35 +0000 (03:53 +0200)]
Import libraw_0.21.4-2+deb13u1.debian.tar.xz

[dgit import tarball libraw 0.21.4-2+deb13u1 libraw_0.21.4-2+deb13u1.debian.tar.xz]

16 months agoImport libraw_0.21.4.orig.tar.gz
xiao sheng wen [Thu, 24 Apr 2025 07:55:00 +0000 (15:55 +0800)]
Import libraw_0.21.4.orig.tar.gz

[dgit import orig libraw_0.21.4.orig.tar.gz]