Fix for TALOS-2026-2358
Origin: https://github.com/LibRaw/LibRaw/commit/
b9809e410d07ca7bf408e6d036615fb34f8c47cc
Bug: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2358
Bug-Debian: https://bugs.debian.org/
1133845
Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2026-20889
Gbp-Pq: Name CVE-2026-20889.patch
Fix for TALOS-2026-2331
Origin: https://github.com/LibRaw/LibRaw/commit/
75ed2c12a35b765b3b6ad695cc1f044f19efe644
Bug: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2331
Bug-Debian: https://bugs.debian.org/
1133845
Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2026-21413
Gbp-Pq: Name CVE-2026-21413.patch
libraw (0.21.4-2+deb13u1) trixie; urgency=high
* Non-maintainer upload.
* Fix CVE-2026-5342: nikon_load_padded_packed_raw() out-of-bounds read
due to missing buffer and dimension validation (closes: #
1132655).
* Fix CVE-2026-20884: deflate_dng_load_raw() integer overflow vulnerability
(closes: #
1133845).
* Fix CVE-2026-20889: x3f_thumb_loader() heap-based buffer overflow
vulnerability (closes: #
1133845).
* Fix CVE-2026-21413: lossless_jpeg_load_raw() heap-based buffer overflow
vulnerability (closes: #
1133845).
* Fix CVE-2026-24450: uncompressed_fp_dng_load_raw() integer overflow
vulnerability (closes: #
1133845).
* Fix CVE-2026-24660: x3f_load_huffman() heap-based buffer overflow
vulnerability (closes: #
1133845).
* Add d/salsa-ci.yml for Salsa CI.
[dgit import unpatched libraw 0.21.4-2+deb13u1]