From: Raspbian automatic forward porter Date: Mon, 14 Sep 2026 03:05:05 +0000 (+0100) Subject: Merge version 0.21.4-2+rpi1 and 0.21.4-2+deb13u1 to produce 0.21.4-2+rpi1+deb13u1 X-Git-Tag: archive/raspbian/0.21.4-2+rpi1+deb13u1^0 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=850e7d06aaaed5061d38ebe1ce0251b5222c8315;p=libraw.git Merge version 0.21.4-2+rpi1 and 0.21.4-2+deb13u1 to produce 0.21.4-2+rpi1+deb13u1 --- 850e7d06aaaed5061d38ebe1ce0251b5222c8315 diff --cc debian/changelog index e6cc2cb,8efa39c..d394f9b --- a/debian/changelog +++ b/debian/changelog @@@ -1,9 -1,21 +1,28 @@@ - libraw (0.21.4-2+rpi1) trixie-staging; urgency=medium ++libraw (0.21.4-2+rpi1+deb13u1) trixie-staging; urgency=medium + + [changes brought forward from 0.21.1-7+rpi1 by Peter Michael Green at Sat, 21 Oct 2023 22:45:40 +0000] + * Update symbols file for raspbian. + - -- Raspbian forward porter Sun, 11 May 2025 04:16:41 +0000 ++ -- Raspbian forward porter Mon, 14 Sep 2026 03:05:05 +0000 ++ + libraw (0.21.4-2+deb13u1) trixie; urgency=high + + * Non-maintainer upload. + * Fix CVE-2026-5342: nikon_load_padded_packed_raw() out-of-bounds read + due to missing buffer and dimension validation (closes: #1132655). + * Fix CVE-2026-20884: deflate_dng_load_raw() integer overflow vulnerability + (closes: #1133845). + * Fix CVE-2026-20889: x3f_thumb_loader() heap-based buffer overflow + vulnerability (closes: #1133845). + * Fix CVE-2026-21413: lossless_jpeg_load_raw() heap-based buffer overflow + vulnerability (closes: #1133845). + * Fix CVE-2026-24450: uncompressed_fp_dng_load_raw() integer overflow + vulnerability (closes: #1133845). + * Fix CVE-2026-24660: x3f_load_huffman() heap-based buffer overflow + vulnerability (closes: #1133845). + * Add d/salsa-ci.yml for Salsa CI. + + -- Guilhem Moulin Wed, 29 Jul 2026 03:53:35 +0200 libraw (0.21.4-2) unstable; urgency=medium