#1142984 trixie-pu: package libraw/0.21.4-2+deb13u1

#1142984#5
Date:
2026-07-29 12:09:30 UTC
From:
To:
[ Reason ]

Fix <no-dsa> issues CVE-2026-5342, CVE-2026-20884, CVE-2026-20889,
CVE-2026-21413, CVE-2026-24450 and CVE-2026-24660.

[ Impact ]

Users will remain vulnerable to the afformentioned issues, and will
regress when upgrading upgrading (a fix was uploaded to Bookworm LTS and
Bullseye LTS as part of DLA-4704-1).

[ Tests ]

Manual tests only using the reporter's PoC information.  AFAICT neither
the package nor the upstream code have an automated test suite.

[ Risks ]

Low risk, all changes have been backported from upstream's 0.22.1
version and trivially apply to trixie's 0.21.4 codebase.

[ Checklist ]

  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in stable
  [x] the issue is verified as fixed in unstable

[ Changes ]

  * Fix CVE-2026-5342: nikon_load_padded_packed_raw() out-of-bounds read
    due to missing buffer and dimension validation (closes: #1132655).
  * Fix CVE-2026-20884: deflate_dng_load_raw() integer overflow vulnerability
    (closes: #1133845).
  * Fix CVE-2026-20889: x3f_thumb_loader() heap-based buffer overflow
    vulnerability (closes: #1133845).
  * Fix CVE-2026-21413: lossless_jpeg_load_raw() heap-based buffer overflow
    vulnerability (closes: #1133845).
  * Fix CVE-2026-24450: uncompressed_fp_dng_load_raw() integer overflow
    vulnerability (closes: #1133845).
  * Fix CVE-2026-24660: x3f_load_huffman() heap-based buffer overflow
    vulnerability (closes: #1133845).
  * Add d/salsa-ci.yml for Salsa CI.

[ Other info ]

Debusine workflow output:
https://debusine.debian.net/debian/developers/work-request/940417/

Individual commits and tag can be found on the LTS team fork at
https://salsa.debian.org/lts-team/packages/libraw/-/tree/debian/trixie?ref_type=heads

#1142984#12
Date:
2026-09-04 11:35:00 UTC
From:
To:
Control: tags -1 + confirmed

Please go ahead.

Regards,

Adam

#1142984#19
Date:
2026-09-05 15:20:17 UTC
From:
To:
package release.debian.org
tags 1142984 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: libraw
Version: 0.21.4-2+deb13u1

Explanation: fix out of bounds read issue [CVE-2026-5342]; fix integer overflow issues [CVE-2026-20884 CVE-2026-24450]; fix buffer overflow issues [CVE-2026-20889 CVE-2026-21413 CVE-2026-24660]

#1142984#24
Date:
2026-09-05 15:20:17 UTC
From:
To:
package release.debian.org
tags 1142984 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: libraw
Version: 0.21.4-2+deb13u1

Explanation: fix out of bounds read issue [CVE-2026-5342]; fix integer overflow issues [CVE-2026-20884 CVE-2026-24450]; fix buffer overflow issues [CVE-2026-20889 CVE-2026-21413 CVE-2026-24660]

#1142984#29
Date:
2026-09-12 08:05:41 UTC
From:
To:
This update was released as part of 13.7.