ELA-1551-1 raptor2 security update

heap-based buffer over-read and integer underflow

2025-10-22
Packageraptor2
Version2.0.14-1+deb9u3 (stretch), 2.0.14-1.1~deb10u3 (buster)
Related CVEs CVE-2024-57822 CVE-2024-57823


Two issues have been found in raptor2, an RDF parser and serializer utilities. One issue is related to a heap-based buffer over-read when parsing triples. The other issue is related to an integer underflow when normalizing an URI.



For Debian 10 buster, these problems have been fixed in version 2.0.14-1.1~deb10u3.

For Debian 9 stretch, these problems have been fixed in version 2.0.14-1+deb9u3.

We recommend that you upgrade your raptor2 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.