| Package | libraw |
|---|---|
| Version | 0.19.2-2+deb10u6 (buster) |
| Related CVEs | CVE-2026-20884 CVE-2026-20889 CVE-2026-21413 CVE-2026-24660 |
- CVE-2026-20884
-
An integer overflow vulnerability was discovered in the decoder routine for deflate-compressed floating-point DNG RAW files, which may lead to heap buffer overflow via specially crafted input file.
- CVE-2026-20889
-
A heap-based buffer overflow vulnerability was discovered in the thumbnail extraction routine for RAW image files from Sigma/Foveon X3F digital cameras.
- CVE-2026-21413
-
A heap-based buffer overflow vulnerability was discovered in the lossless JPEG decoder used for processing compressed RAW data from various camera formats.
- CVE-2026-24660
-
A heap-based buffer overflow vulnerability was discovered in the Huffman decompression routine for RAW image files from Sigma/Foveon X3F digital cameras.
For Debian 10 buster, these problems have been fixed in version 0.19.2-2+deb10u6.
We recommend that you upgrade your libraw packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.