ELA-1790-1 libraw security update

heap buffer overflow vulnerabilities

2026-07-30
Packagelibraw
Version0.19.2-2+deb10u6 (buster)
Related CVEs CVE-2026-20884 CVE-2026-20889 CVE-2026-21413 CVE-2026-24660


CVE-2026-20884

An integer overflow vulnerability was discovered in the decoder routine for deflate-compressed floating-point DNG RAW files, which may lead to heap buffer overflow via specially crafted input file.

CVE-2026-20889

A heap-based buffer overflow vulnerability was discovered in the thumbnail extraction routine for RAW image files from Sigma/Foveon X3F digital cameras.

CVE-2026-21413

A heap-based buffer overflow vulnerability was discovered in the lossless JPEG decoder used for processing compressed RAW data from various camera formats.

CVE-2026-24660

A heap-based buffer overflow vulnerability was discovered in the Huffman decompression routine for RAW image files from Sigma/Foveon X3F digital cameras.



For Debian 10 buster, these problems have been fixed in version 0.19.2-2+deb10u6.

We recommend that you upgrade your libraw packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.