{"id":"openSUSE-SU-2026:20574-1","summary":"Security update for libraw","details":"This update for libraw fixes the following issues:\n\n- CVE-2026-5342: crafted TIFF/NEF file can cause an out-of-bounds read (bsc#1261499).\n- CVE-2026-20884: integer overflow vulnerability in the deflate_dng_load_raw (bsc#1261671).\n- CVE-2026-20889: heap-based buffer overflow vulnerability in the x3f_thumb_loader (bsc#1261672).\n- CVE-2026-20911: heap-based buffer overflow vulnerability in the HuffTable: initval (bsc#1261673).\n- CVE-2026-21413: heap-based buffer overflow vulnerability in the lossless_jpeg_load_raw (bsc#1261674).\n- CVE-2026-24450: integer overflow vulnerability in uncompressed_fp_dng_load_raw (bsc#1261675).\n- CVE-2026-24660: heap-based buffer overflow vulnerability in the x3f_load_huffman (bsc#1261676).\n","modified":"2026-04-22T20:09:56.430651Z","published":"2026-04-20T15:30:10Z","related":["CVE-2026-20884","CVE-2026-20889","CVE-2026-20911","CVE-2026-21413","CVE-2026-24450","CVE-2026-24660","CVE-2026-5342"],"upstream":["CVE-2026-20884","CVE-2026-20889","CVE-2026-20911","CVE-2026-21413","CVE-2026-24450","CVE-2026-24660","CVE-2026-5342"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261499"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261671"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261672"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261673"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261674"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261675"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261676"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20884"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20889"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20911"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21413"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-24450"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-24660"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5342"}],"affected":[{"package":{"name":"libraw","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/libraw&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.21.4-160000.3.1"}]}],"ecosystem_specific":{"binaries":[{"libraw23":"0.21.4-160000.3.1","libraw-devel-static":"0.21.4-160000.3.1","libraw-devel":"0.21.4-160000.3.1","libraw-tools":"0.21.4-160000.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20574-1.json"}}],"schema_version":"1.7.5"}