--- Begin Message ---
Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: [email protected]
Control: affects -1 + src:libraw
User: [email protected]
Usertags: pu
[ Reason ]
Fix <no-dsa> issues CVE-2026-5342, CVE-2026-20884, CVE-2026-20889,
CVE-2026-21413, CVE-2026-24450 and CVE-2026-24660.
[ Impact ]
Users will remain vulnerable to the afformentioned issues, and will
regress when upgrading upgrading (a fix was uploaded to Bookworm LTS and
Bullseye LTS as part of DLA-4704-1).
[ Tests ]
Manual tests only using the reporter's PoC information. AFAICT neither
the package nor the upstream code have an automated test suite.
[ Risks ]
Low risk, all changes have been backported from upstream's 0.22.1
version and trivially apply to trixie's 0.21.4 codebase.
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in stable
[x] the issue is verified as fixed in unstable
[ Changes ]
* Fix CVE-2026-5342: nikon_load_padded_packed_raw() out-of-bounds read
due to missing buffer and dimension validation (closes: #1132655).
* Fix CVE-2026-20884: deflate_dng_load_raw() integer overflow vulnerability
(closes: #1133845).
* Fix CVE-2026-20889: x3f_thumb_loader() heap-based buffer overflow
vulnerability (closes: #1133845).
* Fix CVE-2026-21413: lossless_jpeg_load_raw() heap-based buffer overflow
vulnerability (closes: #1133845).
* Fix CVE-2026-24450: uncompressed_fp_dng_load_raw() integer overflow
vulnerability (closes: #1133845).
* Fix CVE-2026-24660: x3f_load_huffman() heap-based buffer overflow
vulnerability (closes: #1133845).
* Add d/salsa-ci.yml for Salsa CI.
[ Other info ]
Debusine workflow output:
https://debusine.debian.net/debian/developers/work-request/940417/
Individual commits and tag can be found on the LTS team fork at
https://salsa.debian.org/lts-team/packages/libraw/-/tree/debian/trixie?ref_type=heads
--
Guilhem.
diffstat for libraw-0.21.4 libraw-0.21.4
changelog | 19 +
patches/CVE-2026-20884/01-afba34ec3.patch | 69 ++++++
patches/CVE-2026-20884/02-dae685a19.patch | 36 +++
patches/CVE-2026-20884/03-aa4458eb5.patch | 61 +++++
patches/CVE-2026-20889.patch | 96 ++++++++
patches/CVE-2026-21413.patch | 33 ++
patches/CVE-2026-24450.patch | 55 ++++
patches/CVE-2026-24660.patch | 335 ++++++++++++++++++++++++++++++
patches/CVE-2026-5342.patch | 61 +++++
patches/series | 8
salsa-ci.yml | 9
11 files changed, 782 insertions(+)
diff -Nru libraw-0.21.4/debian/changelog libraw-0.21.4/debian/changelog
--- libraw-0.21.4/debian/changelog 2025-04-24 15:52:02.000000000 +0200
+++ libraw-0.21.4/debian/changelog 2026-07-29 03:53:35.000000000 +0200
@@ -1,3 +1,22 @@
+libraw (0.21.4-2+deb13u1) trixie; urgency=high
+
+ * Non-maintainer upload.
+ * Fix CVE-2026-5342: nikon_load_padded_packed_raw() out-of-bounds read
+ due to missing buffer and dimension validation (closes: #1132655).
+ * Fix CVE-2026-20884: deflate_dng_load_raw() integer overflow vulnerability
+ (closes: #1133845).
+ * Fix CVE-2026-20889: x3f_thumb_loader() heap-based buffer overflow
+ vulnerability (closes: #1133845).
+ * Fix CVE-2026-21413: lossless_jpeg_load_raw() heap-based buffer overflow
+ vulnerability (closes: #1133845).
+ * Fix CVE-2026-24450: uncompressed_fp_dng_load_raw() integer overflow
+ vulnerability (closes: #1133845).
+ * Fix CVE-2026-24660: x3f_load_huffman() heap-based buffer overflow
+ vulnerability (closes: #1133845).
+ * Add d/salsa-ci.yml for Salsa CI.
+
+ -- Guilhem Moulin <[email protected]> Wed, 29 Jul 2026 03:53:35 +0200
+
libraw (0.21.4-2) unstable; urgency=medium
* Team upload.
diff -Nru libraw-0.21.4/debian/patches/CVE-2026-20884/01-afba34ec3.patch libraw-0.21.4/debian/patches/CVE-2026-20884/01-afba34ec3.patch
--- libraw-0.21.4/debian/patches/CVE-2026-20884/01-afba34ec3.patch 1970-01-01 01:00:00.000000000 +0100
+++ libraw-0.21.4/debian/patches/CVE-2026-20884/01-afba34ec3.patch 2026-07-29 03:53:35.000000000 +0200
@@ -0,0 +1,69 @@
+From: Alex Tutubalin <[email protected]>
+Date: Sun, 28 Dec 2025 19:18:36 +0300
+Subject: implemented RAW size limit check and allocation result check for
+ 4-shot pentax loaded and FP-dng loader
+
+Origin: https://github.com/LibRaw/LibRaw/commit/afba34ec30bf6409891dc096f6be69155ecf6bdb
+Bug: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2364
+Bug-Debian: https://bugs.debian.org/1133845
+Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2026-20884
+---
+ src/decoders/decoders_libraw.cpp | 12 ++++++++++--
+ src/decoders/fp_dng.cpp | 9 ++++++++-
+ 2 files changed, 18 insertions(+), 3 deletions(-)
+
+diff --git a/src/decoders/decoders_libraw.cpp b/src/decoders/decoders_libraw.cpp
+index 952e41a..eb277c3 100644
+--- a/src/decoders/decoders_libraw.cpp
++++ b/src/decoders/decoders_libraw.cpp
+@@ -54,6 +54,10 @@ void LibRaw::sony_arq_load_raw()
+
+ void LibRaw::pentax_4shot_load_raw()
+ {
++ size_t alloc_sz = size_t(imgdata.sizes.raw_width) * (size_t(imgdata.sizes.raw_height) + 16) * 4 * sizeof(ushort);
++ if (INT64(alloc_sz) > INT64(imgdata.rawparams.max_raw_memory_mb) * INT64(1024 * 1024))
++ throw LIBRAW_EXCEPTION_TOOBIG;
++
+ #ifdef LIBRAW_CALLOC_RAWSTORE
+ ushort *plane = (ushort *)calloc(size_t(imgdata.sizes.raw_width) *
+ size_t(imgdata.sizes.raw_height), sizeof(ushort));
+@@ -61,13 +65,17 @@ void LibRaw::pentax_4shot_load_raw()
+ ushort *plane = (ushort *)malloc(size_t(imgdata.sizes.raw_width) *
+ size_t(imgdata.sizes.raw_height) * sizeof(ushort));
+ #endif
+- int alloc_sz = imgdata.sizes.raw_width * (imgdata.sizes.raw_height + 16) * 4 *
+- sizeof(ushort);
++ if (!plane)
++ throw LIBRAW_EXCEPTION_ALLOC;
++
+ #ifdef LIBRAW_CALLOC_RAWSTORE
+ ushort(*result)[4] = (ushort(*)[4])calloc(alloc_sz,1);
+ #else
+ ushort(*result)[4] = (ushort(*)[4])malloc(alloc_sz);
+ #endif
++ if(!result)
++ throw LIBRAW_EXCEPTION_ALLOC;
++
+ struct movement_t
+ {
+ int row, col;
+diff --git a/src/decoders/fp_dng.cpp b/src/decoders/fp_dng.cpp
+index 4bb8f42..6f82e89 100644
+--- a/src/decoders/fp_dng.cpp
++++ b/src/decoders/fp_dng.cpp
+@@ -350,7 +350,14 @@ void LibRaw::deflate_dng_load_raw()
+ libraw_internal_data.internal_data.input);
+
+ if (ifd->sample_format == 3)
+- float_raw_image = (float *)calloc(tiles.tileCnt * tiles.tileWidth * tiles.tileHeight *ifd->samples, sizeof(float));
++ {
++ INT64 raw_bytes = tiles.tileCnt * tiles.tileWidth * tiles.tileHeight * ifd->samples * sizeof(float);
++ if (raw_bytes > INT64(imgdata.rawparams.max_raw_memory_mb) * INT64(1024 * 1024))
++ throw LIBRAW_EXCEPTION_TOOBIG;
++ float_raw_image = (float *)calloc(tiles.tileCnt * tiles.tileWidth * tiles.tileHeight * ifd->samples, sizeof(float));
++ if (!float_raw_image)
++ throw LIBRAW_EXCEPTION_ALLOC;
++ }
+ else
+ throw LIBRAW_EXCEPTION_DECODE_RAW; // Only float deflated supported
+
diff -Nru libraw-0.21.4/debian/patches/CVE-2026-20884/02-dae685a19.patch libraw-0.21.4/debian/patches/CVE-2026-20884/02-dae685a19.patch
--- libraw-0.21.4/debian/patches/CVE-2026-20884/02-dae685a19.patch 1970-01-01 01:00:00.000000000 +0100
+++ libraw-0.21.4/debian/patches/CVE-2026-20884/02-dae685a19.patch 2026-07-29 03:53:35.000000000 +0200
@@ -0,0 +1,36 @@
+From: Alex Tutubalin <[email protected]>
+Date: Sat, 7 Mar 2026 18:40:05 +0300
+Subject: FP DNG data limit: perform calculations in 64 bit
+
+Origin: https://github.com/LibRaw/LibRaw/commit/dae685a198309b978805f098bafe5d951dbc8747
+Bug: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2364
+Bug-Debian: https://bugs.debian.org/1133845
+Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2026-20884
+---
+ src/decoders/fp_dng.cpp | 11 +++++++----
+ 1 file changed, 7 insertions(+), 4 deletions(-)
+
+diff --git a/src/decoders/fp_dng.cpp b/src/decoders/fp_dng.cpp
+index 6f82e89..b18ca33 100644
+--- a/src/decoders/fp_dng.cpp
++++ b/src/decoders/fp_dng.cpp
+@@ -376,12 +376,15 @@ void LibRaw::deflate_dng_load_raw()
+ break;
+ }
+
+- unsigned tilePixels = tiles.tileWidth * tiles.tileHeight;
++ INT64 tilePixels = INT64(tiles.tileWidth) * INT64(tiles.tileHeight);
+ unsigned pixelSize = sizeof(float) * ifd->samples;
+- unsigned tileBytes = tilePixels * pixelSize;
+- unsigned tileRowBytes = tiles.tileWidth * pixelSize;
++ INT64 tileBytes = tilePixels * INT64(pixelSize);
++ INT64 tileRowBytes = INT64(tiles.tileWidth) * INT64(pixelSize);
+
+- if(INT64(tiles.maxBytesInTile) > INT64(imgdata.rawparams.max_raw_memory_mb) * INT64(1024 * 1024) )
++ if(INT64(tiles.maxBytesInTile) > INT64(imgdata.rawparams.max_raw_memory_mb) * 1024LL * 1024LL )
++ throw LIBRAW_EXCEPTION_TOOBIG;
++
++ if (tileBytes + tileRowBytes > INT64(imgdata.rawparams.max_raw_memory_mb) * 1024LL * 1024LL)
+ throw LIBRAW_EXCEPTION_TOOBIG;
+
+ std::vector<uchar> cBuffer(tiles.maxBytesInTile,0);
diff -Nru libraw-0.21.4/debian/patches/CVE-2026-20884/03-aa4458eb5.patch libraw-0.21.4/debian/patches/CVE-2026-20884/03-aa4458eb5.patch
--- libraw-0.21.4/debian/patches/CVE-2026-20884/03-aa4458eb5.patch 1970-01-01 01:00:00.000000000 +0100
+++ libraw-0.21.4/debian/patches/CVE-2026-20884/03-aa4458eb5.patch 2026-07-29 03:53:35.000000000 +0200
@@ -0,0 +1,61 @@
+From: Alex Tutubalin <[email protected]>
+Date: Fri, 13 Mar 2026 17:43:47 +0300
+Subject: Fix for data size calculation integer overflow in float/deflated DNG
+ loader (TALOS-2026-2364); Check for read results
+
+Origin: https://github.com/LibRaw/LibRaw/commit/aa4458eb511daeae90676c1ce5c587106e4aaec1
+Bug: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2364
+Bug-Debian: https://bugs.debian.org/1133845
+Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2026-20884
+---
+ src/decoders/fp_dng.cpp | 26 +++++++++++++++++++++-----
+ 1 file changed, 21 insertions(+), 5 deletions(-)
+
+diff --git a/src/decoders/fp_dng.cpp b/src/decoders/fp_dng.cpp
+index b18ca33..c460373 100644
+--- a/src/decoders/fp_dng.cpp
++++ b/src/decoders/fp_dng.cpp
+@@ -349,14 +349,28 @@ void LibRaw::deflate_dng_load_raw()
+ tiles.init(ifd, imgdata.sizes, libraw_internal_data.unpacker_data, libraw_internal_data.unpacker_data.order,
+ libraw_internal_data.internal_data.input);
+
++ if (tiles.tBytes.size() < 1)
++ throw LIBRAW_EXCEPTION_IO_CORRUPT;
++
++ // Ensure less then 2GB per compressed tile
++ INT64 maxcomprlen = tiles.tBytes[0];
++ for (int i = 1; i < tiles.tBytes.size(); i++)
++ maxcomprlen = MAX(maxcomprlen, tiles.tBytes[i]);
++
++ if(maxcomprlen >= (1LL << 31) || maxcomprlen < 0)
++ throw LIBRAW_EXCEPTION_TOOBIG;
++
++ // Max bytes: 2^16 raw width * 2^2 bytes/pixel * 2^2 channels = 2^20, so check against 2^22
++ INT64 rowbytes = INT64(MAX(tiles.tileWidth, imgdata.sizes.raw_width)) * 4ULL * INT64(ifd->samples);
++ if (rowbytes > (1LL << 22))
++ throw LIBRAW_EXCEPTION_TOOBIG;
++
+ if (ifd->sample_format == 3)
+ {
+- INT64 raw_bytes = tiles.tileCnt * tiles.tileWidth * tiles.tileHeight * ifd->samples * sizeof(float);
++ INT64 raw_bytes = INT64(tiles.tileCnt) * INT64(tiles.tileWidth) * INT64(tiles.tileHeight) * INT64(ifd->samples) * sizeof(float);
+ if (raw_bytes > INT64(imgdata.rawparams.max_raw_memory_mb) * INT64(1024 * 1024))
+ throw LIBRAW_EXCEPTION_TOOBIG;
+- float_raw_image = (float *)calloc(tiles.tileCnt * tiles.tileWidth * tiles.tileHeight * ifd->samples, sizeof(float));
+- if (!float_raw_image)
+- throw LIBRAW_EXCEPTION_ALLOC;
++ float_raw_image = (float *)calloc(raw_bytes, 1);
+ }
+ else
+ throw LIBRAW_EXCEPTION_DECODE_RAW; // Only float deflated supported
+@@ -395,7 +409,9 @@ void LibRaw::deflate_dng_load_raw()
+ for (size_t x = 0; x < imgdata.sizes.raw_width; x += tiles.tileWidth, ++t)
+ {
+ libraw_internal_data.internal_data.input->seek(tiles.tOffsets[t], SEEK_SET);
+- libraw_internal_data.internal_data.input->read(cBuffer.data(), 1, tiles.tBytes[t]);
++ int bytesread = libraw_internal_data.internal_data.input->read(cBuffer.data(), 1, tiles.tBytes[t]);
++ if (bytesread < tiles.tBytes[t])
++ derror();
+ unsigned long dstLen = tileBytes;
+ int err =
+ uncompress(uBuffer.data() + tileRowBytes, &dstLen, cBuffer.data(), (unsigned long)tiles.tBytes[t]);
diff -Nru libraw-0.21.4/debian/patches/CVE-2026-20889.patch libraw-0.21.4/debian/patches/CVE-2026-20889.patch
--- libraw-0.21.4/debian/patches/CVE-2026-20889.patch 1970-01-01 01:00:00.000000000 +0100
+++ libraw-0.21.4/debian/patches/CVE-2026-20889.patch 2026-07-29 03:53:35.000000000 +0200
@@ -0,0 +1,96 @@
+From: Alex Tutubalin <[email protected]>
+Date: Sun, 1 Mar 2026 19:54:16 +0300
+Subject: Fix for TALOS-2026-2358
+
+Origin: https://github.com/LibRaw/LibRaw/commit/b9809e410d07ca7bf408e6d036615fb34f8c47cc
+Bug: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2358
+Bug-Debian: https://bugs.debian.org/1133845
+Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2026-20889
+---
+ src/decoders/unpack_thumb.cpp | 2 ++
+ src/x3f/x3f_parse_process.cpp | 20 ++++++++++++++++++--
+ src/x3f/x3f_utils_patched.cpp | 7 +++++++
+ 3 files changed, 27 insertions(+), 2 deletions(-)
+
+diff --git a/src/decoders/unpack_thumb.cpp b/src/decoders/unpack_thumb.cpp
+index df30da1..f79b0bb 100644
+--- a/src/decoders/unpack_thumb.cpp
++++ b/src/decoders/unpack_thumb.cpp
+@@ -387,6 +387,8 @@ int LibRaw::unpack_thumb(void)
+ {
+ x3f_thumb_loader();
+ SET_PROC_FLAG(LIBRAW_PROGRESS_THUMB_LOAD);
++ if (!T.twidth && !T.theight)
++ return LIBRAW_NO_THUMBNAIL;
+ return 0;
+ }
+ #endif
+diff --git a/src/x3f/x3f_parse_process.cpp b/src/x3f/x3f_parse_process.cpp
+index 354e467..9742c8e 100644
+--- a/src/x3f/x3f_parse_process.cpp
++++ b/src/x3f/x3f_parse_process.cpp
+@@ -322,6 +322,7 @@ void LibRaw::x3f_thumb_loader()
+ {
+ try
+ {
++ INT64 checked_size = x3f_thumb_size(); // This value was checked at upper level?
+ x3f_t *x3f = (x3f_t *)_x3f_data;
+ if (!x3f)
+ return; // No data pointer set
+@@ -339,12 +340,24 @@ void LibRaw::x3f_thumb_loader()
+ imgdata.thumbnail.tcolors = 3;
+ if (imgdata.thumbnail.tformat == LIBRAW_THUMBNAIL_JPEG)
+ {
+- imgdata.thumbnail.thumb = (char *)malloc(ID->data_size);
++ INT64 alloc_size = ID->data_size;
++ if ((alloc_size > 2 * checked_size) || (alloc_size > 1024LL * 1024LL * LIBRAW_MAX_THUMBNAIL_MB))
++ throw LIBRAW_EXCEPTION_TOOBIG;
++ if(alloc_size < 64LL)
++ throw LIBRAW_EXCEPTION_IO_CORRUPT;
++
++ imgdata.thumbnail.thumb = (char *)malloc(ID->data_size);
+ memmove(imgdata.thumbnail.thumb, ID->data, ID->data_size);
+ imgdata.thumbnail.tlength = ID->data_size;
+ }
+ else if (imgdata.thumbnail.tformat == LIBRAW_THUMBNAIL_BITMAP)
+ {
++ INT64 alloc_size = INT64(ID->columns) * INT64(ID->rows) * 3LL;
++ if ((alloc_size > 2 * checked_size) ||
++ (alloc_size > 1024LL * 1024LL * LIBRAW_MAX_THUMBNAIL_MB)) throw LIBRAW_EXCEPTION_TOOBIG;
++ if (alloc_size < 64LL)
++ throw LIBRAW_EXCEPTION_IO_CORRUPT;
++
+ imgdata.thumbnail.tlength = ID->columns * ID->rows * 3;
+ imgdata.thumbnail.thumb = (char *)malloc(ID->columns * ID->rows * 3);
+ char *src0 = (char *)ID->data;
+@@ -361,7 +374,10 @@ void LibRaw::x3f_thumb_loader()
+ }
+ catch (...)
+ {
+- // do nothing
++ // no rethrow: handled at upper level
++ imgdata.thumbnail.twidth = 0;
++ imgdata.thumbnail.theight = 0;
++ imgdata.thumbnail.tcolors = 0;
+ }
+ }
+
+diff --git a/src/x3f/x3f_utils_patched.cpp b/src/x3f/x3f_utils_patched.cpp
+index 6b20b90..21c7ab1 100644
+--- a/src/x3f/x3f_utils_patched.cpp
++++ b/src/x3f/x3f_utils_patched.cpp
+@@ -1221,7 +1221,14 @@ static uint32_t read_data_block(void **data, x3f_info_t *I,
+ if (fpos + size > I->input.file->size())
+ throw LIBRAW_EXCEPTION_IO_CORRUPT;
+
++ // All known files from real cameras are many times smaller than 1 GB, so the hard limit is OK here.
++
++ if(size > 1024*1024*1024)
++ throw LIBRAW_EXCEPTION_ALLOC;
++
+ *data = (void *)malloc(size);
++ if (!*data)
++ throw LIBRAW_EXCEPTION_ALLOC;
+
+ GETN(*data, size);
+
diff -Nru libraw-0.21.4/debian/patches/CVE-2026-21413.patch libraw-0.21.4/debian/patches/CVE-2026-21413.patch
--- libraw-0.21.4/debian/patches/CVE-2026-21413.patch 1970-01-01 01:00:00.000000000 +0100
+++ libraw-0.21.4/debian/patches/CVE-2026-21413.patch 2026-07-29 03:53:35.000000000 +0200
@@ -0,0 +1,33 @@
+From: Alex Tutubalin <[email protected]>
+Date: Sat, 28 Feb 2026 18:26:53 +0300
+Subject: Fix for TALOS-2026-2331
+
+Origin: https://github.com/LibRaw/LibRaw/commit/75ed2c12a35b765b3b6ad695cc1f044f19efe644
+Bug: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2331
+Bug-Debian: https://bugs.debian.org/1133845
+Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2026-21413
+---
+ src/decoders/decoders_dcraw.cpp | 3 ++-
+ 1 file changed, 2 insertions(+), 1 deletion(-)
+
+diff --git a/src/decoders/decoders_dcraw.cpp b/src/decoders/decoders_dcraw.cpp
+index 183136b..fc73e6c 100644
+--- a/src/decoders/decoders_dcraw.cpp
++++ b/src/decoders/decoders_dcraw.cpp
+@@ -560,6 +560,7 @@ void LibRaw::lossless_jpeg_load_raw()
+ if (jh.clrs == 4 && jwide >= raw_width * 2)
+ jhigh *= 2;
+
++
+ try
+ {
+ for (jrow = 0; jrow < jh.high; jrow++)
+@@ -588,7 +589,7 @@ void LibRaw::lossless_jpeg_load_raw()
+ col += (row--, raw_width);
+ if (row > raw_height)
+ throw LIBRAW_EXCEPTION_IO_CORRUPT;
+- if ((unsigned)row < raw_height)
++ if (((unsigned)row < raw_height) && ((unsigned)col < raw_width))
+ RAW(row, col) = val;
+ if (++col >= raw_width)
+ col = (row++, 0);
diff -Nru libraw-0.21.4/debian/patches/CVE-2026-24450.patch libraw-0.21.4/debian/patches/CVE-2026-24450.patch
--- libraw-0.21.4/debian/patches/CVE-2026-24450.patch 1970-01-01 01:00:00.000000000 +0100
+++ libraw-0.21.4/debian/patches/CVE-2026-24450.patch 2026-07-29 03:53:35.000000000 +0200
@@ -0,0 +1,55 @@
+From: Alex Tutubalin <[email protected]>
+Date: Thu, 12 Mar 2026 20:34:53 +0300
+Subject: Fix for TALOS-2026-2363: avoid integer overflow in allocation size
+ calculation. Also: check for EOF in read loop
+
+Origin: https://github.com/LibRaw/LibRaw/commit/c911c9b9edffa5fab99f828d0fee6dd2d0f6105f
+Bug: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2363
+Bug-Debian: https://bugs.debian.org/1133845
+Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2026-24450
+---
+ src/decoders/fp_dng.cpp | 12 ++++++++++--
+ 1 file changed, 10 insertions(+), 2 deletions(-)
+
+diff --git a/src/decoders/fp_dng.cpp b/src/decoders/fp_dng.cpp
+index df7fe6c..4bb8f42 100644
+--- a/src/decoders/fp_dng.cpp
++++ b/src/decoders/fp_dng.cpp
+@@ -611,12 +611,17 @@ void LibRaw::uncompressed_fp_dng_load_raw()
+ tiles.init(ifd, imgdata.sizes, libraw_internal_data.unpacker_data, libraw_internal_data.unpacker_data.order,
+ libraw_internal_data.internal_data.input);
+
++ // Max bytes: 2^16 raw width * 2^2 bytes/pixel * 2^2 channels = 2^20, so check against 2^22
++ INT64 rowbytes = INT64(MAX(tiles.tileWidth, imgdata.sizes.raw_width)) * INT64(MAX(bytesps,4)) * INT64(ifd->samples);
++ if(rowbytes > (1LL << 22))
++ throw LIBRAW_EXCEPTION_TOOBIG;
++
+ INT64 allocsz = INT64(tiles.tileCnt) * INT64(tiles.tileWidth) * INT64(tiles.tileHeight) * INT64(ifd->samples) * INT64(sizeof(float));
+ if (allocsz > INT64(imgdata.rawparams.max_raw_memory_mb) * INT64(1024 * 1024))
+ throw LIBRAW_EXCEPTION_TOOBIG;
+
+ if (ifd->sample_format == 3)
+- float_raw_image = (float *)calloc(tiles.tileCnt * tiles.tileWidth * tiles.tileHeight *ifd->samples, sizeof(float));
++ float_raw_image = (float *)calloc(allocsz,1);
+ else
+ throw LIBRAW_EXCEPTION_DECODE_RAW; // Only float supported
+
+@@ -633,6 +638,7 @@ void LibRaw::uncompressed_fp_dng_load_raw()
+ size_t rowsInTile = y + tiles.tileHeight > imgdata.sizes.raw_height ? imgdata.sizes.raw_height - y : tiles.tileHeight;
+ size_t colsInTile = x + tiles.tileWidth > imgdata.sizes.raw_width ? imgdata.sizes.raw_width - x : tiles.tileWidth;
+
++ // inrowbytes is less then 2^22 (see above) so conversion to int is safe
+ size_t inrowbytes = colsInTile * bytesps * ifd->samples;
+ int fullrowbytes = tiles.tileWidth *bytesps * ifd->samples;
+ size_t outrowbytes = colsInTile * sizeof(float) * ifd->samples;
+@@ -642,7 +648,9 @@ void LibRaw::uncompressed_fp_dng_load_raw()
+ unsigned char *dst = fullrowbytes > inrowbytes ? rowbuf.data(): // last tile in row, use buffer
+ (unsigned char *)&float_raw_image
+ [((y + row) * imgdata.sizes.raw_width + x) * ifd->samples];
+- libraw_internal_data.internal_data.input->read(dst, 1, fullrowbytes);
++ int bytesread = libraw_internal_data.internal_data.input->read(dst, 1, fullrowbytes);
++ if (bytesread < fullrowbytes)
++ derror();
+ if (bytesps == 2 && difford)
+ libraw_swab(dst, fullrowbytes);
+ else if (bytesps == 3 && (libraw_internal_data.unpacker_data.order == 0x4949)) // II-16bit
diff -Nru libraw-0.21.4/debian/patches/CVE-2026-24660.patch libraw-0.21.4/debian/patches/CVE-2026-24660.patch
--- libraw-0.21.4/debian/patches/CVE-2026-24660.patch 1970-01-01 01:00:00.000000000 +0100
+++ libraw-0.21.4/debian/patches/CVE-2026-24660.patch 2026-07-29 03:53:35.000000000 +0200
@@ -0,0 +1,335 @@
+From: Alex Tutubalin <[email protected]>
+Date: Wed, 11 Mar 2026 11:57:24 +0300
+Subject: X3F decoder: implemented hard single allocation limit via
+ LIBRAW_X3F_ALLOC_LIMIT_MB define;
+ allocation size calculation converted to 64 bit arithm;
+ fix for TALOS-2026-2359
+
+Origin: https://github.com/LibRaw/LibRaw/commit/ac151a829b8d3e4c74fa3aefa8a029c3cc3f857f
+Bug: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2359
+Bug-Debian: https://bugs.debian.org/1133845
+Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2026-24660
+---
+ libraw/libraw_const.h | 4 ++
+ src/x3f/x3f_utils_patched.cpp | 104 +++++++++++++++++++++++++-----------------
+ 2 files changed, 67 insertions(+), 41 deletions(-)
+
+diff --git a/libraw/libraw_const.h b/libraw/libraw_const.h
+index 61f8028..1e32fdf 100644
+--- a/libraw/libraw_const.h
++++ b/libraw/libraw_const.h
+@@ -55,6 +55,10 @@ it under the terms of the one of two licenses as you choose:
+ #endif
+
+
++/* max data size for known foveon cameras: 30mpix * 3 channels * 2 bytes = 180Mb, so 512Mb is OK for everything until/if new cameras will arrive */
++#ifndef LIBRAW_X3F_ALLOC_LIMIT_MB
++#define LIBRAW_X3F_ALLOC_LIMIT_MB 512ULL
++#endif
+
+ /* LibRaw uses own memory pool management, with LIBRAW_MSIZE (512)
+ entries. It is enough for parsing/decoding non-damaged files, but
+diff --git a/src/x3f/x3f_utils_patched.cpp b/src/x3f/x3f_utils_patched.cpp
+index 21c7ab1..fb1ecc1 100644
+--- a/src/x3f/x3f_utils_patched.cpp
++++ b/src/x3f/x3f_utils_patched.cpp
+@@ -50,6 +50,37 @@ BSD-style License
+ /* Reading and writing - assuming little endian in the file */
+ /* --------------------------------------------------------------------- */
+
++static void *x3f_limited_malloc(UINT64 sz)
++{
++ if (sz > LIBRAW_X3F_ALLOC_LIMIT_MB * 1024ULL * 1024ULL)
++ throw LIBRAW_EXCEPTION_TOOBIG;
++ void *ret = malloc(sz);
++ if (!ret)
++ throw LIBRAW_EXCEPTION_ALLOC;
++ return ret;
++}
++
++static void *x3f_limited_calloc(UINT64 n, UINT64 sz)
++{
++ if (sz * n > LIBRAW_X3F_ALLOC_LIMIT_MB * 1024ULL * 1024ULL)
++ throw LIBRAW_EXCEPTION_TOOBIG;
++ void *ret = calloc(n, sz);
++ if (!ret)
++ throw LIBRAW_EXCEPTION_ALLOC;
++ return ret;
++}
++
++static void *x3f_limited_realloc(void *ptr, UINT64 sz)
++{
++ if (sz > LIBRAW_X3F_ALLOC_LIMIT_MB * 1024ULL * 1024ULL)
++ throw LIBRAW_EXCEPTION_TOOBIG;
++ void *ret = realloc(ptr, sz);
++ if (!ret)
++ throw LIBRAW_EXCEPTION_ALLOC;
++ return ret;
++}
++
++
+ static int x3f_get1(LibRaw_abstract_datastream *f)
+ {
+ /* Little endian file */
+@@ -134,7 +165,7 @@ unsigned x3f_get4(LibRaw_abstract_datastream *f)
+ int _i; \
+ (_T).size = (_NUM); \
+ (_T).element = \
+- (_TYPE *)realloc((_T).element, (_NUM) * sizeof((_T).element[0])); \
++ (_TYPE *)x3f_limited_realloc((_T).element, (_NUM) * sizeof((_T).element[0])); \
+ for (_i = 0; _i < (int)(_T).size; _i++) \
+ _GETX((_T).element[_i]); \
+ } while (0)
+@@ -144,7 +175,7 @@ unsigned x3f_get4(LibRaw_abstract_datastream *f)
+ { \
+ int _i; \
+ (_T).size = (_NUM); \
+- (_T).element = (x3f_property_t *)realloc( \
++ (_T).element = (x3f_property_t *)x3f_limited_realloc( \
+ (_T).element, (_NUM) * sizeof((_T).element[0])); \
+ for (_i = 0; _i < (int)(_T).size; _i++) \
+ { \
+@@ -161,7 +192,7 @@ unsigned x3f_get4(LibRaw_abstract_datastream *f)
+ for (_i = 0;; _i++) \
+ { \
+ (_T).size = _i + 1; \
+- (_T).element = (x3f_true_huffman_element_t *)realloc( \
++ (_T).element = (x3f_true_huffman_element_t *)x3f_limited_realloc( \
+ (_T).element, (_i + 1) * sizeof((_T).element[0])); \
+ GET1((_T).element[_i].code_size); \
+ GET1((_T).element[_i].code); \
+@@ -182,7 +213,7 @@ static void new_huffman_tree(x3f_hufftree_t *HTP, int bits)
+
+ HTP->free_node_index = 0;
+ HTP->total_node_index = HUF_TREE_MAX_NODES(leaves);
+- HTP->nodes = (x3f_huffnode_t *)calloc(1, HUF_TREE_MAX_NODES(leaves) *
++ HTP->nodes = (x3f_huffnode_t *)x3f_limited_calloc(1, HUF_TREE_MAX_NODES(leaves) *
+ sizeof(x3f_huffnode_t));
+ }
+
+@@ -209,7 +240,7 @@ static void cleanup_true(x3f_true_t **TRUP)
+
+ static x3f_true_t *new_true(x3f_true_t **TRUP)
+ {
+- x3f_true_t *TRU = (x3f_true_t *)calloc(1, sizeof(x3f_true_t));
++ x3f_true_t *TRU = (x3f_true_t *)x3f_limited_calloc(1, sizeof(x3f_true_t));
+
+ cleanup_true(TRUP);
+
+@@ -241,7 +272,7 @@ static void cleanup_quattro(x3f_quattro_t **QP)
+
+ static x3f_quattro_t *new_quattro(x3f_quattro_t **QP)
+ {
+- x3f_quattro_t *Q = (x3f_quattro_t *)calloc(1, sizeof(x3f_quattro_t));
++ x3f_quattro_t *Q = (x3f_quattro_t *)x3f_limited_calloc(1, sizeof(x3f_quattro_t));
+ int i;
+
+ cleanup_quattro(QP);
+@@ -286,7 +317,7 @@ static void cleanup_huffman(x3f_huffman_t **HUFP)
+
+ static x3f_huffman_t *new_huffman(x3f_huffman_t **HUFP)
+ {
+- x3f_huffman_t *HUF = (x3f_huffman_t *)calloc(1, sizeof(x3f_huffman_t));
++ x3f_huffman_t *HUF = (x3f_huffman_t *)x3f_limited_calloc(1, sizeof(x3f_huffman_t));
+
+ cleanup_huffman(HUFP);
+
+@@ -317,9 +348,7 @@ static x3f_huffman_t *new_huffman(x3f_huffman_t **HUFP)
+ if (!infile)
+ return NULL;
+ INT64 fsize = infile->size();
+- x3f_t *x3f = (x3f_t *)calloc(1, sizeof(x3f_t));
+- if (!x3f)
+- throw LIBRAW_EXCEPTION_ALLOC;
++ x3f_t *x3f = (x3f_t *)x3f_limited_calloc(1, sizeof(x3f_t));
+ try
+ {
+ x3f_info_t *I = NULL;
+@@ -383,7 +412,7 @@ static x3f_huffman_t *new_huffman(x3f_huffman_t **HUFP)
+ if (DS->num_directory_entries > 0)
+ {
+ size_t size = DS->num_directory_entries * sizeof(x3f_directory_entry_t);
+- DS->directory_entry = (x3f_directory_entry_t *)calloc(1, size);
++ DS->directory_entry = (x3f_directory_entry_t *)x3f_limited_calloc(1, size);
+ }
+
+ /* Traverse the directory */
+@@ -1220,15 +1249,8 @@ static uint32_t read_data_block(void **data, x3f_info_t *I,
+
+ if (fpos + size > I->input.file->size())
+ throw LIBRAW_EXCEPTION_IO_CORRUPT;
+-
+- // All known files from real cameras are many times smaller than 1 GB, so the hard limit is OK here.
+-
+- if(size > 1024*1024*1024)
+- throw LIBRAW_EXCEPTION_ALLOC;
+-
+- *data = (void *)malloc(size);
+- if (!*data)
+- throw LIBRAW_EXCEPTION_ALLOC;
++
++ *data = (void *)x3f_limited_malloc(size);
+
+ GETN(*data, size);
+
+@@ -1363,36 +1385,36 @@ static void x3f_load_true(x3f_info_t *I, x3f_directory_entry_t *DE)
+ uint32_t columns = Q->plane[0].columns;
+ uint32_t rows = Q->plane[0].rows;
+ uint32_t channels = 3;
+- uint32_t size = columns * rows * channels;
++ UINT64 size = UINT64(columns) * UINT64(rows) * UINT64(channels);
+
+ TRU->x3rgb16.columns = columns;
+ TRU->x3rgb16.rows = rows;
+ TRU->x3rgb16.channels = channels;
+ TRU->x3rgb16.row_stride = columns * channels;
+- TRU->x3rgb16.buf = malloc(sizeof(uint16_t) * size);
++ TRU->x3rgb16.buf = x3f_limited_malloc(sizeof(uint16_t) * size);
+ TRU->x3rgb16.data = (uint16_t *)TRU->x3rgb16.buf;
+
+ columns = Q->plane[2].columns;
+ rows = Q->plane[2].rows;
+ channels = 1;
+- size = columns * rows * channels;
++ size = UINT64(columns) * UINT64(rows) * UINT64(channels);
+
+ Q->top16.columns = columns;
+ Q->top16.rows = rows;
+ Q->top16.channels = channels;
+ Q->top16.row_stride = columns * channels;
+- Q->top16.buf = malloc(sizeof(uint16_t) * size);
++ Q->top16.buf = x3f_limited_malloc(sizeof(uint16_t) * size);
+ Q->top16.data = (uint16_t *)Q->top16.buf;
+ }
+ else
+ {
+- uint32_t size = ID->columns * ID->rows * 3;
++ UINT64 size = UINT64(ID->columns) * UINT64(ID->rows) * 3ULL;
+
+ TRU->x3rgb16.columns = ID->columns;
+ TRU->x3rgb16.rows = ID->rows;
+ TRU->x3rgb16.channels = 3;
+ TRU->x3rgb16.row_stride = ID->columns * 3;
+- TRU->x3rgb16.buf = malloc(sizeof(uint16_t) * size);
++ TRU->x3rgb16.buf = x3f_limited_malloc(sizeof(uint16_t) * size);
+ TRU->x3rgb16.data = (uint16_t *)TRU->x3rgb16.buf;
+ }
+
+@@ -1441,7 +1463,7 @@ static void x3f_load_huffman(x3f_info_t *I, x3f_directory_entry_t *DE, int bits,
+ x3f_directory_entry_header_t *DEH = &DE->header;
+ x3f_image_data_t *ID = &DEH->data_subsection.image_data;
+ x3f_huffman_t *HUF = new_huffman(&ID->huffman);
+- uint32_t size;
++ UINT64 size;
+
+ if (use_map_table)
+ {
+@@ -1454,21 +1476,21 @@ static void x3f_load_huffman(x3f_info_t *I, x3f_directory_entry_t *DE, int bits,
+ {
+ case X3F_IMAGE_RAW_HUFFMAN_X530:
+ case X3F_IMAGE_RAW_HUFFMAN_10BIT:
+- size = ID->columns * ID->rows * 3;
++ size = UINT64(ID->columns) * UINT64(ID->rows) * 3ULL;
+ HUF->x3rgb16.columns = ID->columns;
+ HUF->x3rgb16.rows = ID->rows;
+ HUF->x3rgb16.channels = 3;
+ HUF->x3rgb16.row_stride = ID->columns * 3;
+- HUF->x3rgb16.buf = malloc(sizeof(uint16_t) * size);
++ HUF->x3rgb16.buf = x3f_limited_malloc(sizeof(uint16_t) * size);
+ HUF->x3rgb16.data = (uint16_t *)HUF->x3rgb16.buf;
+ break;
+ case X3F_IMAGE_THUMB_HUFFMAN:
+- size = ID->columns * ID->rows * 3;
++ size = UINT64(ID->columns) * UINT64(ID->rows) * 3ULL;
+ HUF->rgb8.columns = ID->columns;
+ HUF->rgb8.rows = ID->rows;
+ HUF->rgb8.channels = 3;
+ HUF->rgb8.row_stride = ID->columns * 3;
+- HUF->rgb8.buf = malloc(sizeof(uint8_t) * size);
++ HUF->rgb8.buf = x3f_limited_malloc(sizeof(uint8_t) * size);
+ HUF->rgb8.data = (uint8_t *)HUF->rgb8.buf;
+ break;
+ default:
+@@ -1568,7 +1590,7 @@ static void x3f_load_camf_decode_type2(x3f_camf_t *CAMF)
+ int i;
+
+ CAMF->decoded_data_size = CAMF->data_size;
+- CAMF->decoded_data = malloc(CAMF->decoded_data_size);
++ CAMF->decoded_data = x3f_limited_malloc(CAMF->decoded_data_size);
+
+ for (i = 0; i < (int)CAMF->data_size; i++)
+ {
+@@ -1609,7 +1631,7 @@ static void camf_decode_type4(x3f_camf_t *CAMF)
+
+ CAMF->decoded_data_size = dst_size;
+
+- CAMF->decoded_data = malloc(CAMF->decoded_data_size);
++ CAMF->decoded_data = x3f_limited_malloc(CAMF->decoded_data_size);
+ memset(CAMF->decoded_data, 0, CAMF->decoded_data_size);
+
+ dst = (uint8_t *)CAMF->decoded_data;
+@@ -1688,7 +1710,7 @@ static void x3f_load_camf_decode_type4(x3f_camf_t *CAMF)
+ for (i = 0, p = (uint8_t *)CAMF->data; *p != 0; i++)
+ {
+ /* TODO: Is this too expensive ??*/
+- element = (x3f_true_huffman_element_t *)realloc(element,
++ element = (x3f_true_huffman_element_t *)x3f_limited_realloc(element,
+ (i + 1) * sizeof(*element));
+
+ element[i].code_size = *p++;
+@@ -1729,7 +1751,7 @@ static void camf_decode_type5(x3f_camf_t *CAMF)
+ int32_t i;
+
+ CAMF->decoded_data_size = CAMF->t5.decoded_data_size;
+- CAMF->decoded_data = malloc(CAMF->decoded_data_size);
++ CAMF->decoded_data = x3f_limited_malloc(CAMF->decoded_data_size);
+
+ dst = (uint8_t *)CAMF->decoded_data;
+
+@@ -1753,7 +1775,7 @@ static void x3f_load_camf_decode_type5(x3f_camf_t *CAMF)
+ for (i = 0, p = (uint8_t *)CAMF->data; *p != 0; i++)
+ {
+ /* TODO: Is this too expensive ??*/
+- element = (x3f_true_huffman_element_t *)realloc(element,
++ element = (x3f_true_huffman_element_t *)x3f_limited_realloc(element,
+ (i + 1) * sizeof(*element));
+
+ element[i].code_size = *p++;
+@@ -1796,8 +1818,8 @@ static void x3f_setup_camf_property_entry(camf_entry_t *entry)
+ uint32_t num = entry->property_num = *(uint32_t *)v;
+ uint32_t off = *(uint32_t *)(v + 4);
+
+- entry->property_name = (char **)malloc(num * sizeof(uint8_t *));
+- entry->property_value = (uint8_t **)malloc(num * sizeof(uint8_t *));
++ entry->property_name = (char **)x3f_limited_malloc(num * sizeof(uint8_t *));
++ entry->property_value = (uint8_t **)x3f_limited_malloc(num * sizeof(uint8_t *));
+
+ for (i = 0; i < (int)num; i++)
+ {
+@@ -1851,7 +1873,7 @@ static void get_matrix_copy(camf_entry_t *entry)
+ : sizeof(uint32_t)) *
+ elements;
+
+- entry->matrix_decoded = malloc(size);
++ entry->matrix_decoded = x3f_limited_malloc(size);
+
+ switch (element_size)
+ {
+@@ -1921,7 +1943,7 @@ static void x3f_setup_camf_matrix_entry(camf_entry_t *entry)
+ uint32_t dim = entry->matrix_dim = *(uint32_t *)(v + 4);
+ uint32_t off = entry->matrix_data_off = *(uint32_t *)(v + 8);
+ camf_dim_entry_t *dentry = entry->matrix_dim_entry =
+- (camf_dim_entry_t *)malloc(dim * sizeof(camf_dim_entry_t));
++ (camf_dim_entry_t *)x3f_limited_malloc(dim * sizeof(camf_dim_entry_t));
+
+ for (i = 0; i < (int)dim; i++)
+ {
+@@ -1972,7 +1994,7 @@ static void x3f_setup_camf_entries(x3f_camf_t *CAMF)
+ }
+
+ /* TODO: lots of realloc - may be inefficient */
+- entry = (camf_entry_t *)realloc(entry, (i + 1) * sizeof(camf_entry_t));
++ entry = (camf_entry_t *)x3f_limited_realloc(entry, (i + 1) * sizeof(camf_entry_t));
+
+ /* Pointer */
+ entry[i].entry = p;
diff -Nru libraw-0.21.4/debian/patches/CVE-2026-5342.patch libraw-0.21.4/debian/patches/CVE-2026-5342.patch
--- libraw-0.21.4/debian/patches/CVE-2026-5342.patch 1970-01-01 01:00:00.000000000 +0100
+++ libraw-0.21.4/debian/patches/CVE-2026-5342.patch 2026-07-29 03:53:35.000000000 +0200
@@ -0,0 +1,61 @@
+From: Alex Tutubalin <[email protected]>
+Date: Tue, 17 Mar 2026 12:44:57 +0300
+Subject: Nikon padded/12bit: no need to calculate padded row size before
+ final raw_width adjustment
+
+Origin: https://github.com/LibRaw/LibRaw/commit/2468614a9cbcab6b75ca279ab60cac62156f7aeb
+Bug: https://github.com/LibRaw/LibRaw/issues/795
+Bug-Debian: https://bugs.debian.org/1132655
+Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2026-5342
+---
+ src/decoders/decoders_libraw.cpp | 18 ++++++++++++------
+ src/metadata/tiff.cpp | 2 --
+ 2 files changed, 12 insertions(+), 8 deletions(-)
+
+diff --git a/src/decoders/decoders_libraw.cpp b/src/decoders/decoders_libraw.cpp
+index eb277c3..5a82352 100644
+--- a/src/decoders/decoders_libraw.cpp
++++ b/src/decoders/decoders_libraw.cpp
+@@ -259,17 +259,23 @@ void LibRaw::fuji_14bit_load_raw()
+ void LibRaw::nikon_load_padded_packed_raw() // 12 bit per pixel, padded to 16
+ // bytes
+ {
++ unsigned bytesperrow = (((unsigned(S.raw_width) * 3u / 2u) + 15u) / 16u) * 16u; // bytes per row
++
+ // libraw_internal_data.unpacker_data.load_flags -> row byte count
+- if (libraw_internal_data.unpacker_data.load_flags < 2000 ||
+- libraw_internal_data.unpacker_data.load_flags > 64000)
+- return;
++ if (bytesperrow < 2000 || bytesperrow > 64000)
++ throw LIBRAW_EXCEPTION_IO_CORRUPT;
++
+ unsigned char *buf =
+- (unsigned char *)calloc(libraw_internal_data.unpacker_data.load_flags,1);
++ (unsigned char *)calloc(bytesperrow,1);
+ for (int row = 0; row < S.raw_height; row++)
+ {
+ checkCancel();
+- libraw_internal_data.internal_data.input->read(
+- buf, libraw_internal_data.unpacker_data.load_flags, 1);
++ int readed = libraw_internal_data.internal_data.input->read(
++ buf, 1, bytesperrow);
++
++ if (readed < (int)bytesperrow)
++ derror();
++
+ for (int icol = 0; icol < S.raw_width / 2; icol++)
+ {
+ imgdata.rawdata.raw_image[(row)*S.raw_width + (icol * 2)] =
+diff --git a/src/metadata/tiff.cpp b/src/metadata/tiff.cpp
+index 5ec07a2..5ba41ae 100644
+--- a/src/metadata/tiff.cpp
++++ b/src/metadata/tiff.cpp
+@@ -2031,8 +2031,6 @@ void LibRaw::apply_tiff()
+ INT64(tiff_ifd[raw].bytes))
+ {
+ load_raw = &LibRaw::nikon_load_padded_packed_raw;
+- load_flags = (((INT64(raw_width) * 3ULL / 2ULL) + 15ULL) / 16ULL) *
+- 16ULL; // bytes per row
+ }
+ else if (!strncmp(model, "NIKON Z 9", 9) && tiff_ifd[raw].offset)
+ {
diff -Nru libraw-0.21.4/debian/patches/series libraw-0.21.4/debian/patches/series
--- libraw-0.21.4/debian/patches/series 1970-01-01 01:00:00.000000000 +0100
+++ libraw-0.21.4/debian/patches/series 2026-07-29 03:53:35.000000000 +0200
@@ -0,0 +1,8 @@
+CVE-2026-21413.patch
+CVE-2026-20889.patch
+CVE-2026-24660.patch
+CVE-2026-24450.patch
+CVE-2026-20884/01-afba34ec3.patch
+CVE-2026-20884/02-dae685a19.patch
+CVE-2026-20884/03-aa4458eb5.patch
+CVE-2026-5342.patch
diff -Nru libraw-0.21.4/debian/salsa-ci.yml libraw-0.21.4/debian/salsa-ci.yml
--- libraw-0.21.4/debian/salsa-ci.yml 1970-01-01 01:00:00.000000000 +0100
+++ libraw-0.21.4/debian/salsa-ci.yml 2026-07-29 03:53:35.000000000 +0200
@@ -0,0 +1,9 @@
+---
+include:
+ - https://salsa.debian.org/salsa-ci-team/pipeline/raw/master/recipes/debian.yml
+
+variables:
+ RELEASE: 'trixie'
+ SALSA_CI_DISABLE_LINTIAN: 1
+ SALSA_CI_DISABLE_REPROTEST: 1
+ SALSA_CI_DISABLE_USCAN: 1
signature.asc
Description: PGP signature
--- End Message ---