[CLSA-2026:1777941038] LibRaw: Fix of CVE-2026-21413
Type:
security
Severity:
Critical
Release date:
2026-05-05 00:30:46 UTC
Description:
- CVE-2026-21413: fix heap-based buffer overflow in LibRaw::lossless_jpeg_load_raw by adding (unsigned)col < raw_width bounds check before the RAW(row, col) write
Updated packages:
  • LibRaw-0.21.1-1.el9.tuxcare.els2.i686.rpm
    sha:81f4a5fb1de7e8f08907096a2aafcf8960830bdc227904e510f78683c4a89d15
  • LibRaw-0.21.1-1.el9.tuxcare.els2.x86_64.rpm
    sha:8e0bbc8b102d2fca7dddbe0c83d8ed4a1fe676cef89cb84dca1461c0ed779f62
  • LibRaw-devel-0.21.1-1.el9.tuxcare.els2.i686.rpm
    sha:7d201d30ae7ab6e2158e219106d727c9f51fafd567d6ae9c1b8db3db86d487b7
  • LibRaw-devel-0.21.1-1.el9.tuxcare.els2.x86_64.rpm
    sha:29cf5e23ef423a1ed720a65975340b59e908c987564b84a708fd8f2694533855
  • LibRaw-samples-0.21.1-1.el9.tuxcare.els2.x86_64.rpm
    sha:a2ec1ba7a225859379364e5c298e711a4f978fba2f3777a0753f7a180489ff50
  • LibRaw-static-0.21.1-1.el9.tuxcare.els2.x86_64.rpm
    sha:ba663dc5b76ab178c2b29e1e2b09823a1c81f15c8d68956c77c5319224871ed9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.