Bug 2454464 - CVE-2026-5342 LibRaw: LibRaw: Out-of-bounds read via `load_flags/raw_width` argument manipulation [fedora-all]
Summary: CVE-2026-5342 LibRaw: LibRaw: Out-of-bounds read via `load_flags/raw_width` a...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: LibRaw
Version: rawhide
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Gwyn Ciesla
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["9ccaac71-7cb1-406a-b166-6...
Depends On:
Blocks: CVE-2026-5342
TreeView+ depends on / blocked
 
Reported: 2026-04-02 16:42 UTC by Sandipan Roy
Modified: 2026-04-09 01:39 UTC (History)
4 users (show)

Fixed In Version: LibRaw-0.22.1-1.fc45
Clone Of:
Environment:
Last Closed: 2026-04-08 22:36:02 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Sandipan Roy 2026-04-02 16:42:36 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 1 Fedora Update System 2026-04-08 21:07:26 UTC
FEDORA-2026-ffba395f42 (deepin-image-viewer-5.8.2-21.fc45, dtk6gui-6.7.32-5.fc45, and 26 more) has been submitted as an update to Fedora 45.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-ffba395f42

Comment 2 Fedora Update System 2026-04-08 22:36:02 UTC
FEDORA-2026-ffba395f42 (deepin-image-viewer-5.8.2-21.fc45, dtk6gui-6.7.32-5.fc45, and 26 more) has been pushed to the Fedora 45 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 3 Fedora Update System 2026-04-08 23:11:30 UTC
FEDORA-2026-bef0050737 (deepin-image-viewer-5.8.2-21.fc44, dtk6gui-6.7.32-5.fc44, and 26 more) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-bef0050737

Comment 4 Fedora Update System 2026-04-09 01:39:19 UTC
FEDORA-2026-bef0050737 has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-bef0050737`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-bef0050737

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.


Note You need to log in before you can comment on or make changes to this bug.