CVE-2025-43961: Critical severity libraw vulnerability
Published Apr 20, 2025
·Updated
In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser.
Affected Software
3 affected componentsFixes available
Libraw Libraw<0.21.4
Libraw Libraw<0.21.4
debian/libraw<=0.20.2-1+deb11u1, <=0.20.2-2.1
0.20.2-1+deb11u20.21.4-2
Remediation
Patch Available
Event History
Apr 20, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Apr 21, 2025
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
May 10, 2025
Data Sourced
via Ubuntu·02:17 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-43961?
CVE-2025-43961 is classified as a high severity vulnerability due to its potential to cause out-of-bounds reads.
2
How do I fix CVE-2025-43961?
The fix for CVE-2025-43961 is to upgrade LibRaw to version 0.21.4 or later.
3
What software is affected by CVE-2025-43961?
CVE-2025-43961 affects LibRaw versions prior to 0.21.4.
4
What is the impact of CVE-2025-43961?
CVE-2025-43961 can lead to out-of-bounds read vulnerabilities when processing Fujifilm 0xf00c tag data.
5
Is CVE-2025-43961 a known exploit?
As of now, there are no publicly known exploits specifically targeting CVE-2025-43961.