First published: Sun Apr 20 2025(Updated: )
In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing, related to large w0 or w1 values or the frac and mult calculations.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libraw | <0.21.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-43962 has been classified as a high-severity vulnerability due to its potential for out-of-bounds reads.
To resolve CVE-2025-43962, update LibRaw to version 0.21.4 or later.
CVE-2025-43962 is caused by out-of-bounds reads in the phase_one_correct function due to improper handling of large w0 or w1 values.
CVE-2025-43962 affects all LibRaw versions prior to 0.21.4.
If you cannot update LibRaw, consider implementing mitigations to minimize the risk of exploitation.