CVE-2025-43962: Critical severity libraw vulnerability
Published Apr 20, 2025
·Updated
In LibRaw before 0.21.4, phaseonecorrect in decoders/loadmfbacks.cpp has out-of-bounds reads for tag 0x412 processing, related to large w0 or w1 values or the frac and mult calculations.
Affected Software
3 affected componentsFixes available
Libraw Libraw<0.21.4
Libraw Libraw<0.21.4
debian/libraw<=0.20.2-1+deb11u1, <=0.20.2-2.1
0.20.2-1+deb11u20.21.4-2
Remediation
Patch Available
Event History
Apr 20, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Apr 21, 2025
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
May 10, 2025
Data Sourced
via Ubuntu·02:17 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-43962?
CVE-2025-43962 has been classified as a high-severity vulnerability due to its potential for out-of-bounds reads.
2
How do I fix CVE-2025-43962?
To resolve CVE-2025-43962, update LibRaw to version 0.21.4 or later.
3
What causes the vulnerability in CVE-2025-43962?
CVE-2025-43962 is caused by out-of-bounds reads in the phase_one_correct function due to improper handling of large w0 or w1 values.
4
Which versions are affected by CVE-2025-43962?
CVE-2025-43962 affects all LibRaw versions prior to 0.21.4.
5
What should I do if I cannot update LibRaw to fix CVE-2025-43962?
If you cannot update LibRaw, consider implementing mitigations to minimize the risk of exploitation.