First published: Sun Apr 20 2025(Updated: )
In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col and split_row values are not checked in 0x041f tag processing.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libraw | <0.21.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-43963 is considered to have a critical severity due to potential out-of-bounds access allowing exploitation.
To fix CVE-2025-43963, upgrade LibRaw to version 0.21.4 or later to mitigate the vulnerability.
CVE-2025-43963 is an out-of-bounds write vulnerability in the phase_one_correct function of LibRaw.
LibRaw versions before 0.21.4 are affected by CVE-2025-43963.
Exploitation of CVE-2025-43963 could lead to application crashes, data corruption, or arbitrary code execution.