CVE-2025-43963: Critical severity libraw vulnerability
Published Apr 20, 2025
·Updated
In LibRaw before 0.21.4, phaseonecorrect in decoders/loadmfbacks.cpp allows out-of-buffer access because splitcol and splitrow values are not checked in 0x041f tag processing.
Affected Software
3 affected componentsFixes available
Libraw Libraw<0.21.4
Libraw Libraw<0.21.4
debian/libraw<=0.20.2-1+deb11u1, <=0.20.2-2.1
0.20.2-1+deb11u20.21.4-2
Remediation
Patch Available
Event History
Apr 20, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Apr 21, 2025
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
May 10, 2025
Data Sourced
via Ubuntu·02:17 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-43963?
CVE-2025-43963 is considered to have a critical severity due to potential out-of-bounds access allowing exploitation.
2
How do I fix CVE-2025-43963?
To fix CVE-2025-43963, upgrade LibRaw to version 0.21.4 or later to mitigate the vulnerability.
3
What type of vulnerability is CVE-2025-43963?
CVE-2025-43963 is an out-of-bounds write vulnerability in the phase_one_correct function of LibRaw.
4
Which versions of LibRaw are affected by CVE-2025-43963?
LibRaw versions before 0.21.4 are affected by CVE-2025-43963.
5
What are the consequences of exploiting CVE-2025-43963?
Exploitation of CVE-2025-43963 could lead to application crashes, data corruption, or arbitrary code execution.