CVE-2025-43964: Critical severity libraw vulnerability
Published Apr 20, 2025
·Updated
In LibRaw before 0.21.4, tag 0x412 processing in phaseonecorrect in decoders/loadmfbacks.cpp does not enforce minimum w0 and w1 values.
Affected Software
3 affected componentsFixes available
Libraw Libraw<0.21.4
Libraw Libraw<0.21.4
debian/libraw<=0.20.2-1+deb11u1, <=0.20.2-2.1
0.20.2-1+deb11u20.21.4-2
Remediation
Patch Available
Event History
Apr 20, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Apr 21, 2025
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
May 10, 2025
Data Sourced
via Ubuntu·02:17 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-43964?
CVE-2025-43964 is classified as a moderate severity vulnerability due to the lack of input validation affecting image processing.
2
How do I fix CVE-2025-43964?
To fix CVE-2025-43964, update LibRaw to version 0.21.4 or later, which addresses the issue with tag 0x412 processing.
3
What versions of LibRaw are affected by CVE-2025-43964?
CVE-2025-43964 affects LibRaw versions prior to 0.21.4.
4
What are the potential impacts of CVE-2025-43964?
The vulnerability may lead to incorrect image processing, resulting in potential data corruption or application crashes.
5
Where can I find more information about CVE-2025-43964?
For more details on CVE-2025-43964, refer to the official release notes from LibRaw regarding version 0.21.4.