CVE-2026-20884: Integer Overflow
An integer overflow vulnerability exists in the deflatedngloadraw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/librawto a version that resolves this vulnerability.Fixed in 0.22.1-1 - Upgrade
Upgrade
LibRawto a version that resolves this vulnerability.Patch 8dc68e2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20884?
CVE-2026-20884 has a critical severity rating of 9.8.
How do I fix CVE-2026-20884?
To fix CVE-2026-20884, update LibRaw to the latest version where the vulnerability has been addressed.
What type of vulnerability is CVE-2026-20884?
CVE-2026-20884 is classified as an integer overflow vulnerability leading to a buffer overflow.
What are the potential consequences of exploiting CVE-2026-20884?
Exploiting CVE-2026-20884 can result in a heap buffer overflow, which may allow attackers to execute arbitrary code.
Who is affected by CVE-2026-20884?
Users and applications utilizing vulnerable versions of LibRaw are affected by CVE-2026-20884.