CVE-2026-20889: Buffer Overflow
A heap-based buffer overflow vulnerability exists in the x3fthumbloader functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/librawto a version that resolves this vulnerability.Fixed in 0.22.1-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20889?
CVE-2026-20889 has a critical severity rating of 9.8.
How do I fix CVE-2026-20889?
To fix CVE-2026-20889, update LibRaw to the latest version that addresses this buffer overflow vulnerability.
What type of vulnerability is CVE-2026-20889?
CVE-2026-20889 is a heap-based buffer overflow vulnerability.
What can an attacker do with CVE-2026-20889?
An attacker can exploit CVE-2026-20889 by providing a specially crafted malicious file that triggers the heap buffer overflow.
Which software is affected by CVE-2026-20889?
CVE-2026-20889 affects the LibRaw library.