CVE-2026-21095: Buffer Overflow
Published Sep 9, 2026
·Updated
Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.
Affected Software
1 affected component
libimagecodec.quram.so<SMR Sep-2026 Release 1
Event History
Sep 9, 2026
CVE Published
via MITRE·04:47 AM
Data Sourced
via MITRE·04:47 AM
DescriptionWeakness
Frequently Asked Questions
1
What would an attacker need to do to exploit this issue?
An attacker would need to cause the affected DNG decoder in libimagecodec.quram.so to process maliciously crafted image data. The stated impact is remote arbitrary code execution.
2
Which releases are affected?
The issue affects libimagecodec.quram.so before the SMR Sep-2026 Release 1 update. The provided information does not identify specific device models or operating-system versions.