CVE-2026-21354: DNG SDK | Integer Overflow or Wraparound (CWE-190)
DNG SDK versions 1.7.1 2410 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to cause the application to crash or become unresponsive. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21354?
CVE-2026-21354 is classified as a high severity vulnerability that can lead to application denial-of-service.
How do I fix CVE-2026-21354?
To fix CVE-2026-21354, upgrade to a version of DNG SDK that is later than 1.7.1 2410.
What impact does CVE-2026-21354 have on affected systems?
CVE-2026-21354 can potentially cause the affected application to crash or become unresponsive.
Who is affected by CVE-2026-21354?
CVE-2026-21354 affects users of DNG SDK versions 1.7.1 2410 and earlier.
Is CVE-2026-21354 an easily exploitable vulnerability?
Yes, an attacker may exploit CVE-2026-21354 with relatively low effort to cause application instability.