CVE-2026-21413: Buffer Overflow
A heap-based buffer overflow vulnerability exists in the losslessjpegloadraw functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/librawto a version that resolves this vulnerability.Fixed in 0.22.1-1 - Upgrade
Upgrade
LibRawto a version that resolves this vulnerability.Patch 0b56545 - Upgrade
Upgrade
LibRawto a version that resolves this vulnerability.Patch d20315b
Event History
Frequently Asked Questions
What is CVE-2026-21413?
CVE-2026-21413 is a critical heap-based buffer overflow vulnerability in the lossless_jpeg_load_raw functionality of LibRaw.
What is the risk level of CVE-2026-21413?
CVE-2026-21413 has a risk level of 90, categorized as critical with a score of 9.8.
How can an attacker exploit CVE-2026-21413?
An attacker can exploit CVE-2026-21413 by providing a specially crafted malicious file to trigger the heap buffer overflow.
What are the potential impacts of CVE-2026-21413?
The impacts of CVE-2026-21413 include potential remote code execution and system crashes due to heap memory corruption.
How do I mitigate CVE-2026-21413?
To mitigate CVE-2026-21413, users should update to the latest version of LibRaw that addresses this vulnerability.