CVE-2026-24450: Integer Overflow
An integer overflow vulnerability exists in the uncompressedfpdngloadraw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/librawto a version that resolves this vulnerability.Fixed in 0.22.1-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24450?
CVE-2026-24450 has a critical severity rating of 9.8 based on the CVSS score.
What is the impact of CVE-2026-24450?
CVE-2026-24450 can lead to a heap buffer overflow when processing specially crafted files.
How do I fix CVE-2026-24450?
To fix CVE-2026-24450, update to the latest version of LibRaw that addresses this vulnerability.
Who is affected by CVE-2026-24450?
Anyone using vulnerable versions of LibRaw for processing raw image files is affected by CVE-2026-24450.
Is an exploit available for CVE-2026-24450?
Exploits targeting CVE-2026-24450 may be created by attackers through maliciously crafted files.