CVE-2026-24660: Buffer Overflow
A heap-based buffer overflow vulnerability exists in the x3floadhuffman functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/librawto a version that resolves this vulnerability.Fixed in 0.22.1-1 - Upgrade
Upgrade
LibRawto a version that resolves this vulnerability.Patch d20315b
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24660?
CVE-2026-24660 has been classified as a high severity vulnerability due to its potential for exploitation leading to arbitrary code execution.
How do I fix CVE-2026-24660?
To resolve CVE-2026-24660, upgrade LibRaw to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-24660?
CVE-2026-24660 is a heap-based buffer overflow vulnerability that affects the x3f_load_huffman functionality in LibRaw.
Who can exploit CVE-2026-24660?
Any attacker who can provide a specially crafted malicious file can exploit CVE-2026-24660.
What versions of LibRaw are affected by CVE-2026-24660?
CVE-2026-24660 specifically affects LibRaw version 0.22.0.