CVE-2026-27258: DNG SDK | Out-of-bounds Write (CWE-787)
DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds write vulnerability that could lead to application denial-of-service. An attacker could leverage this vulnerability to corrupt memory, causing the application to crash or become unresponsive. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27258?
CVE-2026-27258 is classified as a high-severity vulnerability due to its potential to cause application denial-of-service.
How do I fix CVE-2026-27258?
To mitigate CVE-2026-27258, update to a version of the Adobe DNG SDK that is 1.7.1 2502 or later.
What causes the vulnerability in CVE-2026-27258?
CVE-2026-27258 is caused by an out-of-bounds write that can lead to memory corruption.
What are the potential impacts of CVE-2026-27258?
The potential impacts of CVE-2026-27258 include application crashes and denial-of-service due to corrupted memory.
Who is affected by CVE-2026-27258?
CVE-2026-27258 affects users of Adobe DNG SDK versions 1.7.1 2502 and earlier.