CVE-2026-48267: DNG SDK | NULL Pointer Dereference (CWE-476)
DNG SDK versions 1.7.1 2536 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DNG SDKto a version that resolves this vulnerability.Fixed in 1.7.1Patch 2536
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48267?
The severity of CVE-2026-48267 is rated as medium with a score of 5.5.
How do I fix CVE-2026-48267?
To fix CVE-2026-48267, upgrade to a version of DNG SDK later than 1.7.1 2536.
What is a NULL Pointer Dereference in CVE-2026-48267?
A NULL Pointer Dereference in CVE-2026-48267 refers to a situation where the application attempts to access a memory location that has not been initialized, potentially causing a crash.
What impact does CVE-2026-48267 have on applications?
CVE-2026-48267 can result in a denial-of-service condition, making the application unavailable to users.
Which versions of DNG SDK are affected by CVE-2026-48267?
DNG SDK versions 1.7.1 2536 and earlier are affected by CVE-2026-48267.