REDHAT-BUG-2455959: Buffer Overflow
Published Apr 7, 2026
·Updated
A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
1 affected component
Libraw Libraw>=0b56545<=d20315b
Event History
Apr 7, 2026
Data Sourced
via Red Hat·03:06 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2455959?
The severity of REDHAT-BUG-2455959 is rated as high with a score of 7.
2
How do I fix REDHAT-BUG-2455959?
To fix REDHAT-BUG-2455959, update to the latest version of LibRaw that contains the patch for this vulnerability.
3
What kind of vulnerability is REDHAT-BUG-2455959?
REDHAT-BUG-2455959 is a heap-based buffer overflow vulnerability.
4
How can an attacker exploit REDHAT-BUG-2455959?
An attacker can exploit REDHAT-BUG-2455959 by providing a specially crafted malicious file that triggers the buffer overflow.
5
What is affected by REDHAT-BUG-2455959?
The vulnerability affects the HuffTable::initval functionality in LibRaw.