Where
-Infinity
0
Severity
7
Buffer Overflow

LibRaw 0.21 is vulnerable to Buffer Overflow in the stretch() function (src/librawcxx.cpp) and fujirotate() function (src/decoders/fuji.cpp).

First published (updated )
Buffer Overflow

LibRaw is a library for reading RAW files obtained from digital photo cameras (CRW/CR2, NEF, RAF, DNG, and others).Security Fix(es): LibRaw: LibRaw: Arbitrary code execution via a specially crafted malicious file (CVE-2026-24450) LibRaw: LibRaw: Arbitrary code execution via heap-based buffer overflow in lossless JPEG loading (CVE-2026-21413) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Remedy

<tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> LibRaw-0.21.1-2.el9_8.src.rpm </td> <td class="checksum">SHA-256: bd08f2bfbe652e2603320ab92ce19a8079b98979d9c059e8f3e69b497e296e76</td> </tr> <tr> <th colspan="2">ppc64le</th> </tr> <tr> <td class="name"> LibRaw-0.21.1-2.el9_8.ppc64le.rpm </td> <td class="checksum">SHA-256: 1379fc70ca331bbe74b11dbbd18c8fcdbaea236b3b467a2f160f637841d0a7a3</td> </tr> <tr> <td class="name"> LibRaw-debuginfo-0.21.1-2.el9_8.ppc64le.rpm </td> <td class="checksum">SHA-256: a9477e40e45a8227dbc764931101a0ccf352b5d6d7f27c673fc704d115041452</td> </tr> <tr> <td class="name"> LibRaw-debugsource-0.21.1-2.el9_8.ppc64le.rpm </td> <td class="checksum">SHA-256: c04021e1958461139bc54990b099e9c72a0cbba4b874edc79deb85777c667814</td> </tr> <tr> <td class="name"> LibRaw-samples-debuginfo-0.21.1-2.el9_8.ppc64le.rpm </td> <td class="checksum">SHA-256: a9ce0a0ba49b24d7e7403d32e5e96fa29dd9711ac7a57d0c5bd4c7416af81102</td> </tr> </tbody>Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> LibRaw-0.21.1-2.el9_8.src.rpm </td> <td class="checksum">SHA-256: bd08f2bfbe652e2603320ab92ce19a8079b98979d9c059e8f3e69b497e296e76</td> </tr> <tr> <th colspan="2">x86_64</th> </tr> <tr> <td class="name"> LibRaw-0.21.1-2.el9_8.i686.rpm </td> <td class="checksum">SHA-256: 52ca975f9955e6ab529b037878142ed5ff4fa1407d4604d42707ab6569ee449a</td> </tr> <tr> <td class="name"> LibRaw-0.21.1-2.el9_8.x86_64.rpm </td> <td class="checksum">SHA-256: 82a6cafbaff297bd9108a49e59ca28541ac0c01dc23b19106f542cf7d09e53b7</td> </tr> <tr> <td class="name"> LibRaw-debuginfo-0.21.1-2.el9_8.i686.rpm </td> <td class="checksum">SHA-256: 5a332c02948f6b2e89c391656e8e668ff51c05e971f59311d08de2df187278ac</td> </tr> <tr> <td class="name"> LibRaw-debuginfo-0.21.1-2.el9_8.x86_64.rpm </td> <td class="checksum">SHA-256: 26b1380b0197d5d639743c6277053dc5a6c8b5c1c3593d739bde5aaf264abc72</td> </tr> <tr> <td class="name"> LibRaw-debugsource-0.21.1-2.el9_8.i686.rpm </td> <td class="checksum">SHA-256: f3bc4d6b83a74d35a9f99c9dba624c9cf2f9d0b08239267a7ba5f6909f0da3b2</td> </tr> <tr> <td class="name"> LibRaw-debugsource-0.21.1-2.el9_8.x86_64.rpm </td> <td class="checksum">SHA-256: a21d678ecfdd3416ab7f35e013f6f625dfce8a71507cbfccf3d2cf654e9ee093</td> </tr> <tr> <td class="name"> LibRaw-samples-debuginfo-0.21.1-2.el9_8.i686.rpm </td> <td class="checksum">SHA-256: 84e9c175aa2fc2b80798a515d64bef3c92e667660e302a498cd2b0deb625d497</td> </tr> <tr> <td class="name"> LibRaw-samples-debuginfo-0.21.1-2.el9_8.x86_64.rpm </td> <td class="checksum">SHA-256: 85849c47f22fe2affb9c4c8a7ee53340ec1c80f719180524ed2ea22de3fdd7b1</td> </tr> </tbody>Red Hat CodeReady Linux Builder for x86_64 9 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <th colspan="2">x86_64</th> </tr> <tr> <td class="name"> LibRaw-debuginfo-0.21.1-2.el9_8.i686.rpm </td> <td class="checksum">SHA-256: 5a332c02948f6b2e89c391656e8e668ff51c05e971f59311d08de2df187278ac</td> </tr> <tr> <td class="name"> LibRaw-debuginfo-0.21.1-2.el9_8.x86_64.rpm </td> <td class="checksum">SHA-256: 26b1380b0197d5d639743c6277053dc5a6c8b5c1c3593d739bde5aaf264abc72</td> </tr> <tr> <td class="name"> LibRaw-debugsource-0.21.1-2.el9_8.i686.rpm </td> <td class="checksum">SHA-256: f3bc4d6b83a74d35a9f99c9dba624c9cf2f9d0b08239267a7ba5f6909f0da3b2</td> </tr> <tr> <td class="name"> LibRaw-debugsource-0.21.1-2.el9_8.x86_64.rpm </td> <td class="checksum">SHA-256: a21d678ecfdd3416ab7f35e013f6f625dfce8a71507cbfccf3d2cf654e9ee093</td> </tr> <tr> <td class="name"> LibRaw-devel-0.21.1-2.el9_8.i686.rpm </td> <td class="checksum">SHA-256: 400d2ecd3fc36eaea5e24e87bf05fb15adc6c3d132619ab1300a7d64efe8992e</td> </tr> <tr> <td class="name"> LibRaw-devel-0.21.1-2.el9_8.x86_64.rpm </td> <td class="checksum">SHA-256: 5cac764f1129e2490d7085220d80cbd69f54d32d69ed6269a3f6dc49d950bfab</td> </tr> <tr> <td class="name"> LibRaw-samples-debuginfo-0.21.1-2.el9_8.i686.rpm </td> <td class="checksum">SHA-256: 84e9c175aa2fc2b80798a515d64bef3c92e667660e302a498cd2b0deb625d497</td> </tr> <tr> <td class="name"> LibRaw-samples-debuginfo-0.21.1-2.el9_8.x86_64.rpm </td> <td class="checksum">SHA-256: 85849c47f22fe2affb9c4c8a7ee53340ec1c80f719180524ed2ea22de3fdd7b1</td> </tr> </tbody>Red Hat CodeReady Linux Builder for Power, little endian 9 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <th colspan="2">ppc64le</th> </tr> <tr> <td class="name"> LibRaw-debuginfo-0.21.1-2.el9_8.ppc64le.rpm </td> <td class="checksum">SHA-256: a9477e40e45a8227dbc764931101a0ccf352b5d6d7f27c673fc704d115041452</td> </tr> <tr> <td class="name"> LibRaw-debugsource-0.21.1-2.el9_8.ppc64le.rpm </td> <td class="checksum">SHA-256: c04021e1958461139bc54990b099e9c72a0cbba4b874edc79deb85777c667814</td> </tr> <tr> <td class="name"> LibRaw-devel-0.21.1-2.el9_8.ppc64le.rpm </td> <td class="checksum">SHA-256: 103b3dbb1308b0bbc6a163423e71efa11c60660e21ac3d3017ecb8bd2830dff7</td> </tr> <tr> <td class="name"> LibRaw-samples-debuginfo-0.21.1-2.el9_8.ppc64le.rpm </td> <td class="checksum">SHA-256: a9ce0a0ba49b24d7e7403d32e5e96fa29dd9711ac7a57d0c5bd4c7416af81102</td> </tr> </tbody>Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.8 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <th colspan="2">x86_64</th> </tr> <tr> <td class="name"> LibRaw-debuginfo-0.21.1-2.el9_8.i686.rpm </td> <td class="checksum">SHA-256: 5a332c02948f6b2e89c391656e8e668ff51c05e971f59311d08de2df187278ac</td> </tr> <tr> <td class="name"> LibRaw-debuginfo-0.21.1-2.el9_8.x86_64.rpm </td> <td class="checksum">SHA-256: 26b1380b0197d5d639743c6277053dc5a6c8b5c1c3593d739bde5aaf264abc72</td> </tr> <tr> <td class="name"> LibRaw-debugsource-0.21.1-2.el9_8.i686.rpm </td> <td class="checksum">SHA-256: f3bc4d6b83a74d35a9f99c9dba624c9cf2f9d0b08239267a7ba5f6909f0da3b2</td> </tr> <tr> <td class="name"> LibRaw-debugsource-0.21.1-2.el9_8.x86_64.rpm </td> <td class="checksum">SHA-256: a21d678ecfdd3416ab7f35e013f6f625dfce8a71507cbfccf3d2cf654e9ee093</td> </tr> <tr> <td class="name"> LibRaw-devel-0.21.1-2.el9_8.i686.rpm </td> <td class="checksum">SHA-256: 400d2ecd3fc36eaea5e24e87bf05fb15adc6c3d132619ab1300a7d64efe8992e</td> </tr> <tr> <td class="name"> LibRaw-devel-0.21.1-2.el9_8.x86_64.rpm </td> <td class="checksum">SHA-256: 5cac764f1129e2490d7085220d80cbd69f54d32d69ed6269a3f6dc49d950bfab</td> </tr> <tr> <td class="name"> LibRaw-samples-debuginfo-0.21.1-2.el9_8.i686.rpm </td> <td class="checksum">SHA-256: 84e9c175aa2fc2b80798a515d64bef3c92e667660e302a498cd2b0deb625d497</td> </tr> <tr> <td class="name"> LibRaw-samples-debuginfo-0.21.1-2.el9_8.x86_64.rpm </td> <td class="checksum">SHA-256: 85849c47f22fe2affb9c4c8a7ee53340ec1c80f719180524ed2ea22de3fdd7b1</td> </tr> </tbody>Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.8 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <th colspan="2">ppc64le</th> </tr> <tr> <td class="name"> LibRaw-debuginfo-0.21.1-2.el9_8.ppc64le.rpm </td> <td class="checksum">SHA-256: a9477e40e45a8227dbc764931101a0ccf352b5d6d7f27c673fc704d115041452</td> </tr> <tr> <td class="name"> LibRaw-debugsource-0.21.1-2.el9_8.ppc64le.rpm </td> <td class="checksum">SHA-256: c04021e1958461139bc54990b099e9c72a0cbba4b874edc79deb85777c667814</td> </tr> <tr> <td class="name"> LibRaw-devel-0.21.1-2.el9_8.ppc64le.rpm </td> <td class="checksum">SHA-256: 103b3dbb1308b0bbc6a163423e71efa11c60660e21ac3d3017ecb8bd2830dff7</td> </tr> <tr> <td class="name"> LibRaw-samples-debuginfo-0.21.1-2.el9_8.ppc64le.rpm </td> <td class="checksum">SHA-256: a9ce0a0ba49b24d7e7403d32e5e96fa29dd9711ac7a57d0c5bd4c7416af81102</td> </tr> </tbody>Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> LibRaw-0.21.1-2.el9_8.src.rpm </td> <td class="checksum">SHA-256: bd08f2bfbe652e2603320ab92ce19a8079b98979d9c059e8f3e69b497e296e76</td> </tr> <tr> <th colspan="2">aarch64</th> </tr> <tr> <td class="name"> LibRaw-0.21.1-2.el9_8.aarch64.rpm </td> <td class="checksum">SHA-256: 409a4526604c6f7b8c147856cd86974cd7ddbce79fe353a0cd72f8cd63eb75b7</td> </tr> <tr> <td class="name"> LibRaw-debuginfo-0.21.1-2.el9_8.aarch64.rpm </td> <td class="checksum">SHA-256: 4d241aeff29fc889f64ec18ca452fb7b10118fe10a2f2a5baf6159d471f62a9c</td> </tr> <tr> <td class="name"> LibRaw-debugsource-0.21.1-2.el9_8.aarch64.rpm </td> <td class="checksum">SHA-256: 43b27084609d503f3272be56716f99034b7df6a7d058eca0ded09b2495c06938</td> </tr> <tr> <td class="name"> LibRaw-samples-debuginfo-0.21.1-2.el9_8.aarch64.rpm </td> <td class="checksum">SHA-256: e02d9be2075f20127f346c5ebe9772c73e68ae27f7056ce943ae209626f0d0ae</td> </tr> </tbody>Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> LibRaw-0.21.1-2.el9_8.src.rpm </td> <td class="checksum">SHA-256: bd08f2bfbe652e2603320ab92ce19a8079b98979d9c059e8f3e69b497e296e76</td> </tr> <tr> <th colspan="2">s390x</th> </tr> <tr> <td class="name"> LibRaw-0.21.1-2.el9_8.s390x.rpm </td> <td class="checksum">SHA-256: 32c47c76ab9f5f6e6c5888f498b51bcf159d821b3cc67f371925615ca825dc86</td> </tr> <tr> <td class="name"> LibRaw-debuginfo-0.21.1-2.el9_8.s390x.rpm </td> <td class="checksum">SHA-256: 6eb5230cac8f3641a4e2777e383d9037f49906add7229b5d54ce4b00021f1a4c</td> </tr> <tr> <td class="name"> LibRaw-debugsource-0.21.1-2.el9_8.s390x.rpm </td> <td class="checksum">SHA-256: efd670d7d823049ad77f9ea30b553fdb8cbbc3a20453517ceff5dae6b631ed27</td> </tr> <tr> <td class="name"> LibRaw-samples-debuginfo-0.21.1-2.el9_8.s390x.rpm </td> <td class="checksum">SHA-256: 6d00e70d31e9b39fb7e68d8aec2107def33324fa5f55dca073fd7edfe66ce9cb</td> </tr> </tbody>Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> LibRaw-0.21.1-2.el9_8.src.rpm </td> <td class="checksum">SHA-256: bd08f2bfbe652e2603320ab92ce19a8079b98979d9c059e8f3e69b497e296e76</td> </tr> <tr> <th colspan="2">x86_64</th> </tr> <tr> <td class="name"> LibRaw-0.21.1-2.el9_8.i686.rpm </td> <td class="checksum">SHA-256: 52ca975f9955e6ab529b037878142ed5ff4fa1407d4604d42707ab6569ee449a</td> </tr> <tr> <td class="name"> LibRaw-0.21.1-2.el9_8.x86_64.rpm </td> <td class="checksum">SHA-256: 82a6cafbaff297bd9108a49e59ca28541ac0c01dc23b19106f542cf7d09e53b7</td> </tr> <tr> <td class="name"> LibRaw-debuginfo-0.21.1-2.el9_8.i686.rpm </td> <td class="checksum">SHA-256: 5a332c02948f6b2e89c391656e8e668ff51c05e971f59311d08de2df187278ac</td> </tr> <tr> <td class="name"> LibRaw-debuginfo-0.21.1-2.el9_8.x86_64.rpm </td> <td class="checksum">SHA-256: 26b1380b0197d5d639743c6277053dc5a6c8b5c1c3593d739bde5aaf264abc72</td> </tr> <tr> <td class="name"> LibRaw-debugsource-0.21.1-2.el9_8.i686.rpm </td> <td class="checksum">SHA-256: f3bc4d6b83a74d35a9f99c9dba624c9cf2f9d0b08239267a7ba5f6909f0da3b2</td> </tr> <tr> <td class="name"> LibRaw-debugsource-0.21.1-2.el9_8.x86_64.rpm </td> <td class="checksum">SHA-256: a21d678ecfdd3416ab7f35e013f6f625dfce8a71507cbfccf3d2cf654e9ee093</td> </tr> <tr> <td class="name"> LibRaw-samples-debuginfo-0.21.1-2.el9_8.i686.rpm </td> <td class="checksum">SHA-256: 84e9c175aa2fc2b80798a515d64bef3c92e667660e302a498cd2b0deb625d497</td> </tr> <tr> <td class="name"> LibRaw-samples-debuginfo-0.21.1-2.el9_8.x86_64.rpm </td> <td class="checksum">SHA-256: 85849c47f22fe2affb9c4c8a7ee53340ec1c80f719180524ed2ea22de3fdd7b1</td> </tr> </tbody>Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> LibRaw-0.21.1-2.el9_8.src.rpm </td> <td class="checksum">SHA-256: bd08f2bfbe652e2603320ab92ce19a8079b98979d9c059e8f3e69b497e296e76</td> </tr> <tr> <th colspan="2">aarch64</th> </tr> <tr> <td class="name"> LibRaw-0.21.1-2.el9_8.aarch64.rpm </td> <td class="checksum">SHA-256: 409a4526604c6f7b8c147856cd86974cd7ddbce79fe353a0cd72f8cd63eb75b7</td> </tr> <tr> <td class="name"> LibRaw-debuginfo-0.21.1-2.el9_8.aarch64.rpm </td> <td class="checksum">SHA-256: 4d241aeff29fc889f64ec18ca452fb7b10118fe10a2f2a5baf6159d471f62a9c</td> </tr> <tr> <td class="name"> LibRaw-debugsource-0.21.1-2.el9_8.aarch64.rpm </td> <td class="checksum">SHA-256: 43b27084609d503f3272be56716f99034b7df6a7d058eca0ded09b2495c06938</td> </tr> <tr> <td class="name"> LibRaw-samples-debuginfo-0.21.1-2.el9_8.aarch64.rpm </td> <td class="checksum">SHA-256: e02d9be2075f20127f346c5ebe9772c73e68ae27f7056ce943ae209626f0d0ae</td> </tr> </tbody>Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> LibRaw-0.21.1-2.el9_8.src.rpm </td> <td class="checksum">SHA-256: bd08f2bfbe652e2603320ab92ce19a8079b98979d9c059e8f3e69b497e296e76</td> </tr> <tr> <th colspan="2">ppc64le</th> </tr> <tr> <td class="name"> LibRaw-0.21.1-2.el9_8.ppc64le.rpm </td> <td class="checksum">SHA-256: 1379fc70ca331bbe74b11dbbd18c8fcdbaea236b3b467a2f160f637841d0a7a3</td> </tr> <tr> <td class="name"> LibRaw-debuginfo-0.21.1-2.el9_8.ppc64le.rpm </td> <td class="checksum">SHA-256: a9477e40e45a8227dbc764931101a0ccf352b5d6d7f27c673fc704d115041452</td> </tr> <tr> <td class="name"> LibRaw-debugsource-0.21.1-2.el9_8.ppc64le.rpm </td> <td class="checksum">SHA-256: c04021e1958461139bc54990b099e9c72a0cbba4b874edc79deb85777c667814</td> </tr> <tr> <td class="name"> LibRaw-samples-debuginfo-0.21.1-2.el9_8.ppc64le.rpm </td> <td class="checksum">SHA-256: a9ce0a0ba49b24d7e7403d32e5e96fa29dd9711ac7a57d0c5bd4c7416af81102</td> </tr> </tbody>Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> LibRaw-0.21.1-2.el9_8.src.rpm </td> <td class="checksum">SHA-256: bd08f2bfbe652e2603320ab92ce19a8079b98979d9c059e8f3e69b497e296e76</td> </tr> <tr> <th colspan="2">s390x</th> </tr> <tr> <td class="name"> LibRaw-0.21.1-2.el9_8.s390x.rpm </td> <td class="checksum">SHA-256: 32c47c76ab9f5f6e6c5888f498b51bcf159d821b3cc67f371925615ca825dc86</td> </tr> <tr> <td class="name"> LibRaw-debuginfo-0.21.1-2.el9_8.s390x.rpm </td> <td class="checksum">SHA-256: 6eb5230cac8f3641a4e2777e383d9037f49906add7229b5d54ce4b00021f1a4c</td> </tr> <tr> <td class="name"> LibRaw-debugsource-0.21.1-2.el9_8.s390x.rpm </td> <td class="checksum">SHA-256: efd670d7d823049ad77f9ea30b553fdb8cbbc3a20453517ceff5dae6b631ed27</td> </tr> <tr> <td class="name"> LibRaw-samples-debuginfo-0.21.1-2.el9_8.s390x.rpm </td> <td class="checksum">SHA-256: 6d00e70d31e9b39fb7e68d8aec2107def33324fa5f55dca073fd7edfe66ce9cb</td> </tr> </tbody>
First published (updated )

https://www.libraw.org/news/libraw-0-22-1-release announces: LibRaw 0.22.1 Release is just published in our Github repository <https://github.com/LibRaw/LibRaw> and this site download section <https://www.libraw.org/download>.

This is bugfix-only release with these commits included:

Limit strcat space in hassy model manipulation Version increment; shlib increment: internal ABI has changed check panasonic enc8 tile width against image width CR3 parser: zero all buffers before fread skip memory allocation checks for OWNALLOC decoders DNG SDK glue: check for memory limits raw2image()/dcrawprocess() - check for int16 source data present Check for correct bayer pattern, pass incorect ones to vnginterpolate parserollei: zero input string before fgets Nikon padded/12bit: no need to calculate padded row size before final rawwidth adjustment TALOS-2026-2364: Fix for data size calculation integer overflow in float/deflated DNG loader; Check for read results Fix for TALOS-2026-2363: avoid integer overflow in allocation size calculation. Also: check for EOF in read loop X3F decoder: implemented hard single allocation limit via LIBRAWX3FALLOCLIMITMB define; allocation size calculation converted to 64 bit arithm; fix for TALOS-2026-2359 Fix for TALOS-2026-2358 Fix for TALOS-2026-2331 Fix for TALOS-2026-2330 Sony YCC decoder: check tile size; add +3 bytes to input buffer to avoid possible overrun in huffman decoder FP DNG data limit: perform calculations in 64 bit Add extra huffcoeff item to handle huffindex==17 with known (zero) value, not externally provided tag value use %lld format for timestamp parse/print where appropriate nikon coolscan loader: check for EOF Initialize olympus lensID bits CR3 parser: all file offsets are unsigned/64bit; check current offset against file size Add Canon EOS Kiss M2 to camera list Check real color count against filters; do not pass really 4-color images to fbdd or advanced demosaic Use LIBRAWEXCEPTION instead of own internal in losslessjpeg.h zero input string to avoid compare random stack garbage with tag names Check for eof in Pentax tag search loop Fuji decoder: initialize allocated buffers Further information about the vulnerabilities reported by Cisco Talos can be found in their reports:

- TALOS-2026-2330 / CVE-2026-20911 LibRaw HuffTable::initval heap-based buffer overflow vulnerability https://talosintelligence.com/vulnerabilityreports/TALOS-2026-2330

A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

- TALOS-2026-2331 / CVE-2026-21413 LibRaw losslessjpegloadraw heap-based buffer overflow vulnerability https://talosintelligence.com/vulnerabilityreports/TALOS-2026-2331

A heap-based buffer overflow vulnerability exists in the losslessjpegloadraw functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

- TALOS-2026-2358 / CVE-2026-20889 LibRaw x3fthumbloader heap-based buffer overflow vulnerability https://talosintelligence.com/vulnerabilityreports/TALOS-2026-2358

A heap-based buffer overflow vulnerability exists in the x3fthumbloader functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

- TALOS-2026-2359 / CVE-2026-24660 LibRaw x3floadhuffman heap-based buffer overflow vulnerability https://talosintelligence.com/vulnerabilityreports/TALOS-2026-2359

A heap-based buffer overflow vulnerability exists in the x3floadhuffman functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

- TALOS-2026-2363 / CVE-2026-24450 LibRaw uncompressedfpdngloadraw integer overflow vulnerability https://talosintelligence.com/vulnerabilityreports/TALOS-2026-2363

An integer overflow vulnerability exists in the uncompressedfpdngloadraw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

- TALOS-2026-2364 / CVE-2026-20884 LibRaw deflatedngloadraw integer overflow vulnerability https://talosintelligence.com/vulnerabilityreports/TALOS-2026-2364

An integer overflow vulnerability exists in the deflatedngloadraw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

Additional CVEs also appear to have been issued for some of the fixes:

- CVE-2026-5318 appears to be a duplicate for independent reporting of the TALOS-2026-2330 / CVE-2026-20911 issue in https://github.com/LibRaw/LibRaw/issues/794

- CVE-2026-5342 for the fix listed above as "Nikon padded/12bit: no need to calculate padded row size before final rawwidth adjustment" and originally reported in https://github.com/LibRaw/LibRaw/issues/795

-- -Alan Coopersmith- alan.coopersmith () oracle com Oracle Solaris Engineering - https://blogs.oracle.com/solaris

Severity
7
Buffer Overflow

A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

First published (updated )
Severity
7
Buffer Overflow

A heap-based buffer overflow vulnerability exists in the x3fthumbloader functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

First published (updated )
Severity
7
Buffer Overflow

A heap-based buffer overflow vulnerability exists in the losslessjpegloadraw functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

First published (updated )
Severity
7
Buffer Overflow

A heap-based buffer overflow vulnerability exists in the x3floadhuffman functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

First published (updated )
Severity
4
Buffer Overflow, Integer Overflow

An integer overflow vulnerability exists in the uncompressedfpdngloadraw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

First published (updated )
Severity
9.8
Buffer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

First published (updated )
Severity
9.8
Buffer Overflow, Out-of-bounds Read
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A heap-based buffer overflow vulnerability exists in the losslessjpegloadraw functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

1 / 2
Source: Red Hat
First published (updated )
Severity
9.8
Buffer Overflow, Integer Overflow
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A heap-based buffer overflow vulnerability exists in the x3fthumbloader functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

1 / 2
Source: Red Hat
First published (updated )
Severity
9.8
Buffer Overflow, Integer Overflow
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

A heap-based buffer overflow vulnerability exists in the x3floadhuffman functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

1 / 2
Source: Red Hat
First published (updated )
Severity
9.8
Integer Overflow, Buffer Overflow
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

An integer overflow vulnerability exists in the uncompressedfpdngloadraw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

1 / 2
Source: NVD
First published (updated )
Severity
9.8
Integer Overflow, Buffer Overflow
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

An integer overflow vulnerability exists in the deflatedngloadraw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

1 / 2
Source: NVD
First published (updated )
Severity
5.5
EPSS
0.08%
Buffer Overflow
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C

A flaw has been found in LibRaw up to 0.22.0. This affects the function LibRaw::nikonloadpaddedpackedraw of the file src/decoders/decoderslibraw.cpp of the component TIFF/NEF. Executing a manipulation of the argument loadflags/rawwidth can lead to out-of-bounds read. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 0.22.1 mitigates this issue. This patch is called b8397cd45657b84e88bd1202528d1764265f185c. It is advisable to upgrade the affected component.

1 / 2
Source: MITRE
First published (updated )
Severity
2.1
EPSS
0.03%
Buffer Overflow
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C

A weakness has been identified in LibRaw up to 0.22.0. This impacts the function HuffTable::initval of the file src/decompressors/losslessjpeg.cpp of the component JPEG DHT Parser. This manipulation of the argument bits[] causes out-of-bounds write. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.22.1 will fix this issue. Patch name: a6734e867b19d75367c05f872ac26322464e3995. It is advisable to upgrade the affected component.

First published (updated )
Severity
7.5
Incorrect Type Cast
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A type confusion error within the "unpackedloadraw()" function within LibRaw versions prior to 0.19.1 (internal/dcrawcommon.cpp) can be exploited to trigger an infinite loop.

1 / 2
Source: Launchpad
First published (updated )
Severity
7.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An error within the "parsesinaria()" function (internal/dcrawcommon.cpp) within LibRaw versions prior to 0.19.1 can be exploited to exhaust available CPU resources.

1 / 2
Source: Launchpad
First published (updated )
Severity
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An error within the "parserollei()" function (internal/dcrawcommon.cpp) within LibRaw versions prior to 0.19.1 can be exploited to trigger an infinite loop.

1 / 2
Source: Launchpad
First published (updated )
Severity
6.5
Buffer Overflow
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Last updated 11 July 2025

1 / 2
Source: Ubuntu
First published (updated )
Severity
6.5
Null Pointer Dereference
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Last updated 11 July 2025

1 / 2
Source: Ubuntu
First published (updated )
Severity
6.5
Null Pointer Dereference
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Last updated 11 July 2025

1 / 2
Source: Ubuntu
First published (updated )
Severity
8.8
Buffer Overflow
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Last updated 11 July 2025

1 / 2
Source: Ubuntu
First published (updated )
Severity
8.8
Buffer Overflow
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

An error within the "rolleiloadraw()" function (internal/dcrawcommon.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash.

1 / 2
Source: Launchpad
First published (updated )
Severity
6.5
Null Pointer Dereference
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

An error within the "nikoncoolscanloadraw()" function (internal/dcrawcommon.cpp) in LibRaw versions prior to 0.18.9 can be exploited to trigger a NULL pointer dereference.

1 / 2
Source: Launchpad
First published (updated )
Severity
7.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

An error within the "parseminolta()" function (dcraw/dcraw.c) in LibRaw versions prior to 0.18.11 can be exploited to trigger an infinite loop via a specially crafted file.

1 / 2
Source: Launchpad
First published (updated )
Severity
7.1
Integer Overflow
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

An integer overflow error within the "identify()" function (internal/dcrawcommon.cpp) in LibRaw versions prior to 0.18.12 can be exploited to trigger a division by zero via specially crafted NOKIARAW file (Note: This vulnerability is caused due to an incomplete fix of CVE-2018-5804).

1 / 2
Source: Launchpad
First published (updated )
Severity
8.8
Buffer Overflow
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

An error related to the "LibRaw::panasonicloadraw()" function (dcrawcommon.cpp) in LibRaw versions prior to 0.18.6 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash via a specially crafted TIFF image.

1 / 2
Source: Launchpad
First published (updated )
Severity
6.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

An error within the "LibRaw::xtransinterpolate()" function (internal/dcrawcommon.cpp) in LibRaw versions prior to 0.18.6 can be exploited to cause an invalid read memory access and subsequently a Denial of Service condition.

1 / 2
Source: Launchpad
First published (updated )
Severity
6.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

An error within the "nikoncoolscanloadraw()" function (internal/dcrawcommon.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause an out-of-bounds read memory access and subsequently cause a crash.

1 / 2
Source: Launchpad
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203