PT-2025-17419 · Libraw+5 · Libraw+5

Lexa

·

Published

2025-04-13

·

Updated

2025-12-04

·

CVE-2025-43962

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions LibRaw versions prior to 0.21.4
Description The issue is related to out-of-bounds reads in the phase one correct function within decoders/load mfbacks.cpp for tag 0x412 processing. This is caused by large w0 or w1 values or the frac and mult calculations.
Recommendations For versions prior to 0.21.4, update to version 0.21.4 or later to resolve the issue. As a temporary workaround, consider restricting the input values for w0 and w1 to prevent large values that could cause out-of-bounds reads.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

AZL-61780
BDU:2025-10597
CVE-2025-43962
DLA-4142-1
MGASA-2025-0316
OESA-2025-1478
OPENSUSE-SU-2025:15025-1
OPENSUSE-SU-2025_1568-1
OPENSUSE-SU-2025_1572-1
SUSE-SU-2025:01569-1
SUSE-SU-2025:01572-1
SUSE-SU-2025:1380-1
SUSE-SU-2025:1568-1
SUSE-SU-2025:1569-1
SUSE-SU-2025:1572-1
USN-7485-1

Affected Products

Alt Linux
Debian
Libraw
Linuxmint
Suse
Ubuntu