PT-2025-17419 · Libraw+5 · Libraw+5
Lexa
·
Published
2025-04-13
·
Updated
2025-12-04
·
CVE-2025-43962
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
LibRaw versions prior to 0.21.4
Description
The issue is related to out-of-bounds reads in the
phase one correct function within decoders/load mfbacks.cpp for tag 0x412 processing. This is caused by large w0 or w1 values or the frac and mult calculations.Recommendations
For versions prior to 0.21.4, update to version 0.21.4 or later to resolve the issue.
As a temporary workaround, consider restricting the input values for
w0 and w1 to prevent large values that could cause out-of-bounds reads.Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Libraw
Linuxmint
Suse
Ubuntu