PT-2026-29677 · Libraw · Libraw

Biniam

·

Published

2026-04-02

·

Updated

2026-04-03

·

CVE-2026-5318

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions LibRaw versions up to 0.22.0
Description A weakness exists in LibRaw, specifically in the HuffTable::initval function within the src/decompressors/losslessjpeg.cpp file of the JPEG DHT Parser component. This allows for an out-of-bounds write due to manipulation of the bits[] argument. The attack can be initiated remotely and an exploit is publicly available.
Recommendations Upgrade to version 0.22.1 or later to address this issue.

Exploit

Fix

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-5318
ECHO-DDB8-C818-EDCA

Affected Products

Libraw