PT-2026-29749 · Libraw · Libraw
Biniam
·
Published
2026-04-02
·
Updated
2026-04-22
·
CVE-2026-5342
CVSS v4.0
5.5
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
LibRaw versions up to 0.22.0
Description
A flaw exists in LibRaw up to version 0.22.0 within the
LibRaw::nikon load padded packed raw function located in the src/decoders/decoders libraw.cpp file, related to the TIFF/NEF component. Manipulation of the load flags/raw width arguments can result in an out-of-bounds read. Remote exploitation is possible.Recommendations
Upgrade to version 0.22.1 or later.
Exploit
Fix
Out of bounds Read
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libraw