PT-2026-29749 · Libraw+2 · Libraw+2

·

CVE-2026-5342

·

Published

2026-04-02

·

Updated

2026-07-09

CVSS v4.0

5.5

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions LibRaw versions up to 0.22.0
Description A flaw exists in LibRaw up to version 0.22.0 within the LibRaw::nikon load padded packed raw function located in the src/decoders/decoders libraw.cpp file, related to the TIFF/NEF component. Manipulation of the load flags/raw width arguments can result in an out-of-bounds read. Remote exploitation is possible.
Recommendations Upgrade to version 0.22.1 or later.

Exploit

Fix

DoS

Buffer Overflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09780
CVE-2026-5342
ECHO-B728-5F8B-4AD6
OPENSUSE-SU-2026:10565-1
OPENSUSE-SU-2026:20574-1
SUSE-SU-2026:1555-1
SUSE-SU-2026:1556-1
SUSE-SU-2026:21360-1
USN-8522-1

Affected Products

Libraw
Linuxmint
Red Os