PT-2026-30829 · Libraw · Libraw
Francesco Benvenuto
·
Published
2026-04-07
·
Updated
2026-04-22
·
CVE-2026-20884
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LibRaw versions prior to Commit 8dc68e2
Description
An integer overflow exists in the
deflate dng load raw functionality of LibRaw. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this issue.Recommendations
Update LibRaw to version Commit 8dc68e2 or later.
Exploit
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libraw