PT-2026-30829 · Libraw+1 · Libraw+1

·

CVE-2026-20884

·

Published

2026-04-07

·

Updated

2026-07-09

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LibRaw versions prior to Commit 8dc68e2
Description An integer overflow exists in the deflate dng load raw functionality of LibRaw. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this issue.
Recommendations Update LibRaw to version Commit 8dc68e2 or later.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-20884
ECHO-E74F-830C-CD04
OPENSUSE-SU-2026:10565-1
OPENSUSE-SU-2026:20574-1
SUSE-SU-2026:1555-1
SUSE-SU-2026:1556-1
SUSE-SU-2026:21360-1
USN-8522-1

Affected Products

Libraw
Linuxmint