PT-2026-30833 · Libraw+2 · Libraw+2

·

CVE-2026-24450

·

Published

2026-04-07

·

Updated

2026-07-16

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LibRaw versions prior to Commit 8dc68e2
Description An integer overflow exists in the uncompressed fp dng load raw functionality of LibRaw. A specially crafted malicious file can trigger a heap buffer overflow. An attacker can provide a malicious file to exploit this issue.
Recommendations Update LibRaw to Commit 8dc68e2 or later.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:11360
ALSA-2026:19345
CVE-2026-24450
ECHO-8D16-7D9A-2E99
OPENSUSE-SU-2026:10565-1
OPENSUSE-SU-2026:20574-1
RHSA-2026:11360
RHSA-2026:13854
RHSA-2026:13870
SUSE-SU-2026:1555-1
SUSE-SU-2026:21360-1
USN-8522-1

Affected Products

Libraw
Linuxmint
Rocky Linux