PT-2026-32765 · Adobe · Dng Sdk

Jann Horn

·

Published

2026-04-14

·

Updated

2026-04-15

·

CVE-2026-27258

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions DNG SDK versions 1.7.1 2502 and earlier
Description An out-of-bounds write issue exists where an attacker can corrupt memory, potentially leading to an application denial-of-service, causing the application to crash or become unresponsive. Exploitation requires user interaction, specifically requiring a victim to open a malicious file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2026-05462
CVE-2026-27258

Affected Products

Dng Sdk