Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-24450

Опубликовано: 07 апр. 2026
Источник: debian
EPSS Низкий

Описание

An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
librawfixed0.22.1-1package
librawfixed0.21.4-2+deb13u1trixiepackage
librawnot-affectedbookwormpackage
librawnot-affectedbullseyepackage

Примечания

  • https://talosintelligence.com/vulnerability_reports/TALOS-2026-2363

  • https://github.com/LibRaw/LibRaw/commit/a58727c1a3cfef4101700e546a6a661c6a299d97

  • https://github.com/LibRaw/LibRaw/commit/c911c9b9edffa5fab99f828d0fee6dd2d0f6105f (0.22.1)

EPSS

Процентиль: 45%
0.00568
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
5 месяцев назад

An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 7.5
redhat
5 месяцев назад

An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 8.1
nvd
5 месяцев назад

An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 8.1
github
5 месяцев назад

An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

rocky
4 месяца назад

Important: LibRaw security update

EPSS

Процентиль: 45%
0.00568
Низкий