Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-51235

Опубликовано: 27 июл. 2026
Источник: redhat
CVSS3: 7.3

Описание

A flaw was found in LibRaw, an open-source library for processing raw image files. This vulnerability is a buffer overflow, which occurs in the stretch() and fuji_rotate() functions. A buffer overflow can allow an attacker to overwrite memory, potentially leading to a denial of service or the execution of unauthorized code.

Отчет

This Important flaw in LibRaw, a library for processing raw image files, is a buffer overflow in the stretch() and fuji_rotate() functions. Successful exploitation requires a local attacker to trick a user into processing a specially crafted raw image file, which could lead to arbitrary code execution or a denial of service. Red Hat Enterprise Linux 9 is affected, while Red Hat Enterprise Linux 8 and older versions are not vulnerable as they ship with older, unaffected versions of LibRaw or do not contain the vulnerable code.

Меры по смягчению последствий

Mitigation for this issue involves avoiding the processing of untrusted raw image files. As this vulnerability resides within a library, there are no direct configuration or operational controls to disable the vulnerable functions without impacting applications that rely on LibRaw for image processing.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libraw1394Not affected
Red Hat Enterprise Linux 7LibRawNot affected
Red Hat Enterprise Linux 7libraw1394Not affected
Red Hat Enterprise Linux 8LibRawNot affected
Red Hat Enterprise Linux 8libraw1394Not affected
Red Hat Enterprise Linux 9LibRawAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2507594LibRaw: LibRaw: Buffer Overflow vulnerability in image processing

7.3 High

CVSS3

Связанные уязвимости

ubuntu
10 дней назад

LibRaw 0.21 is vulnerable to Buffer Overflow in the stretch() function (src/libraw_cxx.cpp) and fuji_rotate() function (src/decoders/fuji.cpp).

nvd
10 дней назад

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

CVSS3: 8.8
github
10 дней назад

LibRaw 0.21 is vulnerable to Buffer Overflow in the stretch() function (src/libraw_cxx.cpp) and fuji_rotate() function (src/decoders/fuji.cpp).

7.3 High

CVSS3

Уязвимость CVE-2026-51235