Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5318

Опубликовано: 02 апр. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A weakness has been identified in LibRaw up to 0.22.0. This impacts the function HuffTable::initval of the file src/decompressors/losslessjpeg.cpp of the component JPEG DHT Parser. This manipulation of the argument bits[] causes out-of-bounds write. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.22.1 will fix this issue. Patch name: a6734e867b19d75367c05f872ac26322464e3995. It is advisable to upgrade the affected component.

A flaw was found in LibRaw. A remote attacker could exploit this vulnerability by manipulating the 'bits[]' argument within the 'HuffTable::initval' function of the JPEG DHT Parser component. This manipulation leads to an out-of-bounds write, which can result in a Denial of Service (DoS) condition, making the affected system or application unavailable. An exploit for this vulnerability has been made public.

Отчет

This Moderate impact flaw in LibRaw's JPEG DHT Parser could lead to a Denial of Service. A remote attacker could trigger an out-of-bounds write by providing a specially crafted JPEG image to an application utilizing LibRaw. This vulnerability affects Red Hat Enterprise Linux versions that include LibRaw.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libraw1394Out of support scope
Red Hat Enterprise Linux 7LibRawFix deferred
Red Hat Enterprise Linux 7libraw1394Fix deferred
Red Hat Enterprise Linux 8LibRawFix deferred
Red Hat Enterprise Linux 8libraw1394Fix deferred
Red Hat Enterprise Linux 9LibRawFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2454185LibRaw: LibRaw: Denial of Service via out-of-bounds write in JPEG DHT Parser

EPSS

Процентиль: 3%
0.00014
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
5 дней назад

A weakness has been identified in LibRaw up to 0.22.0. This impacts the function HuffTable::initval of the file src/decompressors/losslessjpeg.cpp of the component JPEG DHT Parser. This manipulation of the argument bits[] causes out-of-bounds write. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.22.1 will fix this issue. Patch name: a6734e867b19d75367c05f872ac26322464e3995. It is advisable to upgrade the affected component.

CVSS3: 4.3
nvd
6 дней назад

A weakness has been identified in LibRaw up to 0.22.0. This impacts the function HuffTable::initval of the file src/decompressors/losslessjpeg.cpp of the component JPEG DHT Parser. This manipulation of the argument bits[] causes out-of-bounds write. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.22.1 will fix this issue. Patch name: a6734e867b19d75367c05f872ac26322464e3995. It is advisable to upgrade the affected component.

CVSS3: 4.3
debian
6 дней назад

A weakness has been identified in LibRaw up to 0.22.0. This impacts th ...

CVSS3: 4.3
github
6 дней назад

A weakness has been identified in LibRaw up to 0.22.0. This impacts the function HuffTable::initval of the file src/decompressors/losslessjpeg.cpp of the component JPEG DHT Parser. This manipulation of the argument bits[] causes out-of-bounds write. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.22.1 will fix this issue. Patch name: a6734e867b19d75367c05f872ac26322464e3995. It is advisable to upgrade the affected component.

EPSS

Процентиль: 3%
0.00014
Низкий

6.5 Medium

CVSS3