CVE-2026-20884
EUVD-2026-1961807.04.2026, 15:17
An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| libraw | libraw | 0.22.1 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libraw |
| ||||||||||||||
| ufraw |
| ||||||||||||||
| darktable |
| ||||||||||||||
| exactimage |
| ||||||||||||||
| dcraw |
| ||||||||||||||
| rawtherapee |
| ||||||||||||||
| kodi |
| ||||||||||||||
| digikam |
|