CVE-2026-20889
EUVD-2026-1962007.04.2026, 15:17
A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| libraw | libraw | 0.22.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libraw |
| ||||||||||||||
| ufraw |
| ||||||||||||||
| darktable |
| ||||||||||||||
| exactimage |
| ||||||||||||||
| dcraw |
| ||||||||||||||
| rawtherapee |
| ||||||||||||||
| kodi |
| ||||||||||||||
| digikam |
|
Red Hat Enterprise Linux Releases