CVE-2026-21413
EUVD-2026-1962407.04.2026, 15:17
A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| libraw | libraw | 0.22.0 |
| libraw | libraw | 0.22.1 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libraw |
| ||||||||||||||
| ufraw |
| ||||||||||||||
| darktable |
| ||||||||||||||
| exactimage |
| ||||||||||||||
| dcraw |
| ||||||||||||||
| rawtherapee |
| ||||||||||||||
| kodi |
| ||||||||||||||
| digikam |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| libraw-devel |
| ||||||||
| libraw16 |
|
Red Hat Enterprise Linux Releases