An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 09 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Heap Buffer Overflow via Malicious DNG File in LibRaw | LibRaw: LibRaw: Arbitrary code execution via integer overflow in deflate_dng_load_raw |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Heap Buffer Overflow via Malicious DNG File in LibRaw | |
| First Time appeared |
Libraw
Libraw libraw |
|
| Vendors & Products |
Libraw
Libraw libraw |
Tue, 07 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability. | |
| Weaknesses | CWE-190 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2026-04-08T03:55:45.636Z
Reserved: 2026-01-29T14:17:38.877Z
Link: CVE-2026-20884
No data.
Status : Awaiting Analysis
Published: 2026-04-07T15:17:35.127
Modified: 2026-04-08T21:27:15.610
Link: CVE-2026-20884
OpenCVE Enrichment
Updated: 2026-04-08T19:49:27Z
Weaknesses