Junglewise Threat Intelligence

CVE-2026-21354: Adobe DNG SDK integer overflow in file parsing

CVE-2026-21354 · Severity: medium · CVSS 5.5 · Published 2026-02-10

Technologies: Adobe Dng Software Development Kit, Adobe DNG SDK. Vendors: Adobe.

Executive brief

Adobe DNG SDK is a library used by developers to read and process Digital Negative (DNG) image files. An integer overflow vulnerability allows an attacker to craft a malicious DNG file that, when opened by an application using the SDK, causes the application to crash or become unresponsive. This impacts any software built on top of the DNG SDK, potentially disrupting user workflows and creating denial-of-service conditions.

Technical details

The vulnerability is an integer overflow or wraparound in DNG SDK version 1.7.1 2410 and earlier, occurring during file parsing. The root cause involves improper bounds checking when processing numeric fields in DNG image files. The attack requires user interaction—a victim must open a specially crafted malicious DNG file in an affected application. Successful exploitation leads to application denial-of-service (crash or hang), but does not enable code execution or data access. Adobe has released patches to address this issue in newer SDK versions.

Affected products

  • Adobe DNG SDK 1.7.1 2410 and earlier

Timeline

  • 2026-02-10: disclosed

References

Related threats