Executive brief
Adobe's DNG SDK is a library used to process and manipulate digital image files in the DNG (Digital Negative) format. A flaw in how the library handles image dimensions could cause it to crash when processing a specially crafted image file, disrupting workflows for photographers and image editing applications that depend on the library.
Technical details
The vulnerability is an integer overflow or wraparound condition in the DNG SDK image processing logic. The flaw occurs when processing image files with malicious or unexpected dimension values, causing integer arithmetic to wrap and result in invalid memory operations or buffer overflows. Exploitation requires user interaction—an attacker must trick a user into opening a malicious DNG file through email, file sharing, or other delivery mechanisms. A successful exploit leads to denial of service (application crash or unresponsiveness). The vulnerability affects DNG SDK versions 1.7.1 build 2471 and earlier.
Affected products
- Adobe DNG SDK 1.7.1 build 2471 and earlier
Timeline
- 2026-03-10: disclosed: Public disclosure via NVD