Executive brief
Adobe's DNG SDK is a library used to process digital image files in DNG format. Versions 1.7.1 2502 and earlier contain a memory corruption vulnerability that can be triggered when opening a specially crafted malicious image file. An attacker can exploit this to crash applications that use the SDK, causing service disruption or data loss for users attempting to process images.
Technical details
The vulnerability is an out-of-bounds write flaw in the DNG SDK's image parsing logic. The root cause is insufficient bounds checking when processing DNG image data. Exploitation requires user interaction—a victim must open or process a malicious DNG file—but no authentication or special privileges are required. A successful exploit corrupts application memory, leading to denial-of-service through application crash or unresponsiveness. Patches are expected from Adobe; affected versions are 1.7.1 2502 and earlier.
Affected products
- Adobe DNG SDK 1.7.1 2502 and earlier
Timeline
- 2026-08-27: disclosed
- 2026-08-27: advisory