Executive brief
Adobe DNG SDK, a software development kit used by developers to handle Digital Negative (DNG) image files, is affected by a flaw that can cause applications to crash. An attacker could exploit this by tricking a user into opening a specially crafted malicious image file. This would result in a denial-of-service, potentially disrupting business operations or workflows that rely on processing these image types.
Technical details
A NULL Pointer Dereference vulnerability (CWE-476) exists in Adobe DNG SDK versions 1.7.1 2536 and earlier. The flaw is triggered when the library attempts to dereference a pointer that is expected to be valid but is instead NULL, typically during the parsing of malformed DNG files. An attacker can exploit this by providing a specially crafted file to a victim; once opened by an application using the SDK, the process will crash. This is a local attack requiring user interaction. Adobe has addressed this in security bulletin APSB26-67.
Affected products
- Adobe DNG SDK 1.7.1 2536 and earlier
Timeline
- 2026-07-06: disclosed
- 2026-07-06: advisory