Executive brief
LibRaw, a widely used library for processing RAW digital camera images, contains a security vulnerability that can be triggered by a specially crafted image file. If a user opens a malicious Fuji RAW (.RAF) file using an application that relies on this library, the application could crash or allow an attacker to gain unauthorized control over the system. This affects software used for photo editing, viewing, and digital asset management.
Technical details
LibRaw 0.21 contains two heap-based buffer overflow vulnerabilities (CWE-122). The first occurs in the stretch() function (src/libraw_cxx.cpp) due to variable confusion between image dimensions and channel counts, leading to out-of-bounds writes. The second occurs in fuji_rotate() (src/decoders/fuji.cpp) where an unsigned short integer overflow during width and pixel aspect ratio multiplication results in an undersized buffer allocation. An attacker can trigger these by providing a maliciously crafted Fuji RAF image with manipulated header metadata. Exploitation requires a user to process the file with an application linked against the vulnerable library, potentially leading to arbitrary code execution or a process crash.
Affected products
- LibRaw LibRaw 0.21
Timeline
- 2026-07-27: disclosed: Initial disclosure via NVD and researcher advisory