There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be executed in the victim's system.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-dcrawamazon-linux-ami-2-upgrade-dcraw-debuginfoamazon-linux-ami-2-upgrade-librawamazon-linux-ami-2-upgrade-libraw-debuginfoamazon-linux-ami-2-upgrade-libraw-develamazon-linux-ami-2-upgrade-libraw-static | May 20, 2026 | May 20, 2026 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Apr 18, 2022 | |
| Debian | debian-upgrade-dcraw | Jul 30, 2024 | Apr 18, 2022 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Apr 18, 2022 | |
| Suse | — | suse-upgrade-dcrawsuse-upgrade-dcraw-lang | Oct 26, 2022 | Apr 18, 2022 |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Apr 18, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub