There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be executed in the victim's system.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade LibRaw-debuginfoUpgrade dcrawUpgrade LibRaw-staticUpgrade LibRawUpgrade LibRaw-develUpgrade dcraw-debuginfo | May 20, 2026 | May 20, 2026 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Apr 18, 2022 |
| Debian | — | Upgrade dcraw | Jul 30, 2024 | Apr 18, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 18, 2022 |
| Suse | — | Upgrade dcrawUpgrade dcraw-lang | Oct 26, 2022 | Apr 18, 2022 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Apr 18, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub