In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser.
CVSS Details
- CVSS 3.1 Base Score: 2.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade LibRaw-debuginfoUpgrade LibRaw-develUpgrade LibRaw-staticUpgrade LibRaw | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade libraw | May 1, 2025 | Apr 21, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 21, 2025 |
| Suse | — | Upgrade libraw23Upgrade libraw-toolsUpgrade libraw-devel-staticUpgrade libraw-develUpgrade libraw16Upgrade libraw23-32bit | Dec 5, 2025 | Jun 6, 2025 |
| Ubuntu | — | Upgrade libraw20Upgrade libraw-binUpgrade libraw15 (Ubuntu Pro)Upgrade libraw19Upgrade libraw16 (Ubuntu Pro)Upgrade libraw23t64Upgrade libraw-bin (Ubuntu Pro) | May 7, 2025 | Apr 21, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub