Bug 2361283 (CVE-2025-43961)

Summary: CVE-2025-43961 LibRaw: Out-of-Bounds Read in Fujifilm 0xf00c Tag Parser in LibRaw
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in LibRaw. In affected versions of LibRaw, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2361394, 2361395, 2361396, 2361397, 2361398, 2361399, 2361400, 2361401, 2361402, 2361403, 2361404, 2361405, 2361406, 2361407, 2361408, 2361409, 2361410, 2361411    
Bug Blocks:    

Description OSIDB Bzimport 2025-04-21 00:01:09 UTC
In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser.