In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processing cr3 files. Upstream issue: https://github.com/LibRaw/LibRaw/issues/279 Upstream fix: https://github.com/LibRaw/LibRaw/commit/e41f331e90b383e3208cefb74e006df44bf3a4b8
What's the severity of this CVE? Low? For what it's worth, this CVE neither affects the LibRaw package in Fedora (F >= 35 has 0.20.2) nor in RHEL 9 (has 0.20.2). I didn't check packages that carry other copies of the same code (eg., dcraw).