Bug 2454372 (CVE-2026-5342) - CVE-2026-5342 LibRaw: LibRaw: Out-of-bounds read via `load_flags/raw_width` argument manipulation
Summary: CVE-2026-5342 LibRaw: LibRaw: Out-of-bounds read via `load_flags/raw_width` a...
Keywords:
Status: NEW
Alias: CVE-2026-5342
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2454457 2454458 2454459 2454460 2454461 2454462 2454463 2454464 2454465
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-04-02 15:01 UTC by OSIDB Bzimport
Modified: 2026-04-02 17:32 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-04-02 15:01:19 UTC
A flaw has been found in LibRaw up to 0.22.0. This affects the function LibRaw::nikon_load_padded_packed_raw of the file src/decoders/decoders_libraw.cpp of the component TIFF/NEF. Executing a manipulation of the argument load_flags/raw_width can lead to out-of-bounds read. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 0.22.1 mitigates this issue. This patch is called b8397cd45657b84e88bd1202528d1764265f185c. It is advisable to upgrade the affected component.


Note You need to log in before you can comment on or make changes to this bug.