Bug 2540837 (CVE-2026-88387) - CVE-2026-88387 LibRaw: LibRaw: Denial of Service via improper numeric conversion
Summary: CVE-2026-88387 LibRaw: LibRaw: Denial of Service via improper numeric conversion
Keywords:
Status: NEW
Alias: CVE-2026-88387
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2540965 2540966
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-24 20:52 UTC by OSIDB Bzimport
Modified: 2026-09-25 07:02 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-24 20:52:34 UTC
LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF tag 0x00fe (NewSubfileType). A specially crafted RAW, TIFF, or DNG file can supply an attacker-controlled NewSubfileType value outside the range of a signed int. The parser converts this value and narrows it to int without performing range validation. This out-of-range conversion triggers undefined behavior, resulting in process termination and denial of service.


Note You need to log in before you can comment on or make changes to this bug.