Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.1
CVE-2026-24660: LibRaw: Malicious File Can Cause Crash or Data Corruption
CVE-2026-24660 · published 5 months ago
Summary
LibRaw has a security flaw that could allow an attacker to send a specially crafted file, potentially causing the program to crash or corrupt data. This issue affects users who use LibRaw to handle files from certain cameras. To protect your system, update to the latest version of LibRaw.
What to do
- Update debian rootio-libraw to version 0.21.4-2.root.io.1.
- Update debian libraw to version 0.22.1-1.
- Update debian libraw to version 0.21.4-2.root.io.3.
- Update debian rootio-libraw to version 0.21.4-2.root.io.3.
- Update debian libraw to version 0.20.2-2.1+deb12u2.
- Update debian libraw to version 0.21.4-2+deb13u1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:11 | debian | libraw | All versions |
| Debian:12 | debian | libraw |
< 0.20.2-2.1+deb12u2 Fix: upgrade to 0.20.2-2.1+deb12u2
|
| Debian:13 | debian | libraw |
< 0.21.4-2+deb13u1 Fix: upgrade to 0.21.4-2+deb13u1
|
| Debian:14 | debian | libraw |
< 0.22.1-1 Fix: upgrade to 0.22.1-1
|
| Root:Debian:13 | debian | rootio-libraw |
< 0.21.4-2.root.io.1 < 0.21.4-2.root.io.3 Fix: upgrade to 0.21.4-2.root.io.1
|
| – | libraw | libraw |
0.22.0 Commit d20315b cpe:2.3:a:libraw:libraw:0.22.0:*:*:*:*:*:*:* |
| Ubuntu:24.04:LTS | canonical | dcraw | All versions |
| Ubuntu:24.04:LTS | canonical | digikam | All versions |
| Ubuntu:24.04:LTS | canonical | exactimage | All versions |
| Ubuntu:24.04:LTS | canonical | kodi | All versions |
| Ubuntu:24.04:LTS | canonical | libraw | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | libraw | All versions |
| Ubuntu:16.04:LTS | canonical | darktable | All versions |
| Ubuntu:16.04:LTS | canonical | dcraw | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | digikam | All versions |
| Ubuntu:16.04:LTS | canonical | exactimage | All versions |
| Ubuntu:16.04:LTS | canonical | kodi | All versions |
| Ubuntu:16.04:LTS | canonical | rawtherapee | All versions |
| Ubuntu:16.04:LTS | canonical | ufraw | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | libraw | All versions |
| Ubuntu:18.04:LTS | canonical | darktable | All versions |
| Ubuntu:18.04:LTS | canonical | dcraw | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | digikam | All versions |
| Ubuntu:18.04:LTS | canonical | exactimage | All versions |
| Ubuntu:18.04:LTS | canonical | kodi | All versions |
| Ubuntu:18.04:LTS | canonical | rawtherapee | All versions |
| Ubuntu:18.04:LTS | canonical | ufraw | All versions |
| Ubuntu:20.04:LTS | canonical | libraw | All versions |
| Ubuntu:20.04:LTS | canonical | darktable | All versions |
| Ubuntu:20.04:LTS | canonical | dcraw | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | digikam | All versions |
| Ubuntu:20.04:LTS | canonical | exactimage | All versions |
| Ubuntu:20.04:LTS | canonical | kodi | All versions |
| Ubuntu:20.04:LTS | canonical | rawtherapee | All versions |
| Ubuntu:22.04:LTS | canonical | darktable | All versions |
| Ubuntu:22.04:LTS | canonical | dcraw | All versions |
| Ubuntu:22.04:LTS | canonical | exactimage | All versions |
| Ubuntu:22.04:LTS | canonical | kodi | All versions |
| Ubuntu:22.04:LTS | canonical | libraw | All versions |
| Ubuntu:22.04:LTS | canonical | rawtherapee | All versions |
| Ubuntu:Pro:22.04:LTS | canonical | digikam | All versions |
| Ubuntu:24.04:LTS | canonical | darktable | All versions |
| Ubuntu:24.04:LTS | canonical | rawtherapee | All versions |
| Ubuntu:25.10 | canonical | darktable | All versions |
| Ubuntu:25.10 | canonical | dcraw | All versions |
| Ubuntu:25.10 | canonical | digikam | All versions |
| Ubuntu:25.10 | canonical | exactimage | All versions |
| Ubuntu:25.10 | canonical | kodi | All versions |
| Ubuntu:25.10 | canonical | libraw | All versions |
| Ubuntu:25.10 | canonical | rawtherapee | All versions |
Showing 50 of 58. Show the rest
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Ubuntu:26.04:LTS | canonical | darktable | All versions |
| Ubuntu:26.04:LTS | canonical | dcraw | All versions |
| Ubuntu:26.04:LTS | canonical | digikam | All versions |
| Ubuntu:26.04:LTS | canonical | exactimage | All versions |
| Ubuntu:26.04:LTS | canonical | kodi | All versions |
| Ubuntu:26.04:LTS | canonical | libraw | All versions |
| Ubuntu:26.04:LTS | canonical | rawtherapee | All versions |
| Root:Debian:13 | debian | libraw |
< 0.21.4-2.root.io.3 Fix: upgrade to 0.21.4-2.root.io.3
|
Original advisory text
A heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker ...
A heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2026-2359
- https://security-tracker.debian.org/tracker/CVE-2026-24660 Vendor Advisory
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2026-2359 Exploit Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-24660 Third Party Advisory
- https://ubuntu.com/security/CVE-2026-24660 Third Party Advisory
Severity
8.1
High
CVSS 3.1: 8.1 (NVD)
CVSS 3.1: 8.1 (OSV)
Exploitation
EPSS <1%
Type
CWE-190Integer Overflow
Timeline
Published7 Apr 2026
Updated25 Sep 2026
First seen7 Apr 2026
Sources
DEBIAN-CVE-2026-24660 · OSV
UBUNTU-CVE-2026-24660 · OSV
CVE-2026-24660 · NVD
CVE-2026-24660 · MITRE
Track software like this
Free during beta