yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2023-1729
Component Overview
Vulnerability Overview
Name
CVE-2023-1729
Source
NVD (
link
)
Debian (
link
)
Description
A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.
CWEs
CWE-119
CWE-787
Published Date
May 15, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://bugzilla.redhat.com/show_bug.cgi?id=2188240
Issue Tracking
https://github.com/LibRaw/LibRaw/issues/557
Exploit
https://lists.debian.org/debian-lts-announce/2023/05/msg00025.html
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AGZ6XF5WTPJ4GLXQ62JVRDZSVSJHXNQU/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E5ZJ3UBTJBZHNPJQFOSGM5L7WAHHE2GY/
Mailing List
https://security.gentoo.org/glsa/202312-08
Third Party Advisory
https://www.debian.org/security/2023/dsa-5412
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2188240
Issue Tracking
https://github.com/LibRaw/LibRaw/issues/557
Exploit
https://lists.debian.org/debian-lts-announce/2023/05/msg00025.html
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AGZ6XF5WTPJ4GLXQ62JVRDZSVSJHXNQU/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E5ZJ3UBTJBZHNPJQFOSGM5L7WAHHE2GY/
Mailing List
https://security.gentoo.org/glsa/202312-08
Third Party Advisory
https://www.debian.org/security/2023/dsa-5412
Third Party Advisory
Analysis
#
Affected Component
Analysis
libraw
Patched
Vulnerability Rating
#
6.5
CVSSv31
Others affected components
#
Name
Project
Project Version
Version
Status
libraw
buildroot
2025.02.x
0.21.4
Not Affected
libraw
buildroot
master
0.21.4
Not Affected
libraw
yocto
master
0.22.1
Not Affected
libraw
yocto
scarthgap
0.21.2
Not Affected
Resolved with patches
#
libraw (yocto:kirkstone)
#
Title
Author
Resolve
1
do not set shrink flag for 3/4 component images
Alex Tutubalin <lexa@lexa.ru>
CVE-2023-1729