yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2025-43963
Component Overview
Vulnerability Overview
Name
CVE-2025-43963
Source
NVD (
link
)
Debian (
link
)
Description
In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col and split_row values are not checked in 0x041f tag processing.
CWEs
CWE-125
CWE-125
Published Date
Apr 21, 2025
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/LibRaw/LibRaw/commit/be26e7639ecf8beb55f124ce780e99842de2e964
Patch
https://github.com/LibRaw/LibRaw/compare/0.21.3...0.21.4
Patch
https://www.libraw.org/news/libraw-0-21-4-release
Release Notes
Analysis
#
Affected Component
Analysis
libraw
Patched
Vulnerability Ratings
#
2.9
CVSSv31
9.1
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
libraw
buildroot
2025.02.x
0.21.4
Not Affected
libraw
buildroot
master
0.21.4
Not Affected
libraw
yocto
master
0.22.1
Not Affected
libraw
yocto
scarthgap
0.21.2
Patched
Resolved with patches
#
libraw (yocto:kirkstone)
#
Title
Author
Resolve
1
check split_col/split_row values in phase_one_correct
Alex Tutubalin <lexa@lexa.ru>
CVE-2025-43963
libraw (yocto:scarthgap)
#
Title
Author
Resolve
1
CVE-2025-43963
Alex Tutubalin <lexa@lexa.ru>
CVE-2025-43963