Logo
vulnerabilityCVE-2025-43964
Name
CVE-2025-43964
Source
NVD ( link)Debian ( link)
Description
In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libraw
Patched

Vulnerability Ratings#


2.9
CVSSv31
9.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
0.21.4
Not Affected
buildroot
master
0.21.4
Not Affected
yocto
master
0.22.1
Not Affected
yocto
scarthgap
0.21.2
Patched

Resolved with patches#


libraw (yocto:kirkstone)

#
Title
Author
Resolve
1
additional checks in PhaseOne correction tag 0x412 processing
Alex Tutubalin <lexa@lexa.ru>
CVE-2025-43964

libraw (yocto:scarthgap)

#
Title
Author
Resolve
1
CVE-2025-43964
Alex Tutubalin <lexa@lexa.ru>
CVE-2025-43964