yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2025-43964
Component Overview
Vulnerability Overview
Name
CVE-2025-43964
Source
NVD (
link
)
Debian (
link
)
Description
In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.
CWEs
CWE-1284
CWE-1284
Published Date
Apr 21, 2025
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/LibRaw/LibRaw/commit/a50dc3f1127d2e37a9b39f57ad9bb2ebb60f18c0
Patch
https://github.com/LibRaw/LibRaw/compare/0.21.3...0.21.4
Patch
https://www.libraw.org/news/libraw-0-21-4-release
Release Notes
Analysis
#
Affected Component
Analysis
libraw
Patched
Vulnerability Ratings
#
2.9
CVSSv31
9.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
libraw
buildroot
2025.02.x
0.21.4
Not Affected
libraw
buildroot
master
0.21.4
Not Affected
libraw
yocto
master
0.22.1
Not Affected
libraw
yocto
scarthgap
0.21.2
Patched
Resolved with patches
#
libraw (yocto:kirkstone)
#
Title
Author
Resolve
1
additional checks in PhaseOne correction tag 0x412 processing
Alex Tutubalin <lexa@lexa.ru>
CVE-2025-43964
libraw (yocto:scarthgap)
#
Title
Author
Resolve
1
CVE-2025-43964
Alex Tutubalin <lexa@lexa.ru>
CVE-2025-43964