Logo
vulnerabilityCVE-2026-5318
Name
CVE-2026-5318
Source
NVD ( link)Debian ( link)
Description
A weakness has been identified in LibRaw up to 0.22.0. This impacts the function HuffTable::initval of the file src/decompressors/losslessjpeg.cpp of the component JPEG DHT Parser. This manipulation of the argument bits[] causes out-of-bounds write. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.22.1 will fix this issue. Patch name: a6734e867b19d75367c05f872ac26322464e3995. It is advisable to upgrade the affected component.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libraw
Not Affected

Vulnerability Ratings#


2.1
CVSSv4
4.3
CVSSv31
4.3
CVSSv31
5
CVSSv2
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
0.21.4
Exploitable
buildroot
master
0.21.4
Exploitable
yocto
kirkstone
0.20.2
Exploitable
yocto
scarthgap
0.21.2
False Positive