yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2025-43962
Component Overview
Vulnerability Overview
Name
CVE-2025-43962
Source
NVD (
link
)
Debian (
link
)
Description
In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing, related to large w0 or w1 values or the frac and mult calculations.
CWEs
CWE-125
CWE-125
Published Date
Apr 21, 2025
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/LibRaw/LibRaw/commit/66fe663e02a4dd610b4e832f5d9af326709336c2
Patch
https://github.com/LibRaw/LibRaw/compare/0.21.3...0.21.4
Patch
https://www.libraw.org/news/libraw-0-21-4-release
Release Notes
Analysis
#
Affected Component
Analysis
libraw
Patched
Vulnerability Ratings
#
2.9
CVSSv31
9.1
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
libraw
buildroot
2025.02.x
0.21.4
Not Affected
libraw
buildroot
master
0.21.4
Not Affected
libraw
yocto
kirkstone
0.20.2
Patched
libraw
yocto
master
0.22.1
Not Affected
Resolved with patches
#
libraw (yocto:kirkstone)
#
Title
Author
Resolve
1
Prevent out-of-bounds read in fuji 0xf00c tag parser
Alex Tutubalin <lexa@lexa.ru>
CVE-2025-43961
CVE-2025-43962
libraw (yocto:scarthgap)
#
Title
Author
Resolve
1
CVE-2025-43961 CVE-2025-43962
Alex Tutubalin <lexa@lexa.ru>
CVE-2025-43961
CVE-2025-43962