CVE-2026-20884

Name
CVE-2026-20884
Description
An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
talos-cna@cisco.com https://talosintelligence.com/vulnerability_reports/TALOS-2026-2364
af854a3a-2127-422b-91ae-364da2661108 https://www.talosintelligence.com/vulnerability_reports/TALOS-2026-2364

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:libraw:libraw:0.22.1:*:*:*:*:*:*:* libraw == None == 0.22.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libraw edge-community 0.22.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable