Description
A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Published: 2026-04-07
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

A heap‑based buffer overflow exists within LibRaw’s HuffTable::initval routine, allowing a specially crafted image file to corrupt memory and potentially execute arbitrary code. The vulnerability is tied to two specific commits and can be triggered by providing a malicious file to LibRaw. Successful exploitation would compromise the integrity and confidentiality of any application or system that imports the file, and could lead to full system takeover if the process runs with elevated privileges.

Affected Systems

The flaw affects the LibRaw image processing library, specifically versions 0.22.0 and 0.22.1. Any system or application using these versions is potentially vulnerable until patched or upgraded.

Risk and Exploitability

The CVSS base score of 9.8 marks this as a critical vulnerability, yet the EPSS score of less than 1% indicates low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a crafted file to a LibRaw instance; therefore, the likely attack vector is a local or unauthenticated file‑processing scenario where untrusted images are processed. If an application processes images from untrusted sources, the risk is amplified, as the attacker can gain code execution within that application’s context.

Generated by OpenCVE AI on April 10, 2026 at 22:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade LibRaw to a version later than 0.22.1, such as 0.22.2 or newer, which contains the necessary fix.
  • If upgrading immediately is not possible, restrict or quarantine the use of LibRaw in handling untrusted image files until a patch is applied.
  • Monitor logs and security alerts for signs of exploitation attempts or anomalous behaviors in applications that import images via LibRaw.

Generated by OpenCVE AI on April 10, 2026 at 22:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Apr 2026 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:libraw:libraw:0.22.0:*:*:*:*:*:*:*
cpe:2.3:a:libraw:libraw:0.22.1:*:*:*:*:*:*:*

Wed, 08 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Libraw
Libraw libraw
Vendors & Products Libraw
Libraw libraw

Wed, 08 Apr 2026 00:15:00 +0000

Type Values Removed Values Added
Title LibRaw: LibRaw: Arbitrary Code Execution via specially crafted file
Weaknesses CWE-120
References
Metrics threat_severity

None

threat_severity

Important


Tue, 07 Apr 2026 18:00:00 +0000


Tue, 07 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
Description A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Weaknesses CWE-131
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published:

Updated: 2026-04-08T03:55:51.222Z

Reserved: 2026-01-21T16:22:17.256Z

Link: CVE-2026-20911

cve-icon Vulnrichment

Updated: 2026-04-07T16:23:22.203Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-07T15:17:35.467

Modified: 2026-04-10T20:50:34.563

Link: CVE-2026-20911

cve-icon Redhat

Severity : Important

Publid Date: 2026-04-07T13:49:31Z

Links: CVE-2026-20911 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-13T14:26:46Z

Weaknesses