CVE List

CVE-2025-43962

Low 2.9

In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing, related to large w0 or w1 values or the frac and mult calculations.

Published April 21, 2025.

Affected software

Get alerts for Libraw Libraw

Reference links