We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-43962



Description

In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing, related to large w0 or w1 values or the frac and mult calculations.

Reserved 2025-04-20 | Published 2025-04-20 | Updated 2025-04-21 | Assigner mitre


LOW: 2.9CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Problem types

CWE-125 Out-of-bounds Read

Product status

Default status
unaffected

Any version before 0.21.4
affected

References

www.libraw.org/news/libraw-0-21-4-release

github.com/LibRaw/LibRaw/compare/0.21.3...0.21.4

github.com/...ommit/66fe663e02a4dd610b4e832f5d9af326709336c2

cve.org (CVE-2025-43962)

nvd.nist.gov (CVE-2025-43962)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-43962

Support options

Helpdesk Chat, Email, Knowledgebase