PatchSiren

LibRaw CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH LibRaw CVE published 2026-07-27

CVE-2026-51235

CVE-2026-51235 is a high-severity buffer overflow vulnerability in LibRaw 0.21, affecting the stretch() function in src/libraw_cxx.cpp and the fuji_rotate() function in src/decoders/fuji.cpp. The CVSS score is 8.8, indicating a high severity level. The vulnerability is classified as CWE-122. To address this vulnerability, developers and users of LibRaw 0.21 should be aware of this vulnerability and take n [truncated]

CRITICAL LibRaw CVE published 2026-04-07

CVE-2026-20911

CVE-2026-20911 is a critical heap-based buffer overflow vulnerability in the HuffTable::initval functionality of LibRaw. The vulnerability exists in LibRaw Commit 0b56545 and Commit d20315b. An attacker can provide a malicious file to trigger this vulnerability, potentially leading to arbitrary code execution. The vulnerability has a CVSS score of 9.8 and is classified as CRITICAL. The CVE was published o [truncated]