Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 13 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Apr 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:libraw:libraw:0.22.1:*:*:*:*:*:*:* |
Thu, 09 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Heap Buffer Overflow via Malicious DNG File in LibRaw | LibRaw: LibRaw: Arbitrary code execution via integer overflow in deflate_dng_load_raw |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Heap Buffer Overflow via Malicious DNG File in LibRaw | |
| First Time appeared |
Libraw
Libraw libraw |
|
| Vendors & Products |
Libraw
Libraw libraw |
Tue, 07 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability. | |
| Weaknesses | CWE-190 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2026-04-13T13:04:17.769Z
Reserved: 2026-01-29T14:17:38.877Z
Link: CVE-2026-20884
Updated: 2026-04-07T16:23:20.112Z
Status : Analyzed
Published: 2026-04-07T15:17:35.127
Modified: 2026-04-10T20:50:52.523
Link: CVE-2026-20884
OpenCVE Enrichment
Updated: 2026-04-13T14:27:15Z