Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 02 Apr 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in LibRaw up to 0.22.0. This impacts the function HuffTable::initval of the file src/decompressors/losslessjpeg.cpp of the component JPEG DHT Parser. This manipulation of the argument bits[] causes out-of-bounds write. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.22.1 will fix this issue. Patch name: a6734e867b19d75367c05f872ac26322464e3995. It is advisable to upgrade the affected component. | |
| Title | LibRaw JPEG DHT losslessjpeg.cpp initval out-of-bounds write | |
| First Time appeared |
Libraw
Libraw libraw |
|
| Weaknesses | CWE-119 CWE-787 |
|
| CPEs | cpe:2.3:a:libraw:libraw:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Libraw
Libraw libraw |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-02T01:45:12.421Z
Reserved: 2026-04-01T12:43:19.844Z
Link: CVE-2026-5318
No data.
No data.
No data.
OpenCVE Enrichment
No data.