Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and possibly execute arbitrary code via vectors related to indexes.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HLibraw
APPLibraw< 0.17.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
Related vulnerabilities
CVE-2026-20911CRITICAL9.8PL ✓same product
Przepełnienie bufora sterty w LibRaw — funkcja HuffTable::initval
CVE-2026-20889CRITICAL9.8PL ✓same product
LibRaw: przepełnienie bufora sterty w x3f_thumb_loader
CVE-2026-21413CRITICAL9.8PL ✓same product
Heap buffer overflow w LibRaw — funkcja lossless_jpeg_load_raw
CVE-2015-8367CRITICAL9.8PL ✓same product
LibRaw: błąd inicjalizacji pamięci w phase_one_correct umożliwiający RCE
CVE-2017-14608CRITICAL9.1PL ✓same product
LibRaw: out of bounds read w obsłudze plików Kodak (kodak_65000_load_raw)