Description

An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

INFO

Published Date :

2026-04-07T13:49:23.872Z

Last Modified :

2026-04-08T03:55:46.772Z

Source :

talos
AFFECTED PRODUCTS

The following products are affected by CVE-2026-24450 vulnerability.

No data.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact