CVE-2026-21413
Critical · CVSS 9.8LibRaw — Heap-based buffer overflow
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-129, CWE-787
Description
A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Search profile — drives PoC discovery
Symbols lossless_jpeg_load_rawLibRawCWE-129CWE-787
Keywords CVE-2026-21413LibRawlossless_jpeg_load_rawheap buffer overflowTALOS-2026-2331LibRaw heap overflowraw image parsing vulnerability
Versions: Commit 0b56545, Commit d20315b
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2026-2331
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2026-2331
- https://access.redhat.com/errata/RHSA-2026:11360
- https://access.redhat.com/errata/RHSA-2026:13284
- https://access.redhat.com/errata/RHSA-2026:13854
- https://access.redhat.com/errata/RHSA-2026:13860
- https://access.redhat.com/errata/RHSA-2026:13868
- https://access.redhat.com/errata/RHSA-2026:13870
- https://access.redhat.com/errata/RHSA-2026:14224
- https://access.redhat.com/errata/RHSA-2026:14655
- https://access.redhat.com/errata/RHSA-2026:14673
- https://access.redhat.com/errata/RHSA-2026:19345
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-06-30T18:30:14.000Z