OVERVIEW CVE-2026-24450 is an integer overflow vulnerability in LibRaw's uncompressed_fp_dng_load_raw function (Commit 8dc68e2) that results in a heap buffer overflow condition. The vulnerability is triggered when processing specially crafted malicious DNG image files, making it relevant to any software or service that uses LibRaw for digital image processing. SEVERITY The vulnerability carries a CVSS v3.1 score of 8.1 (HIGH) with a network-based attack vector, high complexity, and no privilege or user interaction requirements. An attacker can achieve high-impact compromises across confidentiality, integrity, and availability. The FAUCET Risk Score of 55.0 out of 100 indicates moderate concern from a threat modeling perspective, though the EPSS score of 0.0005 suggests current real-world exploitation probability remains extremely low. EXPLOITATION STATUS The vulnerability is not currently included in CISA's Known Exploited Vulnerabilities (KEV) catalog and shows no signs of active exploitation or public exploit code availability. Community attention appears minimal, with no indication of widespread awareness or weaponization. However, the technical feasibility of exploitation and the availability of the vulnerable code commit suggest that proof-of-concept development remains possible, warranting proactive patching in environments where LibRaw is deployed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.22.1CPE matchmatch criteria | cpe:2.3:a:libraw:libraw:0.22.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.