CVE-2023-1729
published 2023-05-15CVE-2023-1729: A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.
PriorityP428medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
1.29%
67.0th percentile
A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libraw | < libraw 0.20.2-2.1 (bookworm) | libraw 0.20.2-2.1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libraw | libraw | < 0.21.2 | 0.21.2 |
| libraw | libraw | — | — |
| libraw | libraw | >= 0 < 0.20.2-1+deb11u1 | 0.20.2-1+deb11u1 |
| libraw | libraw | >= 0 < 0.20.2-2.1 | 0.20.2-2.1 |
| libraw | libraw | >= 0 < 0.20.2-2.1 | 0.20.2-2.1 |
| libraw | libraw | >= 0 < 0.20.2-2.1 | 0.20.2-2.1 |
| linux | linux_kernel | >= 5.18.0 < 6.5.4 | 6.5.4 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: bpf: bpf_sk_storage: Fix invalid wait context lockdep report
vendor_redhat·2025-12-09·CVSS 5.5
CVE-2023-53857 [LOW] CWE-413 kernel: bpf: bpf_sk_storage: Fix invalid wait context lockdep report
kernel: bpf: bpf_sk_storage: Fix invalid wait context lockdep report
In the Linux kernel, the following vulnerability has been resolved:
bpf: bpf_sk_storage: Fix invalid wait context lockdep report
'./test_progs -t test_local_storage' reported a splat:
[ 27.137569] =============================
[ 27.138122] [ BUG: Invalid wait context ]
[ 27.138650] 6.5.0-03980-gd11ae1b16b0a #247 Tainted: G O
[ 27.139542] -----------------------------
[ 27.140106] test_progs/1729 is trying to lock:
[ 27.140713] ffff8883ef047b88 (stock_lock){-.-.}-{3:3}, at: local_lock_acquire+0x9/0x130
[ 27.141834] other info that might help us debug this:
[ 27.142437] context-{5:5}
[ 27.142856] 2 locks held by test_progs/1729:
[ 27.143352] #0: ffffffff84bcd9c0 (rcu_read_lock){....}-{1:3}, at: rcu_lock_acquire+0x4/0x40
[
Ubuntu
digiKam vulnerabilities
vendor_ubuntu·2025-02-13·CVSS 5.5
CVE-2020-35531 [MEDIUM] digiKam vulnerabilities
Title: digiKam vulnerabilities
Summary: Several security issues were fixed in digiKam.
Zinuo Han and Ao Wang discovered that the Android DNG SDK, vendored in
digiKam, did not correctly parse certain files. An attacker could possibly
use this issue to execute arbitrary code. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2017-0691)
It was discovered that Platinum Upnp SDK, vendored in digiKam, was
vulnerable to a path traversal attack. An attacker could possibly use this
issue to leak sensitive information. This issue only affected
Ubuntu 20.04 LTS. (CVE-2020-19858)
It was discovered that LibRaw, vendored in digiKam, did not correctly
handle certain memory operations. If a user or automated system were
tricked into opening a specially crafted file
Ubuntu
LibRaw vulnerabilities
vendor_ubuntu·2023-06-05
CVE-2023-1729 LibRaw vulnerabilities
Title: LibRaw vulnerabilities
Summary: Several security issues were fixed in LibRaw.
It was discovered that LibRaw incorrectly handled photo files. If a user or
automated system were tricked into processing a specially crafted photo
file, a remote attacker could cause applications linked against LibRaw to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
LibRaw: a heap-buffer-overflow in raw2image_ex()
vendor_redhat·2023-01-14·CVSS 6.5
CVE-2023-1729 [MEDIUM] CWE-119 LibRaw: a heap-buffer-overflow in raw2image_ex()
LibRaw: a heap-buffer-overflow in raw2image_ex()
A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.
A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.
Package: LibRaw (Red Hat Enterprise Linux 7) - Fix deferred
Package: LibRaw (Red Hat Enterprise Linux 8) - Fix deferred
Debian
CVE-2023-1729: libraw - A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a...
vendor_debian·2023·CVSS 6.5
CVE-2023-1729 [MEDIUM] CVE-2023-1729: libraw - A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a...
A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.
Scope: local
bookworm: resolved (fixed in 0.20.2-2.1)
bullseye: resolved (fixed in 0.20.2-1+deb11u1)
forky: resolved (fixed in 0.20.2-2.1)
sid: resolved (fixed in 0.20.2-2.1)
trixie: resolved (fixed in 0.20.2-2.1)
OSV
bpf: bpf_sk_storage: Fix invalid wait context lockdep report
osv·2025-12-09
CVE-2023-53857 bpf: bpf_sk_storage: Fix invalid wait context lockdep report
bpf: bpf_sk_storage: Fix invalid wait context lockdep report
In the Linux kernel, the following vulnerability has been resolved:
bpf: bpf_sk_storage: Fix invalid wait context lockdep report
'./test_progs -t test_local_storage' reported a splat:
[ 27.137569] =============================
[ 27.138122] [ BUG: Invalid wait context ]
[ 27.138650] 6.5.0-03980-gd11ae1b16b0a #247 Tainted: G O
[ 27.139542] -----------------------------
[ 27.140106] test_progs/1729 is trying to lock:
[ 27.140713] ffff8883ef047b88 (stock_lock){-.-.}-{3:3}, at: local_lock_acquire+0x9/0x130
[ 27.141834] other info that might help us debug this:
[ 27.142437] context-{5:5}
[ 27.142856] 2 locks held by test_progs/1729:
[ 27.143352] #0: ffffffff84bcd9c0 (rcu_read_lock){....}-{1:3}, at: rcu_lock_acquire+0x4/0x40
[ 27.14
OSV
digikam vulnerabilities
osv·2025-02-13·CVSS 5.5
CVE-2017-0691 [MEDIUM] digikam vulnerabilities
digikam vulnerabilities
Zinuo Han and Ao Wang discovered that the Android DNG SDK, vendored in
digiKam, did not correctly parse certain files. An attacker could possibly
use this issue to execute arbitrary code. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2017-0691)
It was discovered that Platinum Upnp SDK, vendored in digiKam, was
vulnerable to a path traversal attack. An attacker could possibly use this
issue to leak sensitive information. This issue only affected
Ubuntu 20.04 LTS. (CVE-2020-19858)
It was discovered that LibRaw, vendored in digiKam, did not correctly
handle certain memory operations. If a user or automated system were
tricked into opening a specially crafted file, an attacker could possibly
use this issue to leak sensitive in
GHSA
GHSA-5gp6-9w92-5752: A flaw was found in LibRaw
ghsa_unreviewed·2023-05-16
CVE-2023-1729 [MEDIUM] CWE-119 GHSA-5gp6-9w92-5752: A flaw was found in LibRaw
A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.
OSV
CVE-2023-1729: A flaw was found in LibRaw
osv·2023-05-15·CVSS 6.5
CVE-2023-1729 [MEDIUM] CVE-2023-1729: A flaw was found in LibRaw
A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2188240https://github.com/LibRaw/LibRaw/issues/557https://lists.debian.org/debian-lts-announce/2023/05/msg00025.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AGZ6XF5WTPJ4GLXQ62JVRDZSVSJHXNQU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E5ZJ3UBTJBZHNPJQFOSGM5L7WAHHE2GY/https://security.gentoo.org/glsa/202312-08https://www.debian.org/security/2023/dsa-5412https://bugzilla.redhat.com/show_bug.cgi?id=2188240https://github.com/LibRaw/LibRaw/issues/557https://lists.debian.org/debian-lts-announce/2023/05/msg00025.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AGZ6XF5WTPJ4GLXQ62JVRDZSVSJHXNQU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E5ZJ3UBTJBZHNPJQFOSGM5L7WAHHE2GY/https://security.gentoo.org/glsa/202312-08https://www.debian.org/security/2023/dsa-5412
2023-05-15
Published