cbcvebase.
CVE-2025-43962
published 2025-04-21

CVE-2025-43962: In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing, related to large w0 or w1 values or…

PriorityP341critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.42%
34.3th percentile
In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing, related to large w0 or w1 values or the frac and mult calculations.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlibraw< libraw 0.20.2-2.1+deb12u1 (bookworm)libraw 0.20.2-2.1+deb12u1 (bookworm)
librawlibraw< 0.21.40.21.4
librawlibraw>= 0 < 0.20.2-1+deb11u20.20.2-1+deb11u2
librawlibraw>= 0 < 0.20.2-2.1+deb12u10.20.2-2.1+deb12u1
librawlibraw>= 0 < 0.21.4-10.21.4-1
librawlibraw>= 0 < 0.21.4-10.21.4-1
librawlibraw>= 0 < 0.19.5-1ubuntu1.40.19.5-1ubuntu1.4
librawlibraw>= 0 < 0.20.2-2ubuntu2.22.04.20.20.2-2ubuntu2.22.04.2
librawlibraw>= 0 < 0.21.2-2.1ubuntu0.24.04.10.21.2-2.1ubuntu0.24.04.1
librawlibraw>= 0 < 0.17.1-1ubuntu0.5+esm10.17.1-1ubuntu0.5+esm1
librawlibraw>= 0 < 0.18.8-1ubuntu0.4+esm10.18.8-1ubuntu0.4+esm1

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
osv9.1CRITICAL
vendor_debian2.9LOW
vendor_redhat2.9LOW
vendor_ubuntu2.9LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.