| Package | libraw |
|---|---|
| Version | 0.17.2-6+deb9u6 (stretch), 0.19.2-2+deb10u5 (buster) |
| Related CVEs | CVE-2025-43961 CVE-2025-43962 CVE-2025-43963 CVE-2025-43964 |
- CVE-2025-43961
-
Out-of-bounds read in the Fujifilm
0xf00ctag parser. (This issue did not affect 0.17.2-6+deb9u5 and earlier versions.) - CVE-2025-43962
-
Out-of-bounds reads for tag
0x412processing, related to largew0orw1values or thefracandmultcalculations. - CVE-2025-43963
-
phase_one_correct()allows out-of-buffer access becausesplit_colandsplit_rowvalues are not checked in0x041ftag processing. - CVE-2025-43964
-
Tag
0x412processing inphase_one_correct()does not enforce minimumw0andw1values.
For Debian 10 buster, these problems have been fixed in version 0.19.2-2+deb10u5.
For Debian 9 stretch, these problems have been fixed in version 0.17.2-6+deb9u6.
We recommend that you upgrade your libraw packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.