Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 42 - FEDORA-2025-caed275f11 critical: LibRaw Out-of-Buffer Access

fedora
Calendar Grey April 29, 2025
Dist Fedora Esm H88
LibRaw version 0.21.4 rollout in Fedora 42 rectifies severe accessibility problems and validation vulnerabilities.
Update to LibRaw 0.21.4.

Summary

MinGW Windows LibRaw library.

Update Information:

Update to LibRaw 0.21.4.

Change Log

* Wed Apr 16 2025 Sandro Mani - 0.21.4-1 - Update to 0.21.4

References


[ 1 ] Bug #2361338 - CVE-2025-43963 mingw-LibRaw: out-of-buffer access [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2361338 [ 2 ] Bug #2361343 - CVE-2025-43963 mingw-LibRaw: out-of-buffer access [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2361343 [ 3 ] Bug #2361348 - CVE-2025-43963 mingw-LibRaw: out-of-buffer access [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2361348 [ 4 ] Bug #2361356 - CVE-2025-43964 mingw-LibRaw: Improper Validation of Specified Quantity in Input in LibRaw [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2361356 [ 5 ] Bug #2361361 - CVE-2025-43964 mingw-LibRaw: Improper Validation of Specified Quantity in Input in LibRaw [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2361361 [ 6 ] Bug #2361366 - CVE-2025-43964 mingw-LibRaw: Improper Validation of Specified Quantity in Input in LibRaw [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2361...

Read the Full Advisory

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-caed275f11' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: mingw-LibRaw
Product: Fedora 42
Version: 0.21.4
Release: 1.fc42
Summary: Library for reading RAW files obtained from digital photo cameras

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here