ECHO-ddb8-c818-edca

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-ddb8-c818-edca.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-ddb8-c818-edca
Upstream
Withdrawn
2026-05-04T12:45:02Z
Published
2026-04-02T21:00:47Z
Modified
2026-09-15T03:34:25Z
Summary
Vulnerable code is not present in libraw 0.21.4 (the version shipped in Debian trixie). The CVE describes a heap out-of-bounds write in HuffTable::initval (src/decompressors/losslessjpeg.cpp), reachable via LibRaw::sony_ycbcr_load_raw -> LibRaw_LjpegDecompressor::initialize -> HuffTable::initval. None of those symbols exist in 0.21.4: the src/decompressors/ directory, the LibRaw_LjpegDecompressor class, and the sony_ycbcr_load_raw entry point were all introduced together in libraw 0.22.0. Empirically confirmed by running the public PoC from https://github.com/biniamf/pocs/tree/main/libraw_lljpeg against an ASan build of unpatched libraw 0.21.4: the file is rejected at open with "Unsupported file format or not RAW file"; the same PoC reproduces the heap-buffer-overflow in 0.22.0 with the stack trace from the Talos report.
Details
References

Affected packages

Echo / libraw

Package

Name
libraw
Purl
pkg:deb/echo/libraw

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.21.4

Database specific

source
"https://advisory.echohq.com/osv/ECHO-ddb8-c818-edca.json"