LibRaw 0.22.1 was released with security fixes for multiple high-severity memory corruption and integer overflow vulnerabilities in the library’s RAW image parsing code, including CVE-2026-21413 in lossless_jpeg_load_raw, CVE-2026-20889 in x3f_thumb_loader, and CVE-2026-20884 in deflate_dng_load_raw. The flaws were reported by Cisco Talos and affect parsing paths for formats such as Canon CR2, Sigma X3F, and DNG files, where crafted metadata or compressed image data can trigger heap-based buffer overflows or undersized allocations followed by out-of-bounds writes.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
LibRaw 0.22.1 was released on 2026-04-11 as a bugfix-only update containing multiple security fixes for memory corruption and integer overflow issues in image parsing and decoding code. The release addressed several vulnerabilities reported by Cisco Talos, including flaws in lossless_jpeg_load_raw, x3f_thumb_loader, x3f_load_huffman, HuffTable::initval, uncompressed_fp_dng_load_raw, and deflate_dng_load_raw.
A new LibRaw vulnerability, CVE-2026-21413, was received by Cisco Talos CNA on 2026-04-07. The issue is a heap-based buffer overflow in lossless_jpeg_load_raw that can be triggered by a specially crafted malicious image file, including Canon CR2-related parsing paths.
A new LibRaw vulnerability, CVE-2026-20889, was received by Cisco Talos CNA on 2026-04-07. The flaw is a heap-based buffer overflow in x3f_thumb_loader that can be triggered by a specially crafted Sigma X3F image file.
A new LibRaw vulnerability, CVE-2026-20884, was received by Cisco Talos CNA on 2026-04-07. The issue is an integer overflow in deflate_dng_load_raw that can lead to a heap buffer overflow when parsing a specially crafted malicious file.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcecvereports.com
Open sourcecvereports.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.