CVE-2025-43963

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Apr 21, 2025
Updated: May 8, 2025
CWE ID 125

Summary

CVE-2025-43963 is a vulnerability affecting LibRaw versions prior to 0.21.4. This issue arises due to a lack of proper checks on 'split_col' and 'split_row' values during the processing of 0x041f tags in the 'decoders/load_mfbacks.cpp' file. As a result, out-of-buffer access is allowed, leaving the software open to potential attacks. This weakness could lead to memory corruption or buffer overflow, posing a significant risk to users if exploited. Upgrading to the latest version of LibRaw is strongly advised to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share