{"id":"CVE-2026-88387","published":"2026-09-24T21:18:57.120","lastModified":"2026-09-29T03:17:21.263","description":"LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF tag 0x00fe (NewSubfileType). A specially crafted RAW, TIFF, or DNG file can supply an attacker-controlled NewSubfileType value outside the range of a signed int. The parser converts this value and narrows it to int without performing range validation. This out-of-range conversion triggers undefined behavior, resulting in process termination and denial of service.","cvssScore":5.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwes":["CWE-681"],"vendors":[],"products":[],"references":[{"url":"https://github.com/LibRaw/LibRaw/commit/b41cbbd61951783e0440590dae55411a16185bdf","tags":[]},{"url":"https://github.com/LibRaw/LibRaw/issues/844","tags":[]},{"url":"https://github.com/LibRaw/LibRaw/pull/853","tags":[]},{"url":"https://github.com/LibRaw/LibRaw/issues/844","tags":[]}],"exploitRefs":[{"url":"https://github.com/LibRaw/LibRaw/commit/b41cbbd61951783e0440590dae55411a16185bdf","tags":[]},{"url":"https://github.com/LibRaw/LibRaw/issues/844","tags":[]},{"url":"https://github.com/LibRaw/LibRaw/pull/853","tags":[]},{"url":"https://github.com/LibRaw/LibRaw/issues/844","tags":[]}],"hasPoc":true,"ai":null}