


Perceptive Security
SOC/SIEM Consultancy

LibRaw 0.21 is vulnerable to Buffer Overflow in the stretch() function (src/libraw_cxx.cpp) and fuji_rotate() function (src/decoders/fuji.cpp).
Published:
26 July 2026 at 22:00:00
Alert date:
27 July 2026 at 20:03:54
Source:
nvd.nist.gov
Zero-Day Vulnerabilities
LibRaw version 0.21 contains a buffer overflow vulnerability affecting two functions: stretch() in src/libraw_cxx.cpp and fuji_rotate() in src/decoders/fuji.cpp. Buffer overflow vulnerabilities in image processing libraries can be exploited by attackers through maliciously crafted image files. This could potentially allow arbitrary code execution or cause application crashes. The vulnerability has been assigned CVE-2026-51235 and is tracked by the National Vulnerability Database. LibRaw is a widely used library for reading RAW files from digital cameras, making this vulnerability relevant to many applications that process raw image data. A proof-of-concept advisory has been published on GitHub by the reporter.
Technical details
Mitigation steps:
Affected products:
LibRaw 0.21
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-51235
http://libraw.com
https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51235
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
