CVE-2025-43964 | LibRaw up to 0.21.3 load_mfbacks.cpp phase_one_correct w0/w1 improper validation of specified quantity in input
A vulnerability, which was classified as problematic, was found in LibRaw up to 0.21.3. This affects the function phase_one_correct of the file decoders/load_mfbacks.cpp. The manipulation of the argument w0/w1 leads to improper validation of specified quantity in input.
This vulnerability is uniquely identified as CVE-2025-43964. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.