CVE-2017-6886: Libraw

Critical severity, CVSS 9.8. EPSS: 3.4% chance of exploitation in the next 30 days.

An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memory.

Affected products

  • Libraw Libraw: up to and including 0.18.1

Published 2017-05-16. Last modified 2026-06-17.