CVE-2020-24889: Libraw

High severity, CVSS 7.8. EPSS: 1.4% chance of exploitation in the next 30 days.

A buffer overflow vulnerability in LibRaw version < 20.0 LibRaw::GetNormalizedModel in src/metadata/normalize_model.cpp may lead to context-dependent arbitrary code execution.

Affected products

  • Libraw Libraw: before 0.20.0 (fixed in 0.20.0)

Published 2020-09-16. Last modified 2026-06-17.