CVE-2026-24808

NameCVE-2026-24808
DescriptionInteger Overflow or Wraparound vulnerability in RawTherapee (rtengine modules). This vulnerability is associated with program files dcraw.Cc. This issue affects RawTherapee: through 5.11.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rawtherapee (PTS)bullseye5.8-3vulnerable
bookworm5.9-1vulnerable
trixie5.11-2vulnerable
forky, sid5.12-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
rawtherapeesource(unstable)5.12-1

Notes

https://github.com/RawTherapee/RawTherapee/pull/7359
Fixed by: https://github.com/RawTherapee/RawTherapee/commit/e86bc3f638f8db3ac7b2d1d12df6ee38155788e7 (5.12-rc1)

Search for package or bug name: Reporting problems