LibRaw is vulnerable to denial of service. It not supposed to be used in RHEL by network-facing applications, thus reducing the impact of this flaw. A stack buffer overflow vulnerability was found in LibRaw. This flaw allows a malicious user to send a crafted image that, when parsed by an application linked to LibRaw, leads to a denial of service or potential code execution.
access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.5_release_notes/
access.redhat.com/errata/RHSA-2021:4381
access.redhat.com/security/updates/classification/#moderate
bugzilla.redhat.com/show_bug.cgi?id=1928794
github.com/LibRaw/LibRaw/commit/4feaed4dea636cee4fee010f615881ccf76a096d
github.com/LibRaw/LibRaw/issues/330
security.gentoo.org/glsa/202208-07