CVE detail
CVE-2026-20911
A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 14.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-20911.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comApr 7, 2026, 3:17 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2455959bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comApr 7, 2026, 3:17 PM - https://access.redhat.com/security/cve/CVE-2026-20911access.redhat.com
No excerpt available.
Exploitaccess.redhat.comApr 7, 2026, 3:17 PM - https://www.talosintelligence.com/vulnerability_reports/TALOS-2026-2330www.talosintelligence.com
No excerpt available.
Exploitwww.talosintelligence.comApr 7, 2026, 3:17 PM - https://talosintelligence.com/vulnerability_reports/TALOS-2026-2330talosintelligence.com
No excerpt available.
Exploittalosintelligence.comApr 7, 2026, 3:17 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-27820CVSS 1.7 · Low
zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zli…
- CVE-2026-1188CVSS 6.9 · Medium
In the Eclipse OMR port library component since release 0.2.0, an API function to return the textual names of all supported processor features was not accounting for the separator…
- CVE-2025-55297CVSS 5.2 · Medium
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: Wi-Fi credential han…
- CVE-2024-23621CVSS 10.0 · Critical
A buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vulnerability to achieve remote code executi…
- CVE-2023-4257CVSS 7.6 · High
Unchecked user input length in /subsys/net/l2/wifi/wifi_shell.c can cause buffer overflows.
- CVE-2022-39377CVSS 7.0 · High
sysstat is a set of system performance tools for the Linux operating system. On 32 bit systems, in versions 9.1.16 and newer but prior to 12.7.1, allocate_structures contains a si…