CVE-2023-1729
NixOS vulnerability analysis and mitigation

Overview

CVE-2023-1729 is a vulnerability discovered in LibRaw, a library for reading RAW files obtained from digital photo cameras. The vulnerability was identified as a heap-buffer-overflow in the raw2image_ex() function. This security flaw was reported on January 14, 2023, and affects various versions of LibRaw (LibRaw Issue, NVD).

Technical details

The vulnerability is characterized by a heap-buffer-overflow condition in the raw2image_ex() function when processing maliciously crafted files. The issue occurs during memory operations, specifically in a WRITE operation of size 2224 bytes, which could lead to buffer overflow. The vulnerability has been assigned a CVSS v3.1 base score of 6.5 (Medium), with attack vector being Network, attack complexity Low, and requiring user interaction (Ubuntu Security).

Impact

When exploited, this vulnerability can lead to application crashes when processing maliciously crafted files. The impact primarily affects the availability of applications using the LibRaw library, with no reported impacts on confidentiality or integrity (NVD, Debian Security).

Mitigation and workarounds

The vulnerability has been fixed in multiple versions across different distributions. Fixes have been implemented through commits 9ab70f6dca19229cb5caad7cc31af4e7501bac93 and 477e0719ffc07190c89b4f3d12d51b1292e75828 in the LibRaw repository. Various distributions have released security updates, including Debian (version 0.20.2-1+deb11u1), Ubuntu, and Fedora (Debian Security, Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22783HIGH8.1
  • NixOSNixOS
  • iris
NoYesJan 12, 2026
CVE-2026-0821MEDIUM6.9
  • NixOSNixOS
  • quickjs
NoNoJan 10, 2026
CVE-2025-68949MEDIUM5.3
  • NixOSNixOS
  • n8n
NoYesJan 13, 2026
CVE-2026-22784LOW2.3
  • NixOSNixOS
  • lychee
NoYesJan 12, 2026
CVE-2026-23497LOW1.3
  • NixOSNixOS
  • learning
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management