In LibRaw before 0.21.4, tag 0x412 processing in phaseonecorrect in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-61756.json"