In LibRaw before 0.21.4, phaseonecorrect in decoders/loadmfbacks.cpp allows out-of-buffer access because splitcol and split_row values are not checked in 0x041f tag processing.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-61810.json"