SB2026083131 - Multiple vulnerabilities in Exiv2
Published: August 31, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 7 vulnerabilities.
1) Out-of-bounds write (CVE-ID: N/A)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds write in RemoteIo::mmap when listing available image previews from a URL input. A remote attacker can provide a specially crafted image URL to cause a denial of service.
The issue affects the RemoteIo code path and is triggered when Exiv2 is run on a URL rather than a local file using the -pp command line option.
2) Out-of-bounds write (CVE-ID: N/A)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds write in Exiv2::http in http.cpp when processing a URL argument. A remote attacker can supply a specially crafted URL to cause a denial of service.
The issue can only be triggered when Exiv2 is run on a URL rather than a local file.
3) Out-of-bounds write (CVE-ID: CVE-2026-68546)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds write in RemoteIo::Impl::populateBlocks when reading data from a malicious remote server through a URL input. A remote attacker can serve a specially crafted file from a malicious remote server to cause a denial of service.
The issue affects the RemoteIo class and can be triggered only when Exiv2 is run on a URL rather than a local file.
4) Out-of-bounds read (CVE-ID: CVE-2026-68547)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in RemoteIo::Impl::populateBlocks in the RemoteIo class when reading a block-aligned remote CRW file from a URL. A remote attacker can supply a specially crafted remote CRW file to disclose sensitive information.
The issue is triggered only when Exiv2 is run on a URL rather than a local file.
5) Input validation error (CVE-ID: N/A)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in QuickTimeVideo::userDataDecoder when parsing an invalid input file. A remote attacker can supply a specially crafted file to cause a denial of service.
6) Out-of-bounds read (CVE-ID: CVE-2026-49275)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in CrwMap::decodeBasic() when parsing crafted input. A remote attacker can supply specially crafted input to disclose sensitive information.
The issue was reproduced with the project's fuzz target, and the vendor noted that it could not be reproduced with the exiv2 command line application.
7) Stack-based buffer overflow (CVE-ID: N/A)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled memory allocation in PgfImage::readMetadata() when parsing a crafted PGF file. A remote attacker can supply a malicious file to trigger excessive memory allocation and impact system performance.
User interaction is required to process the crafted file.
Remediation
Install update from vendor's website.
References
- https://github.com/Exiv2/exiv2/security/advisories/GHSA-vg6c-9f6h-4x5q
- https://github.com/Exiv2/exiv2/security/advisories/GHSA-9v3x-mhg4-wwv2
- https://github.com/Exiv2/exiv2/security/advisories/GHSA-3695-mjv8-3r52
- https://github.com/Exiv2/exiv2/security/advisories/GHSA-jcgh-p9v3-pw6j
- https://github.com/Exiv2/exiv2/security/advisories/GHSA-fgw8-p7pr-37cp
- https://github.com/Exiv2/exiv2/pull/9309
- https://github.com/Exiv2/exiv2/security/advisories/GHSA-hxph-pv7w-8649
- https://github.com/Exiv2/exiv2/pull/9308
- https://github.com/Exiv2/exiv2/security/advisories/GHSA-pwvq-9w4q-786w