SB20260925192 - openEuler 24.03 LTS SP4 update for exiv2



SB20260925192 - openEuler 24.03 LTS SP4 update for exiv2

Published: September 25, 2026

Security Bulletin ID SB20260925192
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Out-of-bounds read (CVE-ID: CVE-2026-49275)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in CrwMap::decodeBasic() when parsing crafted input. A remote attacker can supply specially crafted input to disclose sensitive information.

The issue was reproduced with the project's fuzz target, and the vendor noted that it could not be reproduced with the exiv2 command line application.


2) Out-of-bounds write (CVE-ID: CVE-2026-68546)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds write in RemoteIo::Impl::populateBlocks when reading data from a malicious remote server through a URL input. A remote attacker can serve a specially crafted file from a malicious remote server to cause a denial of service.

The issue affects the RemoteIo class and can be triggered only when Exiv2 is run on a URL rather than a local file.


3) Out-of-bounds read (CVE-ID: CVE-2026-68547)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in RemoteIo::Impl::populateBlocks in the RemoteIo class when reading a block-aligned remote CRW file from a URL. A remote attacker can supply a specially crafted remote CRW file to disclose sensitive information.

The issue is triggered only when Exiv2 is run on a URL rather than a local file.


Remediation

Install update from vendor's website.