Out-of-bounds read in Exiv2 - CVE-2025-54080
Published: September 2, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in Exiv2::EpsImage::writeMetadata() function. A remote attacker can create a specially crafted EPS file, trick the victim into opening it, trigger an out-of-bounds read error and read contents of memory on the system.
Affected software
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
openSUSE Leap
Ubuntu
Anolis OS
openEuler
Fedora
exiv2-debuginfo
libexiv2-12-debuginfo
libexiv2-12
libexiv2-devel
exiv2-debugsource
exiv2 (Ubuntu package)
libexiv2-26-64bit-debuginfo
libexiv2-26-debuginfo
exiv2-0_26-debugsource
libexiv2-26
libexiv2-26-32bit-debuginfo
libexiv2-26-32bit
libexiv2-26-64bit
exiv2
exiv2-devel
exiv2-help
exiv2-libs
exiv2-doc
mingw-exiv2
inih
How to mitigate CVE-2025-54080
exiv2-debuginfo - update to 0.23-12.26.1
libexiv2-12-debuginfo - update to 0.23-12.26.1
libexiv2-12 - update to 0.23-12.26.1
libexiv2-devel - update to 0.23-12.26.1
exiv2-debugsource - update to 0.23-12.26.1
exiv2 (Ubuntu package) - addressed in versions 0.25-2.1ubuntu16.04.7+esm5, 0.25-3.1ubuntu0.18.04.11+esm1, 0.27.2-8ubuntu2.7+esm1, 0.27.2-8ubuntu2.7+esm3, 0.27.5-3ubuntu1.1, 0.27.5-3ubuntu1.3, 0.27.6-1ubuntu0.1, 0.27.6-1ubuntu0.3, 0.28.5+dfsg-1ubuntu0.1, 0.28.5+dfsg-1ubuntu0.3
libexiv2-26-64bit-debuginfo - update to 0.26-150400.9.34.1
libexiv2-26-debuginfo - update to 0.26-150400.9.34.1
exiv2-0_26-debugsource - update to 0.26-150400.9.34.1
libexiv2-26 - update to 0.26-150400.9.34.1
libexiv2-26-32bit-debuginfo - update to 0.26-150400.9.34.1
libexiv2-26-32bit - update to 0.26-150400.9.34.1
libexiv2-26-64bit - update to 0.26-150400.9.34.1
exiv2 - update to 0.28.2-4
exiv2-debuginfo - update to 0.28.2-4
exiv2-debugsource - update to 0.28.2-4
exiv2-devel - update to 0.28.2-4
exiv2-help - update to 0.28.2-4
exiv2 - addressed in versions 0.28.6-1.fc41, 0.28.6-1.fc42, 0.28.6-1.fc43, 0.28.6-2.fc41, 0.28.6-2.fc42, 0.28.6-2.fc43
exiv2 - update to 0.28.7-1
exiv2-devel - update to 0.28.7-1
exiv2-libs - update to 0.28.7-1
exiv2-doc - update to 0.28.7-1
mingw-exiv2 - addressed in versions 0.28.7-1.fc41, 0.28.7-1.fc42
inih - addressed in versions 62-1.fc41, 62-1.fc42
External References
Related Security Bulletins
- Multiple vulnerabilities in GNU Exiv2
- Fedora 43 update for exiv2
- Fedora 42 update for exiv2
- Fedora 41 update for exiv2
- Fedora 43 update for exiv2
- Fedora 42 update for exiv2
- Fedora 41 update for exiv2
- openEuler 24.03 LTS update for exiv2
- Anolis OS update for exiv2
- Fedora 41 update for inih, mingw-exiv2
- Fedora 42 update for inih, mingw-exiv2
- Ubuntu update for exiv2
- Ubuntu update for exiv2
- SUSE update for exiv2
- SUSE update for exiv2-0_26