Out-of-bounds read in Exiv2 - CVE-2025-54080

 

Out-of-bounds read in Exiv2 - CVE-2025-54080

Published: September 2, 2025


Vulnerability identifier: #VU114674
CSH Severity: Medium
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-54080
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition in Exiv2::EpsImage::writeMetadata() function. A remote attacker can create a specially crafted EPS file, trick the victim into opening it, trigger an out-of-bounds read error and read contents of memory on the system.


Affected software

Exiv2
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
openSUSE Leap
Ubuntu
Anolis OS
openEuler
Fedora
exiv2-debuginfo
libexiv2-12-debuginfo
libexiv2-12
libexiv2-devel
exiv2-debugsource
exiv2 (Ubuntu package)
libexiv2-26-64bit-debuginfo
libexiv2-26-debuginfo
exiv2-0_26-debugsource
libexiv2-26
libexiv2-26-32bit-debuginfo
libexiv2-26-32bit
libexiv2-26-64bit
exiv2
exiv2-devel
exiv2-help
exiv2-libs
exiv2-doc
mingw-exiv2
inih

How to mitigate CVE-2025-54080

Install updates from vendor's website.

Exiv2 - update to 0.28.6
exiv2-debuginfo - update to 0.23-12.26.1
libexiv2-12-debuginfo - update to 0.23-12.26.1
libexiv2-12 - update to 0.23-12.26.1
libexiv2-devel - update to 0.23-12.26.1
exiv2-debugsource - update to 0.23-12.26.1
exiv2 (Ubuntu package) - addressed in versions 0.25-2.1ubuntu16.04.7+esm5, 0.25-3.1ubuntu0.18.04.11+esm1, 0.27.2-8ubuntu2.7+esm1, 0.27.2-8ubuntu2.7+esm3, 0.27.5-3ubuntu1.1, 0.27.5-3ubuntu1.3, 0.27.6-1ubuntu0.1, 0.27.6-1ubuntu0.3, 0.28.5+dfsg-1ubuntu0.1, 0.28.5+dfsg-1ubuntu0.3
libexiv2-26-64bit-debuginfo - update to 0.26-150400.9.34.1
libexiv2-26-debuginfo - update to 0.26-150400.9.34.1
exiv2-0_26-debugsource - update to 0.26-150400.9.34.1
libexiv2-26 - update to 0.26-150400.9.34.1
libexiv2-26-32bit-debuginfo - update to 0.26-150400.9.34.1
libexiv2-26-32bit - update to 0.26-150400.9.34.1
libexiv2-26-64bit - update to 0.26-150400.9.34.1
exiv2 - update to 0.28.2-4
exiv2-debuginfo - update to 0.28.2-4
exiv2-debugsource - update to 0.28.2-4
exiv2-devel - update to 0.28.2-4
exiv2-help - update to 0.28.2-4
exiv2 - addressed in versions 0.28.6-1.fc41, 0.28.6-1.fc42, 0.28.6-1.fc43, 0.28.6-2.fc41, 0.28.6-2.fc42, 0.28.6-2.fc43
exiv2 - update to 0.28.7-1
exiv2-devel - update to 0.28.7-1
exiv2-libs - update to 0.28.7-1
exiv2-doc - update to 0.28.7-1
mingw-exiv2 - addressed in versions 0.28.7-1.fc41, 0.28.7-1.fc42
inih - addressed in versions 62-1.fc41, 62-1.fc42

External References

Related Security Bulletins