Out-of-bounds write in Exiv2 - #VU146328
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds write in RemoteIo::mmap when listing available image previews from a URL input. A remote attacker can provide a specially crafted image URL to cause a denial of service.
The issue affects the RemoteIo code path and is triggered when Exiv2 is run on a URL rather than a local file using the -pp command line option.