Out-of-bounds write in Exiv2 - CVE-2026-68546
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds write in RemoteIo::Impl::populateBlocks when reading data from a malicious remote server through a URL input. A remote attacker can serve a specially crafted file from a malicious remote server to cause a denial of service.
The issue affects the RemoteIo class and can be triggered only when Exiv2 is run on a URL rather than a local file.