Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-35590

Опубликовано: 20 июл. 2026
Источник: debian

Описание

libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing data to libexif, leading to a possible null pointer dereference and crash. This has been patched in version 8.18.2.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
vipsfixed8.18.2-1package

Примечания

  • https://github.com/libvips/libvips/security/advisories/GHSA-jmwm-wc68-mhwm

  • https://github.com/libvips/libvips/pull/4972

  • Fixed by: https://github.com/libvips/libvips/commit/91ebd4d35341a8353ea490392d556d582e4b846f (v8.18.2)

Связанные уязвимости

ubuntu
30 дней назад

libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing data to libexif, leading to a possible null pointer dereference and crash. This has been patched in version 8.18.2.

CVSS3: 5.5
redhat
30 дней назад

libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing data to libexif, leading to a possible null pointer dereference and crash. This has been patched in version 8.18.2.

nvd
30 дней назад

libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing data to libexif, leading to a possible null pointer dereference and crash. This has been patched in version 8.18.2.