Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-35590

Опубликовано: 20 июл. 2026
Источник: redhat
CVSS3: 5.5

Описание

libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing data to libexif, leading to a possible null pointer dereference and crash. This has been patched in version 8.18.2.

A flaw was found in libvips. The EXIF decoder did not properly verify the range of EXIF tag groups, which could lead to a null pointer dereference. A local user could exploit this by providing specially crafted EXIF data, causing the application to crash and resulting in a denial of service.

Отчет

This Moderate severity flaw in libvips' EXIF decoder allows a local attacker to trigger a denial of service. By providing a specially crafted image file containing malformed EXIF data, an application utilizing libvips can crash due to a null pointer dereference. This impact is limited to scenarios where untrusted image input is processed.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2502887libvips: libvips: Denial of Service vulnerability in EXIF decoder

5.5 Medium

CVSS3

Связанные уязвимости

ubuntu
30 дней назад

libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing data to libexif, leading to a possible null pointer dereference and crash. This has been patched in version 8.18.2.

nvd
30 дней назад

libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing data to libexif, leading to a possible null pointer dereference and crash. This has been patched in version 8.18.2.

debian
30 дней назад

libvips is a fast image processing library with low memory needs. The ...

5.5 Medium

CVSS3