Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2663-1

Опубликовано: 26 июн. 2026
Источник: suse-cvrf

Описание

Security update for exiv2

This update for exiv2 fixes the following issues

  • CVE-2025-54080: out-of-bounds read in Exiv2::EpsImage::writeMetadata() when writing metadata into a crafted image file (bsc#1248962).
  • CVE-2026-25884: out-of-bounds read in CrwMap::decode0x0805 (bsc#1259083).
  • CVE-2026-27596: integer overflow in LoaderNative::getData() leads to out-of-bounds read (bsc#1259084).
  • CVE-2026-27631: crash due to uncaught exception when trying to create std::vector larger than max_size() (bsc#1259085).

Список пакетов

SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
libexiv2-12-0.23-12.26.1
libexiv2-devel-0.23-12.26.1

Описание

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions 0.28.5 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. The bug is fixed in version 0.28.6.


Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libexiv2-12-0.23-12.26.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libexiv2-devel-0.23-12.26.1

Ссылки

Описание

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-bounds read was found. The vulnerability is in the CRW image parser. This issue has been patched in version 0.28.8.


Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libexiv2-12-0.23-12.26.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libexiv2-devel-0.23-12.26.1

Ссылки

Описание

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-bounds read was found in Exiv2. The vulnerability is in the preview component, which is only triggered when running Exiv2 with an extra command line argument, like -pp. The out-of-bounds read is at a 4GB offset, which usually causes Exiv2 to crash. This issue has been patched in version 0.28.8.


Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libexiv2-12-0.23-12.26.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libexiv2-devel-0.23-12.26.1

Ссылки

Описание

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an uncaught exception was found in Exiv2. The vulnerability is in the preview component, which is only triggered when running Exiv2 with an extra command line argument, like -pp. Due to an integer overflow, the code attempts to create a huge std::vector, which causes Exiv2 to crash with an uncaught exception. This issue has been patched in version 0.28.8.


Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libexiv2-12-0.23-12.26.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libexiv2-devel-0.23-12.26.1

Ссылки