Ubuntu alert USN-8103-1 (exiv2)
| From: | noreply+usn-bot@canonical.com | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8103-1] Exiv2 vulnerabilities | |
| Date: | Wed, 18 Mar 2026 22:08:25 +0000 | |
| Message-ID: | <E1w2z3x-0003sC-5q@lists.ubuntu.com> |
========================================================================== Ubuntu Security Notice USN-8103-1 March 18, 2026 exiv2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Exiv2. Software Description: - exiv2: EXIF/IPTC/XMP metadata manipulation tool Details: It was discovered that Exiv2 did not correctly handle reading certain buffers. An attacker could possibly use this issue to leak sensitive information. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2020-18771) Wen Cheng discovered that Exiv2 did not correctly handle certain memory allocation. If a user or system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2020-18899) It was discovered that Exiv2 did not correctly handle writing certain metadata. If a user or system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. (CVE-2025-54080) It was discovered that Exiv2 did not correctly handle parsing certain metadata. If a user or system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 25.10. (CVE-2025-55304) It was discovered that Exiv2 did not correctly handle parsing certain images. If a user or system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. (CVE-2026-25884) It was discovered that Exiv2 did not correctly handle previewing certain images. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-27596) It was discovered that Exiv2 did not correctly handle certain integer arithmetic. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-27631) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 exiv2 0.28.5+dfsg-1ubuntu0.1 Ubuntu 24.04 LTS exiv2 0.27.6-1ubuntu0.1 Ubuntu 22.04 LTS exiv2 0.27.5-3ubuntu1.1 Ubuntu 20.04 LTS exiv2 0.27.2-8ubuntu2.7+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS exiv2 0.25-3.1ubuntu0.18.04.11+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS exiv2 0.25-2.1ubuntu16.04.7+esm5 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8103-1 CVE-2020-18771, CVE-2020-18899, CVE-2025-54080, CVE-2025-55304, CVE-2026-25884, CVE-2026-27596, CVE-2026-27631 Package Information: https://launchpad.net/ubuntu/+source/exiv2/0.28.5+dfsg-1u... https://launchpad.net/ubuntu/+source/exiv2/0.27.6-1ubuntu0.1 https://launchpad.net/ubuntu/+source/exiv2/0.27.5-3ubuntu1.1
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmm7IaAACgkQcpJm3tlz hgH2eg/5ATuTR6CYFosAIoyWO0WvEpN6s05phHEfRQX9KgM+/Z65II1jxPoAgvD9 fKiJBiuFCvcnD0GrUgLcAZ9nZqvNhOmAoYgrijS3m8mN3axjEVRcizra2oJCaR5W 4kklG4Uj1Ksm7Jinif1lhNIK4gp2Y069BMhE+VWB2yfj9yUCxrrDpMzNnRRluRv6 /Gkmue3PZUNHNsEZpI7kQBvx1NdC2fMVsyS3oDkeYA2tW2Hc8lqtvlEwV4AvKyvE 9XiukgyEpTw7m15HHooRa80M7HhBrTEFuKmfoa5M+s615jef8tpGT4Mzv1jRQskz ud+i0RfXLOe1tB2zi3QNs5zI6RFYMxg1BliU0KfW2bc41XGeVUD3nVsqw4D3IAiM JiikaZidRQBQLSh/5j9hI5GThD+L5yUPHSVFxJd9F/O8WN3oyNzj0XDWYhLZboeS orL4lFP5UmC3/gI0bVLwvwo070evB6DxS7eJ0N9MNEMFXdKmENYKOCkYwG1C5oRZ 6ZROZLyJ92A4KA9FFUxkf6Dm5CI6clSeY9kkgy8rkCuqK8Zflhv+KC1pwD5vdQBe jya+N6HhHlYib09YnABEIctL6lC/um22fGMUGdDkgfiVN2CNZi1qOnjgnCegNJBE rwnCa7NcgDiBXmuSKm6ruTkL8UTRIFmd9v47ZaPJHlTpvIUqtGM= =ycHk -----END PGP SIGNATURE-----
