|
|
Log in / Subscribe / Register

Ubuntu alert USN-8103-2 (exiv2)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8103-2] Exiv2 regression
Date:  Thu, 19 Mar 2026 22:10:47 +0000
Message-ID:  <E1w3LZn-0006lG-Oy@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-8103-2 March 19, 2026 exiv2 regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: USN-8103-1 introduced a regression in Exiv2 Software Description: - exiv2: EXIF/IPTC/XMP metadata manipulation tool Details: USN-8103-1 fixed vulnerabilities in Exiv2. The update caused a regression for Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 25.10. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that Exiv2 did not correctly handle reading certain buffers. An attacker could possibly use this issue to leak sensitive information. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2020-18771) Wen Cheng discovered that Exiv2 did not correctly handle certain memory allocation. If a user or system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2020-18899) It was discovered that Exiv2 did not correctly handle writing certain metadata. If a user or system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. (CVE-2025-54080) It was discovered that Exiv2 did not correctly handle parsing certain metadata. If a user or system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 25.10. (CVE-2025-55304) It was discovered that Exiv2 did not correctly handle parsing certain images. If a user or system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. (CVE-2026-25884) It was discovered that Exiv2 did not correctly handle previewing certain images. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-27596) It was discovered that Exiv2 did not correctly handle certain integer arithmetic. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-27631) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 exiv2 0.28.5+dfsg-1ubuntu0.3 libexiv2-28 0.28.5+dfsg-1ubuntu0.3 libexiv2-dev 0.28.5+dfsg-1ubuntu0.3 Ubuntu 24.04 LTS exiv2 0.27.6-1ubuntu0.3 libexiv2-27 0.27.6-1ubuntu0.3 libexiv2-dev 0.27.6-1ubuntu0.3 Ubuntu 22.04 LTS exiv2 0.27.5-3ubuntu1.3 libexiv2-27 0.27.5-3ubuntu1.3 libexiv2-dev 0.27.5-3ubuntu1.3 Ubuntu 20.04 LTS exiv2 0.27.2-8ubuntu2.7+esm3 Available with Ubuntu Pro libexiv2-27 0.27.2-8ubuntu2.7+esm3 Available with Ubuntu Pro libexiv2-dev 0.27.2-8ubuntu2.7+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8103-2 https://ubuntu.com/security/notices/USN-8103-1 CVE-2025-55304, https://bugs.launchpad.net/ubuntu/+source/gimp/+bug/2144731 Package Information: https://launchpad.net/ubuntu/+source/exiv2/0.28.5+dfsg-1u... https://launchpad.net/ubuntu/+source/exiv2/0.27.6-1ubuntu0.3 https://launchpad.net/ubuntu/+source/exiv2/0.27.5-3ubuntu1.3


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmm8c/kACgkQcpJm3tlz hgGSXBAAgmcv5N+TC+pFFFJ7KJhMSLYHvOmnGr11tWibPGyyeVAi4AozNSMEzdoK xnT+wYwlAxZkllaI5irUwRS3goGLYr2LHNtT8hlMWTj0Zy1372myzxbQIo3EYKwT 5B26+eSNQaWLwwuS2EIS6nOFD1GSeNvsdKPRX7rn2CX5vchv27AcBOerNtcYCRT7 eTuEUp46em9Nz7rc6jiAjSRWSytW33gbb3LJ+8IQturyk1wYvBpktCohbzv4athR GVt3f2YAH2gayrsWGnvy/HiFNi3oo+JBzyBgbw6zVfoYirxCwLYv5RF48KjWLvzj vWRmW9u0/6RU/aEPJV0bxaN2M+XnkWuy/DaDlh65IYUko+VybiJK5+wEZVUQNow8 sgdQ4eoPRdJY23zXyLoHGLKZNGzTuw+rwemFx9+OAI2j3zJ1hwM0l3mxA0oiTAHs QCW8rfpbTM/CJGcpA41SdwWUJ6MOLWmMgq7lj1B4YZpPsQwooTClf1ptPZ1bevdk /+EW0uwE4/8PiCfzGIediUt0gWVqEb7K56ebWckB6+V/+IDZ5mQhjIwGfyA6KdQV 1fwUEj6OgjyyuVJaMgYz79rj/pnSKQguYZPRQuj+JYw//MKIuSKrmZWQIF/VPFte HDaRGvMi7Xef+u24Ntj4F182ZyTbl5M8I2ELvPxVnUMhnfMKkIU= =bis+ -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds