PT-2026-22696 · Exiv2+2 · Exiv2+2

Kevinbackhouse

·

Published

2026-01-01

·

Updated

2026-03-23

·

CVE-2026-27631

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Exiv2 versions prior to 0.28.8
Description Exiv2 is a C++ library and a command-line utility used to read, write, delete, and modify image metadata (Exif, IPTC, XMP, and ICC). A flaw exists in the preview component where an integer overflow can occur when the utility is run with an extra command-line argument, such as -pp. This overflow leads to an attempt to create an excessively large std::vector, resulting in an uncaught exception and causing Exiv2 to crash.
Recommendations Versions prior to 0.28.8 should be updated to version 0.28.8 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-78527
AZL-78627
CVE-2026-27631
GHSA-P2PW-7935-C73J
OESA-2026-1564
OPENSUSE-SU-2026:10298-1
OPENSUSE-SU-2026:20410-1
SUSE-SU-2026:20923-1
USN-8103-1

Affected Products

Exiv2
Linuxmint
Ubuntu