OESA-2026-3890

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-3890
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-3890.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-3890
Upstream
CVE (3)
  • CVE-2026-49275
  • CVE-2026-68546
  • CVE-2026-68547
Published
2026-09-20T13:22:57Z
Modified
2026-09-20T13:30:22Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
exiv2 security update
Details

Exiv2 is a Cross-platform C++ library and a command line utility to manage image metadata. It provides fast and easy read and write access to the Exif, IPTC and XMP metadata and the ICC Profile embedded within digital images in various formats.

Security Fix(es):

Exiv2 has an out-of-bounds read vulnerability in the CrwMap::decodeBasic() function in versions 0.28.8 and earlier. This vulnerability was discovered by OSS-Fuzz and can be reproduced through the fuzz testing target, but currently cannot be reproduced through the exiv2 command line application. The affected Snyk trace is the exiv2 package in the Alpine 3.24 release (SNYK-ALPINE324-EXIV2-19432405).(CVE-2026-49275)

Exiv2 discovered a heap out-of-bounds write vulnerability in the RemoteIo::Impl::populateBlocks() function in versions 0.28.8 and earlier. The vulnerability is located in the RemoteIo class and is only triggered when Exiv2 handles a remote resource through a URL (not a local file), such as exiv2 https://dodgywebsite.com/poc.jpg. This vulnerability only affects WebReady or Exiv2 binaries built with Curl. The affected Snyk trace is the exiv2 package in the Alpine 3.24 release (SNYK-ALPINE324-EXIV2-19432403). Reported by zenniskayy2k4.(CVE-2026-68546)

Exiv2 discovered a heap out-of-bounds read vulnerability (off-by-one) in the RemoteIo::Impl::populateBlocks() function in versions 0.28.8 and earlier. The vulnerability is located in the RemoteIo class and is only triggered when Exiv2 handles a remote resource through a URL (not a local file), such as exiv2 https://dodgywebsite.com/poc.jpg. The root cause is related to reading a block-aligned remote CRW file. The affected Snyk trace is the exiv2 package in the Alpine 3.24 release (SNYK-ALPINE324-EXIV2-19432401). Reported by Mmandysa.(CVE-2026-68547)

Database specific
{
    "severity":  "Critical"
}
References

Affected packages

openEuler:24.03-LTS-SP1 / exiv2

Package

Name
exiv2
Purl
pkg:rpm/openEuler/exiv2&distro=openEuler-24.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.28.2-10.oe2403sp1

Ecosystem specific

{
    "aarch64":  [
        "exiv2-0.28.2-10.oe2403sp1.aarch64.rpm",
        "exiv2-debuginfo-0.28.2-10.oe2403sp1.aarch64.rpm",
        "exiv2-debugsource-0.28.2-10.oe2403sp1.aarch64.rpm",
        "exiv2-devel-0.28.2-10.oe2403sp1.aarch64.rpm"
    ],
    "noarch":  [
        "exiv2-help-0.28.2-10.oe2403sp1.noarch.rpm"
    ],
    "src":  [
        "exiv2-0.28.2-10.oe2403sp1.src.rpm"
    ],
    "x86_64":  [
        "exiv2-0.28.2-10.oe2403sp1.x86_64.rpm",
        "exiv2-debuginfo-0.28.2-10.oe2403sp1.x86_64.rpm",
        "exiv2-debugsource-0.28.2-10.oe2403sp1.x86_64.rpm",
        "exiv2-devel-0.28.2-10.oe2403sp1.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3890.json"