Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-0493

NIXPKGS-2026-0493
published 3 months, 3 weeks ago
updated 3 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    10 packages
    • gexiv2
    • libsForQt5.libkexiv2
    • kdePackages.libkexiv2
    • python312Packages.exiv2
    • python313Packages.exiv2
    • python314Packages.exiv2
    • plasma5Packages.libkexiv2
    • python312Packages.py3exiv2
    • python313Packages.py3exiv2
    • python314Packages.py3exiv2
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Exiv2: Out-of-bounds read in CrwMap::decode0x0805

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-bounds read was found. The vulnerability is in the CRW image parser. This issue has been patched in version 0.28.8.

Affected products

exiv2
  • ==< 0.28.8

Matching in nixpkgs

pkgs.exiv2

Library and command-line utility to manage image metadata

Ignored packages (10)

pkgs.gexiv2

GObject wrapper around the Exiv2 photo metadata library

Package maintainers

Upstream advisory: https://github.com/Exiv2/exiv2/security/advisories/GHSA-9mxq-4j5g-5wrp
Upstream patch: https://github.com/Exiv2/exiv2/commit/cbba4d206512fe63e12d164fdd1881562f072a9d