{"id":"SUSE-SU-2026:23871-1","summary":"Security update for exiv2","details":"This update for exiv2 fixes the following issues:\n\n- CVE-2026-49275: Out of bounds read in CrwMap::decodeBasic (bsc#1277791).\n- CVE-2026-68546: Heap out-of-bounds read in RemoteIo when reading block-aligned remote CRW files (bsc#1277579).\n- CVE-2026-68547: Heap out-of-bounds write in RemoteIo when reading from a malicious remote server (bsc#1277591).\n\nChanges for exiv2:\n\n- update to 0.28.9:\n * https://github.com/Exiv2/exiv2/security/advisories/GHSA-3695-mjv8-3r52\n * https://github.com/Exiv2/exiv2/security/advisories/GHSA-jcgh-p9v3-pw6j\n * https://github.com/Exiv2/exiv2/security/advisories/GHSA-hxph-pv7w-8649\n * https://github.com/Exiv2/exiv2/security/advisories/GHSA-vg6c-9f6h-4x5q\n * https://github.com/Exiv2/exiv2/security/advisories/GHSA-9v3x-mhg4-wwv2\n * https://github.com/Exiv2/exiv2/security/advisories/GHSA-fgw8-p7pr-37cp\n * https://github.com/Exiv2/exiv2/security/advisories/GHSA-pwvq-9w4q-786w\n","modified":"2026-09-27T18:23:17.187758902Z","published":"2026-09-22T07:21:58Z","related":["CVE-2026-49275","CVE-2026-68546","CVE-2026-68547"],"upstream":["CVE-2026-49275","CVE-2026-68546","CVE-2026-68547"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623871-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277579"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277591"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277791"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-49275"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-68546"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-68547"}],"affected":[{"package":{"name":"exiv2","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.28.9-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-28-x86-64-v3":"0.28.9-160000.1.1","libexiv2-28":"0.28.9-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23871-1.json"}},{"package":{"name":"exiv2","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.28.9-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-28":"0.28.9-160000.1.1","libexiv2-28-x86-64-v3":"0.28.9-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23871-1.json"}}],"schema_version":"1.9.0"}