https://seclists.org/oss-sec/2026/q1/243: Exiv2 version 0.28.8 leased with fixes for 3 low-severity CVEs
Published Mar 2, 2026
·Updated
Affected Software
1 affected component
exiv2 exiv2
Frequently Asked Questions
1
What is the severity of CVE-2026-25884?
CVE-2026-25884 has a low severity rating due to the fact that it's only reproducible with a fuzz target, not with the standard exiv2 command-line application.
2
How do I fix CVE-2026-25884?
To fix CVE-2026-25884, update to Exiv2 version 0.28.8 or later.
3
What impact does CVE-2026-25884 have on Exiv2 usage?
CVE-2026-25884 leads to an out-of-bounds read, but its impact is minimal as it does not affect the common usage of Exiv2.
4
Is CVE-2026-25884 easy to exploit?
Exploiting CVE-2026-25884 is not straightforward as it only manifests during fuzz testing under specific conditions.
5
Who discovered CVE-2026-25884?
CVE-2026-25884 was discovered by researchers at Google.