[CLSA-2026:1787932207] Fix CVE(s): CVE-2020-18771, CVE-2026-27596
Type:
security
Severity:
Important
Release date:
2026-08-28 17:40:42 UTC
Description:
* SECURITY UPDATE: out-of-bounds read in the Nikon MakerNote printer - debian/patches/CVE-2020-18771.patch: bound the nikonFocusarea[] index in Nikon1MakerNote::print0x0088() with EXV_COUNTOF(), so a crafted MakerNote cannot make the printer read a pointer from past the end of the table (upstream 5e6c2855ce, via Debian DLA-3265-1). - CVE-2020-18771 * SECURITY UPDATE: out-of-bounds read in the native preview loader - debian/patches/CVE-2026-27596.patch: require sizeData >= 28 in LoaderNative::getData() before subtracting 28, so a Photoshop preview IRB declaring a shorter payload cannot wrap the length to nearly 4 GB (upstream 2cb728a850). - CVE-2026-27596
Updated packages:
  • exiv2_0.25-3.1ubuntu0.18.04.11+tuxcare.els2_amd64.deb
    sha:9ad03425b2d04dd52593a0173c3ea96c6e301219
  • libexiv2-14_0.25-3.1ubuntu0.18.04.11+tuxcare.els2_amd64.deb
    sha:0deefb4d1abb098dbb7de3edee0db4d51f0c4dbc
  • libexiv2-dev_0.25-3.1ubuntu0.18.04.11+tuxcare.els2_amd64.deb
    sha:85a573b623b6974af20b2037454e20efdc82f9a4
  • libexiv2-doc_0.25-3.1ubuntu0.18.04.11+tuxcare.els2_all.deb
    sha:c9fdaa7c5d3b6559ebdab568eb2f3179ec20cbbc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.