Release date:
2026-08-28 17:40:42 UTC
Description:
* SECURITY UPDATE: out-of-bounds read in the Nikon MakerNote printer
- debian/patches/CVE-2020-18771.patch: bound the nikonFocusarea[]
index in Nikon1MakerNote::print0x0088() with EXV_COUNTOF(), so a
crafted MakerNote cannot make the printer read a pointer from past
the end of the table (upstream 5e6c2855ce, via Debian DLA-3265-1).
- CVE-2020-18771
* SECURITY UPDATE: out-of-bounds read in the native preview loader
- debian/patches/CVE-2026-27596.patch: require sizeData >= 28 in
LoaderNative::getData() before subtracting 28, so a Photoshop
preview IRB declaring a shorter payload cannot wrap the length to
nearly 4 GB (upstream 2cb728a850).
- CVE-2026-27596
Updated packages:
-
exiv2_0.25-3.1ubuntu0.18.04.11+tuxcare.els2_amd64.deb
sha:9ad03425b2d04dd52593a0173c3ea96c6e301219
-
libexiv2-14_0.25-3.1ubuntu0.18.04.11+tuxcare.els2_amd64.deb
sha:0deefb4d1abb098dbb7de3edee0db4d51f0c4dbc
-
libexiv2-dev_0.25-3.1ubuntu0.18.04.11+tuxcare.els2_amd64.deb
sha:85a573b623b6974af20b2037454e20efdc82f9a4
-
libexiv2-doc_0.25-3.1ubuntu0.18.04.11+tuxcare.els2_all.deb
sha:c9fdaa7c5d3b6559ebdab568eb2f3179ec20cbbc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.