Skip to content
Critical Exiv2 Vulnerabilities Affect Multiple Ubuntu Releases

Critical Exiv2 Vulnerabilities Affect Multiple Ubuntu Releases

First seen 19 Mar 2026, 04:57 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 20, 2026 at 04:57 UTC

Multiple vulnerabilities have been discovered in Exiv2, a metadata manipulation tool, affecting various Ubuntu versions including 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, 24.04 LTS, and 25.10. Notably, CVE-2020-18771 and CVE-2020-18899 could allow attackers to leak sensitive information or cause denial of service by tricking users into opening specially crafted files. Additionally, CVE-2025-54080 and CVE-2025-55304 also pose denial of service risks. The vulnerabilities were reported by Wen Cheng and others, with several CVEs published on 2026-03-02. Users are advised to update their systems to mitigate these risks. The issues primarily affect older and newer LTS versions of Ubuntu, indicating a broad impact across supported systems. The current status is that patches are available for the affected versions.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 205d ago How this analysis works

Timeline

2021-08-19
CVE-2020-18899 published
2021-08-23
CVE-2020-18771 published
2025-08-29
CVE-2025-54080 published
2025-08-29
CVE-2025-55304 published
2026-03-02
CVE-2026-25884 published
2026-03-02
CVE-2026-27596 published
2026-03-02
CVE-2026-27631 published
2026-03-18
Ubuntu security announcement USN-8103-1 released

More articles in this cluster (3)

Following this threat?

Track Ubuntu and CVE-2020-18771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed