Linuxsecurity
Critical Exiv2 Vulnerabilities Affect Multiple Ubuntu Releases
Article Content
Multiple vulnerabilities have been discovered in Exiv2, a metadata manipulation tool, affecting various Ubuntu versions including 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, 24.04 LTS, and 25.10. Notably, CVE-2020-18771 and CVE-2020-18899 could allow attackers to leak sensitive information or cause denial of service by tricking users into opening specially crafted files. Additionally, CVE-2025-54080 and CVE-2025-55304 also pose denial of service risks. The vulnerabilities were reported by Wen Cheng and others, with several CVEs published on 2026-03-02. Users are advised to update their systems to mitigate these risks. The issues primarily affect older and newer LTS versions of Ubuntu, indicating a broad impact across supported systems. The current status is that patches are available for the affected versions.
Key Points: • Exiv2 vulnerabilities affect Ubuntu 16.04, 18.04, 20.04, 22.04, 24.04, and 25.10. • CVE-2020-18771 and CVE-2020-18899 can lead to information leakage and denial of service. • Patches are available for all affected Ubuntu versions to address these vulnerabilities.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.