Critical Exiv2 Vulnerabilities Affect Multiple Ubuntu Releases

Critical Exiv2 Vulnerabilities Affect Multiple Ubuntu Releases

First seen 19 Mar 2026, 04:57 UTC UbuntuLinuxsecurity 57.8

Article Content

Browse articles
ThreatCluster

Multiple vulnerabilities have been discovered in Exiv2, a metadata manipulation tool, affecting various Ubuntu versions including 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, 24.04 LTS, and 25.10. Notably, CVE-2020-18771 and CVE-2020-18899 could allow attackers to leak sensitive information or cause denial of service by tricking users into opening specially crafted files. Additionally, CVE-2025-54080 and CVE-2025-55304 also pose denial of service risks. The vulnerabilities were reported by Wen Cheng and others, with several CVEs published on 2026-03-02. Users are advised to update their systems to mitigate these risks. The issues primarily affect older and newer LTS versions of Ubuntu, indicating a broad impact across supported systems. The current status is that patches are available for the affected versions.

Key Points: • Exiv2 vulnerabilities affect Ubuntu 16.04, 18.04, 20.04, 22.04, 24.04, and 25.10. • CVE-2020-18771 and CVE-2020-18899 can lead to information leakage and denial of service. • Patches are available for all affected Ubuntu versions to address these vulnerabilities.

Timeline

2021-08-19
CVE-2020-18899 published
2021-08-23
CVE-2020-18771 published
2025-08-29
CVE-2025-54080 published
2025-08-29
CVE-2025-55304 published
2026-03-02
CVE-2026-25884 published
2026-03-02
CVE-2026-27596 published
2026-03-02
CVE-2026-27631 published
2026-03-18
Ubuntu security announcement USN-8103-1 released