CVE-2026-35590

NameCVE-2026-35590
Descriptionlibvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing data to libexif, leading to a possible null pointer dereference and crash. This has been patched in version 8.18.2.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
vips (PTS)bullseye8.10.5-2vulnerable
bullseye (security)8.10.5-2+deb11u1vulnerable
bookworm8.14.1-3+deb12u3vulnerable
bookworm (security)8.14.1-3+deb12u2vulnerable
trixie8.16.1-1+deb13u1vulnerable
forky, sid8.18.4-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
vipssource(unstable)8.18.2-1

Notes

https://github.com/libvips/libvips/security/advisories/GHSA-jmwm-wc68-mhwm
https://github.com/libvips/libvips/pull/4972
Fixed by: https://github.com/libvips/libvips/commit/91ebd4d35341a8353ea490392d556d582e4b846f (v8.18.2)

Search for package or bug name: Reporting problems