CVE-2021-22204Patch(debian / debian_linux)

LOWCVSS 7.8 · HIGHCISA KEV

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch debian debian_linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image

1.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2021-12-01. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • exiftool
  • fedora

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclo: 1 classified signal
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-08-28)
  • 3 total mentions across 2 days

Affected systems

Products
debian_linuxexiftoolfedora

5 versions affected across 3 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-10: 1Mentions · 2026-08-28: 2Patch / Workaround · 2026-03-10: 1Technical Details · 2026-03-10: 1Technical Details · 2026-08-28: 203-1008-28
Signal classification3 categories
Patch
133.3%
Disclo
133.3%
General
133.3%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-03-101
Patch1
2026-08-282
Disclo1General1
Full discourse3 posts
  • NimaAshrafi@NimaAshrafi131
    Disclo

    4/ Key detail: CVE-2021-22204 = ExifTool CVE-2021-22205 = GitLab This vulnerability was rated CVSS 10.0 Critical.

    Post summary

    The post simply lists CVE-2021-22204 for ExifTool and CVE-2021-22205 for GitLab, noting a CVSS 10.0 Critical rating, but offers no additional technical, exploit, or remediation details.

    0003042
    14 followersView on X
  • NimaAshrafi@NimaAshrafi131
    General

    1/ GitLab used ExifTool to process metadata from uploaded files. But a vulnerability in ExifTool itself, CVE-2021-22204, allowed arbitrary code execution.

    Post summary

    The statement notes that GitLab uses ExifTool, and that CVE‑2021‑22204 in ExifTool permits arbitrary code execution, but provides no further details on PoC, exploitation, or remediation.

    0003078
    14 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical ExifTool vulnerability (CVE-2021-22204) allows remote code execution via malicious images. Update to version 12.24+ immediately to secure your systems. Link: https://thedailytechfeed.com/critical-exiftool-flaw-allows-remote-code-execution-via-malicious-images-prompt-update-advised/ #Security #Vulnerability #Update #Malware #Patch #Software #Threat #Hacking #Exploit #Protection #Attack #IT #Technology #System #Bug #Network #Data #Safety #Digital #Cyber

    Post summary

    The post announces CVE-2021-22204 in ExifTool, warns of remote code execution via malicious images, and urges users to upgrade to version 12.24+ to apply the patch.

    000007
    256 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux10.0--
OSdebiandebian_linux9.0--
Appexiftool_projectexiftool---
OSfedoraprojectfedora32--
OSfedoraprojectfedora33--
OSfedoraprojectfedora34--

Explore more