CVE-2025-55304Patch(exiv2 / exiv2)

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch exiv2 exiv2 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A denial-of-service was found in Exiv2 version 0.28.5: a quadratic algorithm in the ICC profile parsing code in jpegBase::readMetadata() can cause Exiv2 to run for a long time. The denial-of-service is triggered when Exiv2 is used to read the metadata of a crafted jpg image file. The bug is fixed in version 0.28.6.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-407

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • exiv2

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
exiv2

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-19: 2Patch / Workaround · 2026-03-19: 2Technical Details · 2026-03-19: 203-19
Signal classification1 categories
Patch
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Daniel Trekker@Dr_Knuth
    Patch

    Con razón me reventaba Okular 😂 exiv2 (0.27.6-1ubuntu0.3) noble-security; urgency=medium  * SECURITY REGRESSION: Segmentation Fault (LP: #2144731)   - Remove CVE-2025-55304 patches due to intrusive changes causing     a segmentation fault   - CVE-2025-55304

    Post summary

    The note reports that patches for CVE‑2025‑55304 were removed from exiv2 due to a regression that caused segmentation faults, indicating a patch‑related issue rather than active exploitation or proof of concept.

    10100292
    2.3K followersView on X
  • Daniel Trekker@Dr_Knuth
    Patch

    https://ubuntu.com/security/CVE-2025-55304

    Post summary

    The Ubuntu security advisory for CVE-2025-55304 outlines the vulnerability details and confirms that a patch is available, with no evidence of active exploitation or PoC.

    00000149
    2.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appexiv2exiv2---

Explore more