Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-49275
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-49275 is an out-of-bounds read vulnerability in the CrwMap::decodeBasic() function of Exiv2, an open-source C++ library for image metadata manipulation. It affects all Exiv2 versions up to and including 0.28.8, with version 0.28.9 containing the fix. The vulnerability was discovered by OSS-Fuzz and publicly disclosed on August 30, 2026 via a GitHub Security Advisory. It carries a Low severity rating (CVSS estimate: Medium per Feedly) (GitHub Advisory).

Technical details

The root cause is an out-of-bounds read (CWE-125) in the CrwMap::decodeBasic() function within the Exiv2 library, triggered when processing malformed CRW (Canon Raw) image files. The bug was identified through OSS-Fuzz fuzzing of Exiv2's fuzz targets, and while it is reproducible via the library's fuzz harness, the Exiv2 maintainers have noted they were unable to reproduce it using the standard exiv2 command-line application, suggesting exploitation may require crafted input passed directly through the library API. The vulnerability involves reading data past the end of an intended buffer during CRW metadata decoding (GitHub Advisory, OSS-Sec).

Impact

Successful exploitation of this out-of-bounds read could allow an attacker to read memory beyond the intended buffer boundaries during CRW image metadata parsing, potentially exposing sensitive in-process memory contents. The practical impact is assessed as Low by the Exiv2 maintainers, as the bug has not been demonstrated to be exploitable via the command-line tool and may be limited to applications that directly invoke the affected library function with attacker-controlled input. Availability impact (e.g., crash/denial of service) is also possible if the out-of-bounds read triggers an access violation (GitHub Advisory).

Exploitability

There are no known public proof-of-concept exploits, exploit kits, or reports of in-the-wild exploitation for CVE-2026-49275. The vulnerability was found through automated fuzzing (OSS-Fuzz) and has not been added to the CISA Known Exploited Vulnerabilities catalog. No EPSS score data is currently available, and no threat actor attribution has been reported (GitHub Advisory, OSS-Sec).

Mitigation and workarounds

Exiv2 has released version 0.28.9, which patches this vulnerability. Users and downstream distributors (including Debian and Mageia, which have issued their own advisories) should upgrade to Exiv2 0.28.9 or later as soon as possible. No configuration-based workarounds have been published; upgrading to the patched version is the recommended remediation (GitHub Advisory, OSV Debian, OSV Mageia).

Community reactions

The vulnerability was disclosed by Exiv2 maintainer kevinbackhouse via a GitHub Security Advisory rated Low severity, with the maintainers explicitly noting the limited exploitability via the command-line application. Downstream Linux distributions including Debian and Mageia have issued their own advisories and package updates. No significant broader media coverage or notable researcher commentary beyond the initial disclosure has been observed (GitHub Advisory, OSS-Sec).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

exiv2

Affected

sid

exiv2: 0.28.9+dfsg-1

Fixed

trixie

exiv2

Affected

Ubuntu

Unknown

bionic (esm-infra)

exiv2

Unknown

devel

exiv2

Unknown

focal (esm-infra)

exiv2

Unknown

jammy

exiv2

Unknown

noble

exiv2

Unknown

resolute

exiv2

Unknown

xenial (esm-infra-legacy)

exiv2

Unknown

Alpine

Fixed

edge

exiv2: 0.28.9-r0

Fixed

SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93574MEDIUM6.5
  • Linux Debian logoLinux Debian
  • netty
NoNoSep 18, 2026
CVE-2026-93562MEDIUM6.5
  • Linux Debian logoLinux Debian
  • netty
NoNoSep 18, 2026
CVE-2026-93894LOW2.3
  • Linux Debian logoLinux Debian
  • varnish
NoNoSep 18, 2026
CVE-2026-82560NONEN/A
  • Linux Debian logoLinux Debian
  • perl
NoNoSep 19, 2026
CVE-2026-78030NONEN/A
  • Linux Debian logoLinux Debian
  • perl-DBI
NoYesSep 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management