Junglewise Threat Intelligence

CVE-2026-38332: TinyEXIF heap-based buffer over-read in EXIF parsing

CVE-2026-38332 · Severity: low · CVSS 2.9 · Published 2026-09-13

Executive brief

TinyEXIF is a library that parses EXIF metadata from JPEG images. A crafted image with a malicious SubjectArea tag can trigger a heap buffer over-read, potentially causing the application to read sensitive memory or crash. An attacker can exploit this by distributing a specially crafted JPEG file that applications using TinyEXIF will process.

Technical details

The vulnerability is a heap-based buffer over-read in the EntryParser::Fetch methods within TinyEXIF's EXIF parsing code. The root cause is insufficient bounds validation when parsing the SubjectArea tag (0x9214); the parser reads the length field directly from untrusted EXIF data without verifying it against the actual buffer size. When a crafted JPEG supplies an excessively large SubjectArea length (e.g., 0xFFFF = 65,535 bytes), the code resizes the SubjectArea array and loops to parse it, calling parse16() which reads past the end of the allocated heap buffer. The vulnerability is reachable via processing a malicious JPEG file—no authentication or user interaction beyond opening the image is required. An attacker can trigger an out-of-bounds read to leak heap memory or cause a denial of service. A fix has been available since March 19, 2026, implementing bounds validation in the Fetch methods.

Affected products

  • cdcseacave TinyEXIF before 1.1.0

Timeline

  • 2026-03-17: disclosed: Vulnerability reported on GitHub issue #24
  • 2026-03-19: patched: Fix merged in pull request #25
  • 2026-09-13: advisory: CVE-2026-38332 published

References