Executive brief
jhead is a command-line utility used to read and manipulate EXIF metadata from image files. A heap buffer overflow vulnerability in the GPS EXIF processing function allows an attacker to craft a malicious WebP image file that, when processed by jhead, reads memory beyond allocated buffer boundaries. This can lead to information disclosure or cause the application to crash, disrupting automated image processing workflows.
Technical details
The vulnerability is a heap-based buffer over-read in the ProcessGpsInfo function (gpsinfo.c:144) when parsing GPS latitude/longitude rational values from WebP EXIF chunks. The root cause is insufficient bounds checking on ValuePtr before calling Get32s to read 4-byte values—the code does not validate that ValuePtr+offset remains within the allocated EXIF buffer range. An attacker can supply a crafted WebP file with a malformed EXIF GPS sub-directory where ValuePtr points past the buffer boundary, triggering an out-of-bounds read. The attack requires only local file access (no network or authentication); the vulnerability is triggered during normal file processing. An attacker can achieve information disclosure (reading adjacent heap memory) or denial of service (crash via AddressSanitizer or similar protections). No patch has been publicly released; the project maintainer was notified but has not yet responded.
Affected products
- Matthias-Wandel jhead up to 3.3
Timeline
- 2026-07-27: disclosed: Vulnerability reported via GitHub issue #99
- 2026-09-14: advisory: CVE-2026-90682 published