CVE-2016-6328: Canonical Ubuntu Linux

High severity, CVSS 8.1. EPSS: 1.7% chance of exploitation in the next 30 days.

A vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can cause Denial-of-Service (DoS) and Information Disclosure (disclosing some critical heap chunk metadata, even other applications' private data).

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 19.10 only
  • Debian Debian Linux: version 8.0 only
  • Libexif Project Libexif: before 0.6.22 (fixed in 0.6.22)

Published 2018-10-31. Last modified 2026-06-17.