CVE-2019-9278: Canonical Ubuntu Linux

High severity, CVSS 8.8. EPSS: 4.1% chance of exploitation in the next 30 days.

In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112537774

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 19.10 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Fedoraproject Fedora: version 31 only; version 32 only
  • Google Android: version 10.0 only
  • Opensuse Leap: version 15.1 only

Published 2019-09-27. Last modified 2026-06-17.