CVE-2019-9640: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 6.2% chance of exploitation in the next 30 days.

An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an Invalid Read in exif_process_SOFn.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Netapp Storage Automation Store: affected versions not specified
  • Opensuse Leap: version 15.0 only; version 15.1 only; version 42.3 only
  • PHP PHP: from 7.1.0, before 7.1.27 (fixed in 7.1.27); from 7.2.0, before 7.2.16 (fixed in 7.2.16); from 7.3.0, before 7.3.3 (fixed in 7.3.3)
  • Red Hat Software Collections: version 1.0 only

Published 2019-03-09. Last modified 2026-06-17.