CVE-2019-9641: Canonical Ubuntu Linux

Critical severity, CVSS 9.8. EPSS: 9.4% chance of exploitation in the next 30 days.

An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Netapp Storage Automation Store: affected versions not specified
  • Opensuse Leap: version 15.0 only; version 15.1 only; version 42.3 only
  • PHP PHP: before 7.1.27 (fixed in 7.1.27); from 7.2.0, before 7.2.16 (fixed in 7.2.16); from 7.3.0, before 7.3.3 (fixed in 7.3.3)

Published 2019-03-09. Last modified 2026-06-17.