{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Low"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "DoS due to infinite loop in JpegBase::printStructure",
    "tracking": {
      "current_release_date": "2026-08-11T14:59:33+00:00",
      "generator": {
        "date": "2026-08-11T14:59:33+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2021-37622",
      "initial_release_date": "2021-08-08T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T14:59:33+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 6-els",
            "product": {
              "name": "Red Hat Enterprise Linux 6-els",
              "product_id": "rhel-6-els.els",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:rhel_els:6"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 7-els",
            "product": {
              "name": "Red Hat Enterprise Linux 7-els",
              "product_id": "rhel-7-els.els",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:rhel_els:7"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 8.10.z",
            "product": {
              "name": "Red Hat Enterprise Linux 8.10.z",
              "product_id": "rhel-8",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:enterprise_linux:8"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 9.0",
            "product": {
              "name": "Red Hat Enterprise Linux 9.0",
              "product_id": "rhel-9.0",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:enterprise_linux:9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "compat-exiv2-023",
            "product": {
              "name": "compat-exiv2-023",
              "product_id": "compat-exiv2-023",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/compat-exiv2-023"
              }
            }
          },
          {
            "category": "product_version",
            "name": "compat-exiv2-023-debuginfo",
            "product": {
              "name": "compat-exiv2-023-debuginfo",
              "product_id": "compat-exiv2-023-debuginfo",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/compat-exiv2-023-debuginfo"
              }
            }
          },
          {
            "category": "product_version",
            "name": "compat-exiv2-023",
            "product": {
              "name": "compat-exiv2-023",
              "product_id": "compat-exiv2-023.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/compat-exiv2-023?arch=src"
              }
            }
          },
          {
            "category": "product_version",
            "name": "compat-exiv2-026",
            "product": {
              "name": "compat-exiv2-026",
              "product_id": "compat-exiv2-026",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/compat-exiv2-026"
              }
            }
          },
          {
            "category": "product_version",
            "name": "compat-exiv2-026-debuginfo",
            "product": {
              "name": "compat-exiv2-026-debuginfo",
              "product_id": "compat-exiv2-026-debuginfo",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/compat-exiv2-026-debuginfo"
              }
            }
          },
          {
            "category": "product_version",
            "name": "compat-exiv2-026",
            "product": {
              "name": "compat-exiv2-026",
              "product_id": "compat-exiv2-026.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/compat-exiv2-026?arch=src"
              }
            }
          },
          {
            "category": "product_version",
            "name": "exiv2",
            "product": {
              "name": "exiv2",
              "product_id": "exiv2",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/exiv2"
              }
            }
          },
          {
            "category": "product_version",
            "name": "exiv2-debuginfo",
            "product": {
              "name": "exiv2-debuginfo",
              "product_id": "exiv2-debuginfo",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/exiv2-debuginfo"
              }
            }
          },
          {
            "category": "product_version",
            "name": "exiv2-devel",
            "product": {
              "name": "exiv2-devel",
              "product_id": "exiv2-devel",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/exiv2-devel"
              }
            }
          },
          {
            "category": "product_version",
            "name": "exiv2-doc",
            "product": {
              "name": "exiv2-doc",
              "product_id": "exiv2-doc",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/exiv2-doc"
              }
            }
          },
          {
            "category": "product_version",
            "name": "exiv2-libs",
            "product": {
              "name": "exiv2-libs",
              "product_id": "exiv2-libs",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/exiv2-libs"
              }
            }
          },
          {
            "category": "product_version",
            "name": "exiv2",
            "product": {
              "name": "exiv2",
              "product_id": "exiv2.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/exiv2?arch=src"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "compat-exiv2-023 as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:compat-exiv2-023"
        },
        "product_reference": "compat-exiv2-023",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "compat-exiv2-023-debuginfo as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:compat-exiv2-023-debuginfo"
        },
        "product_reference": "compat-exiv2-023-debuginfo",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "compat-exiv2-023.src as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:compat-exiv2-023.src"
        },
        "product_reference": "compat-exiv2-023.src",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "compat-exiv2-026 as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:compat-exiv2-026"
        },
        "product_reference": "compat-exiv2-026",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "compat-exiv2-026 as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:compat-exiv2-026"
        },
        "product_reference": "compat-exiv2-026",
        "relates_to_product_reference": "rhel-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "compat-exiv2-026-debuginfo as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:compat-exiv2-026-debuginfo"
        },
        "product_reference": "compat-exiv2-026-debuginfo",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "compat-exiv2-026.src as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:compat-exiv2-026.src"
        },
        "product_reference": "compat-exiv2-026.src",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "compat-exiv2-026.src as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:compat-exiv2-026.src"
        },
        "product_reference": "compat-exiv2-026.src",
        "relates_to_product_reference": "rhel-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2 as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:exiv2"
        },
        "product_reference": "exiv2",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2 as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:exiv2"
        },
        "product_reference": "exiv2",
        "relates_to_product_reference": "rhel-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2 as a component of Red Hat Enterprise Linux 9.0",
          "product_id": "rhel-9.0:exiv2"
        },
        "product_reference": "exiv2",
        "relates_to_product_reference": "rhel-9.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2 as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:exiv2"
        },
        "product_reference": "exiv2",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2-debuginfo as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:exiv2-debuginfo"
        },
        "product_reference": "exiv2-debuginfo",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2-debuginfo as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:exiv2-debuginfo"
        },
        "product_reference": "exiv2-debuginfo",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2-devel as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:exiv2-devel"
        },
        "product_reference": "exiv2-devel",
        "relates_to_product_reference": "rhel-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2-devel as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:exiv2-devel"
        },
        "product_reference": "exiv2-devel",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2-devel as a component of Red Hat Enterprise Linux 9.0",
          "product_id": "rhel-9.0:exiv2-devel"
        },
        "product_reference": "exiv2-devel",
        "relates_to_product_reference": "rhel-9.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2-devel as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:exiv2-devel"
        },
        "product_reference": "exiv2-devel",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2-doc as a component of Red Hat Enterprise Linux 9.0",
          "product_id": "rhel-9.0:exiv2-doc"
        },
        "product_reference": "exiv2-doc",
        "relates_to_product_reference": "rhel-9.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2-doc as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:exiv2-doc"
        },
        "product_reference": "exiv2-doc",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2-doc as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:exiv2-doc"
        },
        "product_reference": "exiv2-doc",
        "relates_to_product_reference": "rhel-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2-libs as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:exiv2-libs"
        },
        "product_reference": "exiv2-libs",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2-libs as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:exiv2-libs"
        },
        "product_reference": "exiv2-libs",
        "relates_to_product_reference": "rhel-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2-libs as a component of Red Hat Enterprise Linux 9.0",
          "product_id": "rhel-9.0:exiv2-libs"
        },
        "product_reference": "exiv2-libs",
        "relates_to_product_reference": "rhel-9.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2-libs as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:exiv2-libs"
        },
        "product_reference": "exiv2-libs",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2.src as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:exiv2.src"
        },
        "product_reference": "exiv2.src",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2.src as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:exiv2.src"
        },
        "product_reference": "exiv2.src",
        "relates_to_product_reference": "rhel-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2.src as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:exiv2.src"
        },
        "product_reference": "exiv2.src",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2.src as a component of Red Hat Enterprise Linux 9.0",
          "product_id": "rhel-9.0:exiv2.src"
        },
        "product_reference": "exiv2.src",
        "relates_to_product_reference": "rhel-9.0"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2021-37622",
      "cwe": {
        "id": "CWE-835",
        "name": "Loop with Unreachable Exit Condition ('Infinite Loop')"
      },
      "discovery_date": "2021-08-09T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "rhel-6-els.els:exiv2-debuginfo",
            "rhel-6-els.els:exiv2-devel",
            "rhel-7-els.els:compat-exiv2-023-debuginfo",
            "rhel-7-els.els:compat-exiv2-026-debuginfo",
            "rhel-7-els.els:exiv2-debuginfo",
            "rhel-7-els.els:exiv2-devel",
            "rhel-7-els.els:exiv2-doc",
            "rhel-8:exiv2-devel",
            "rhel-8:exiv2-doc",
            "rhel-9.0:exiv2-devel",
            "rhel-9.0:exiv2-doc"
          ]
        }
      ],
      "notes": [
        {
          "category": "other",
          "text": "To exploit this issue, an attacker needs to convince a user to process a specially crafted image file, specifically to delete IPTC data, an uncommon operation that requires an extra command line option (`-d I rm`). Additionally, this issue can lead to an infinite loop and cause a denial of service with no other security impact. Due to these reasons, this flaw has been rated with a low severity.",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to modify the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when deleting the IPTC data, which is a less frequently used Exiv2 operation that requires an extra command line option (`-d I rm`). The bug is fixed in version v0.27.5.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "rhel-6-els.els:exiv2",
          "rhel-6-els.els:exiv2-libs",
          "rhel-6-els.els:exiv2.src",
          "rhel-7-els.els:compat-exiv2-023",
          "rhel-7-els.els:compat-exiv2-023.src",
          "rhel-7-els.els:compat-exiv2-026",
          "rhel-7-els.els:compat-exiv2-026.src",
          "rhel-7-els.els:exiv2",
          "rhel-7-els.els:exiv2-libs",
          "rhel-7-els.els:exiv2.src",
          "rhel-8:compat-exiv2-026",
          "rhel-8:compat-exiv2-026.src",
          "rhel-8:exiv2",
          "rhel-8:exiv2-libs",
          "rhel-8:exiv2.src",
          "rhel-9.0:exiv2",
          "rhel-9.0:exiv2-libs",
          "rhel-9.0:exiv2.src"
        ],
        "known_not_affected": [
          "rhel-6-els.els:exiv2-debuginfo",
          "rhel-6-els.els:exiv2-devel",
          "rhel-7-els.els:compat-exiv2-023-debuginfo",
          "rhel-7-els.els:compat-exiv2-026-debuginfo",
          "rhel-7-els.els:exiv2-debuginfo",
          "rhel-7-els.els:exiv2-devel",
          "rhel-7-els.els:exiv2-doc",
          "rhel-8:exiv2-devel",
          "rhel-8:exiv2-doc",
          "rhel-9.0:exiv2-devel",
          "rhel-9.0:exiv2-doc"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2021-37622"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-37622"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-37622"
        }
      ],
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "Out of support scope",
          "product_ids": [
            "rhel-6-els.els:exiv2",
            "rhel-6-els.els:exiv2-libs",
            "rhel-6-els.els:exiv2.src",
            "rhel-7-els.els:compat-exiv2-023",
            "rhel-7-els.els:compat-exiv2-023.src",
            "rhel-7-els.els:compat-exiv2-026",
            "rhel-7-els.els:compat-exiv2-026.src",
            "rhel-7-els.els:exiv2",
            "rhel-7-els.els:exiv2-libs",
            "rhel-7-els.els:exiv2.src"
          ]
        },
        {
          "category": "no_fix_planned",
          "details": "Will not fix",
          "product_ids": [
            "rhel-8:compat-exiv2-026",
            "rhel-8:compat-exiv2-026.src",
            "rhel-8:exiv2",
            "rhel-8:exiv2-libs",
            "rhel-8:exiv2.src",
            "rhel-9.0:exiv2",
            "rhel-9.0:exiv2-libs",
            "rhel-9.0:exiv2.src"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM"
          },
          "products": [
            "rhel-6-els.els:exiv2",
            "rhel-6-els.els:exiv2-debuginfo",
            "rhel-6-els.els:exiv2-devel",
            "rhel-6-els.els:exiv2-libs",
            "rhel-6-els.els:exiv2.src",
            "rhel-7-els.els:compat-exiv2-023",
            "rhel-7-els.els:compat-exiv2-023-debuginfo",
            "rhel-7-els.els:compat-exiv2-023.src",
            "rhel-7-els.els:compat-exiv2-026",
            "rhel-7-els.els:compat-exiv2-026-debuginfo",
            "rhel-7-els.els:compat-exiv2-026.src",
            "rhel-7-els.els:exiv2",
            "rhel-7-els.els:exiv2-debuginfo",
            "rhel-7-els.els:exiv2-devel",
            "rhel-7-els.els:exiv2-doc",
            "rhel-7-els.els:exiv2-libs",
            "rhel-7-els.els:exiv2.src",
            "rhel-8:compat-exiv2-026",
            "rhel-8:compat-exiv2-026.src",
            "rhel-8:exiv2",
            "rhel-8:exiv2-devel",
            "rhel-8:exiv2-doc",
            "rhel-8:exiv2-libs",
            "rhel-8:exiv2.src",
            "rhel-9.0:exiv2",
            "rhel-9.0:exiv2-devel",
            "rhel-9.0:exiv2-doc",
            "rhel-9.0:exiv2-libs",
            "rhel-9.0:exiv2.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low",
          "product_ids": [
            "rhel-6-els.els:exiv2",
            "rhel-6-els.els:exiv2-debuginfo",
            "rhel-6-els.els:exiv2-devel",
            "rhel-6-els.els:exiv2-libs",
            "rhel-6-els.els:exiv2.src",
            "rhel-7-els.els:compat-exiv2-023",
            "rhel-7-els.els:compat-exiv2-023-debuginfo",
            "rhel-7-els.els:compat-exiv2-023.src",
            "rhel-7-els.els:compat-exiv2-026",
            "rhel-7-els.els:compat-exiv2-026-debuginfo",
            "rhel-7-els.els:compat-exiv2-026.src",
            "rhel-7-els.els:exiv2",
            "rhel-7-els.els:exiv2-debuginfo",
            "rhel-7-els.els:exiv2-devel",
            "rhel-7-els.els:exiv2-doc",
            "rhel-7-els.els:exiv2-libs",
            "rhel-7-els.els:exiv2.src",
            "rhel-8:compat-exiv2-026",
            "rhel-8:compat-exiv2-026.src",
            "rhel-8:exiv2",
            "rhel-8:exiv2-devel",
            "rhel-8:exiv2-doc",
            "rhel-8:exiv2-libs",
            "rhel-8:exiv2.src",
            "rhel-9.0:exiv2",
            "rhel-9.0:exiv2-devel",
            "rhel-9.0:exiv2-doc",
            "rhel-9.0:exiv2-libs",
            "rhel-9.0:exiv2.src"
          ]
        }
      ],
      "title": "DoS due to infinite loop in JpegBase::printStructure"
    }
  ]
}