CVE-2026-32775

libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.
Configurations

Configuration 1 (hide)

cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:*

History

21 Apr 2026, 13:54

Type Values Removed Values Added
References () https://github.com/libexif/libexif/commit/7df372e9d31d7c993a22b913c813a5f7ec4f3692 - () https://github.com/libexif/libexif/commit/7df372e9d31d7c993a22b913c813a5f7ec4f3692 - Patch
References () https://github.com/libexif/libexif/issues/247 - () https://github.com/libexif/libexif/issues/247 - Issue Tracking, Exploit, Vendor Advisory
First Time Libexif Project libexif
Libexif Project
CPE cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:*
Summary
  • (es) libexif hasta 0.6.25 tiene una falla en la decodificación de MakerNotes. Si a la función exif_mnote_data_get_value se le pasa un tamaño de 0, el búfer pasado sería sobrescrito debido a un subdesbordamiento de enteros.

16 Mar 2026, 14:19

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 14:19

Updated : 2026-04-21 13:54


NVD link : CVE-2026-32775

Mitre link : CVE-2026-32775

CVE.ORG link : CVE-2026-32775


JSON object : View

Products Affected

libexif_project

  • libexif
CWE
CWE-191

Integer Underflow (Wrap or Wraparound)