In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.
References
Configurations
History
14 Apr 2026, 20:43
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:* | |
| First Time |
Libexif Project libexif
Libexif Project |
|
| References | () https://github.com/libexif/libexif/commit/dc6eac6e9655d14d0779d99e82d0f5f442d2f34b - Patch |
12 Apr 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-12 19:16
Updated : 2026-04-14 20:43
NVD link : CVE-2026-40386
Mitre link : CVE-2026-40386
CVE.ORG link : CVE-2026-40386
JSON object : View
Products Affected
libexif_project
- libexif
CWE
CWE-191
Integer Underflow (Wrap or Wraparound)
