CVE-2026-40386

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.
Configurations

Configuration 1 (hide)

cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:*

History

14 Apr 2026, 20:43

Type Values Removed Values Added
CPE cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:*
First Time Libexif Project libexif
Libexif Project
References () https://github.com/libexif/libexif/commit/dc6eac6e9655d14d0779d99e82d0f5f442d2f34b - () https://github.com/libexif/libexif/commit/dc6eac6e9655d14d0779d99e82d0f5f442d2f34b - Patch

12 Apr 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-12 19:16

Updated : 2026-04-14 20:43


NVD link : CVE-2026-40386

Mitre link : CVE-2026-40386

CVE.ORG link : CVE-2026-40386


JSON object : View

Products Affected

libexif_project

  • libexif
CWE
CWE-191

Integer Underflow (Wrap or Wraparound)