Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40385

Опубликовано: 12 апр. 2026
Источник: redhat
CVSS3: 4

Описание

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.

A flaw was found in libexif. A local attacker on a 32-bit system could exploit an unsigned 32-bit integer overflow vulnerability in the Nikon MakerNote handling. This could lead to application crashes or the disclosure of sensitive information.

Отчет

This Moderate impact vulnerability in libexif affects 32-bit systems. A local attacker could trigger an integer overflow in the Nikon MakerNote handling, potentially leading to application crashes or information disclosure.

Меры по смягчению последствий

On 32-bit systems, avoid processing untrusted image files that contain Nikon MakerNotes. This operational control reduces the risk of exploitation by preventing vulnerable applications from parsing malicious EXIF data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libexifNot affected
Red Hat Enterprise Linux 6libexifOut of support scope
Red Hat Enterprise Linux 7 Extended Lifecycle SupportlibexifFixedRHSA-2026:2656717.06.2026
Red Hat Enterprise Linux 8libexifFixedRHSA-2026:2092926.05.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportlibexifFixedRHSA-2026:2629216.06.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnlibexifFixedRHSA-2026:2629216.06.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportlibexifFixedRHSA-2026:2619116.06.2026
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnlibexifFixedRHSA-2026:2619116.06.2026
Red Hat Enterprise Linux 8.8 Telecommunications Update ServicelibexifFixedRHSA-2026:2619016.06.2026
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionslibexifFixedRHSA-2026:2619016.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2457687libexif: libexif: Information disclosure and crashes via integer overflow in Nikon MakerNote handling

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4
ubuntu
4 месяца назад

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.

CVSS3: 4
nvd
4 месяца назад

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.

CVSS3: 4
msrc
4 месяца назад

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.

CVSS3: 4
debian
4 месяца назад

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon ...

CVSS3: 7.1
redos
24 дня назад

Уязвимость libexif

4 Medium

CVSS3