Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40386

Опубликовано: 12 апр. 2026
Источник: redhat
CVSS3: 4
EPSS Низкий

Описание

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.

A flaw was found in libexif. An integer underflow vulnerability in the size checking mechanism for Fuji and Olympus MakerNote decoding could allow attackers to exploit programs using libexif. This could lead to a Denial of Service (DoS) by crashing the program or result in information disclosure, potentially exposing sensitive data.

Отчет

Moderate impact. An integer underflow in libexif's Fuji and Olympus MakerNote decoding could allow an attacker to cause a denial of service or information disclosure. This vulnerability affects programs that process specially crafted image files utilizing libexif.

Меры по смягчению последствий

To mitigate this issue, users should avoid processing untrusted image files with applications that utilize libexif. Restricting the source of image files to trusted origins can reduce the risk of exploitation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libexifOut of support scope
Red Hat Enterprise Linux 10libexifFixedRHSA-2026:2252903.06.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportlibexifFixedRHSA-2026:2627416.06.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupportlibexifFixedRHSA-2026:2656717.06.2026
Red Hat Enterprise Linux 8libexifFixedRHSA-2026:2092926.05.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportlibexifFixedRHSA-2026:2629216.06.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnlibexifFixedRHSA-2026:2629216.06.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportlibexifFixedRHSA-2026:2619116.06.2026
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnlibexifFixedRHSA-2026:2619116.06.2026
Red Hat Enterprise Linux 8.8 Telecommunications Update ServicelibexifFixedRHSA-2026:2619016.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-191
https://bugzilla.redhat.com/show_bug.cgi?id=2457689libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding

EPSS

Процентиль: 4%
0.0014
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4
ubuntu
4 месяца назад

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.

CVSS3: 4
nvd
4 месяца назад

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.

CVSS3: 4
msrc
4 месяца назад

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.

CVSS3: 4
debian
4 месяца назад

In libexif through 0.6.25, an integer underflow in size checking for F ...

rocky
около 2 месяцев назад

Moderate: libexif security update

EPSS

Процентиль: 4%
0.0014
Низкий

4 Medium

CVSS3