Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40386

Опубликовано: 12 апр. 2026
Источник: redhat
CVSS3: 4
EPSS Низкий

Описание

A flaw was found in libexif. An integer underflow vulnerability in the size checking mechanism for Fuji and Olympus MakerNote decoding could allow attackers to exploit programs using libexif. This could lead to a Denial of Service (DoS) by crashing the program or result in information disclosure, potentially exposing sensitive data.

Отчет

Moderate impact. An integer underflow in libexif's Fuji and Olympus MakerNote decoding could allow an attacker to cause a denial of service or information disclosure. This vulnerability affects programs that process specially crafted image files utilizing libexif.

Меры по смягчению последствий

To mitigate this issue, users should avoid processing untrusted image files with applications that utilize libexif. Restricting the source of image files to trusted origins can reduce the risk of exploitation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libexifFix deferred
Red Hat Enterprise Linux 6libexifFix deferred
Red Hat Enterprise Linux 7libexifFix deferred
Red Hat Enterprise Linux 8libexifFix deferred
Red Hat Enterprise Linux 9libexifFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-191
https://bugzilla.redhat.com/show_bug.cgi?id=2457689libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding

EPSS

Процентиль: 2%
0.00013
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4
ubuntu
2 дня назад

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.

CVSS3: 4
nvd
3 дня назад

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.

msrc
1 день назад

Описание отсутствует

CVSS3: 4
debian
3 дня назад

In libexif through 0.6.25, an integer underflow in size checking for F ...

CVSS3: 4
github
3 дня назад

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.

EPSS

Процентиль: 2%
0.00013
Низкий

4 Medium

CVSS3