Описание
Security update for libexif
This update for libexif fixes the following issues
- CVE-2026-40385: Fixed information disclosure and crashes via integer overflow in Nikon MakerNote handling (bsc#1262000)
- CVE-2026-40386: Fixed denial of service and information disclosure via integer underflow in MakerNote decoding (bsc#1262001)
- CVE-2026-32775: Fixed Buffer overwrite via integer underflow in MakerNotes decoding (bsc#1259755)
Список пакетов
SUSE Linux Enterprise Module for Desktop Applications 15 SP7
libexif-devel-0.6.22-150000.5.12.1
libexif12-0.6.22-150000.5.12.1
SUSE Linux Enterprise Module for Package Hub 15 SP7
libexif12-32bit-0.6.22-150000.5.12.1
Ссылки
- Link for SUSE-SU-2026:2837-1
- E-Mail link for SUSE-SU-2026:2837-1
- SUSE Security Ratings
- SUSE Bug 1259755
- SUSE Bug 1262000
- SUSE Bug 1262001
- SUSE CVE CVE-2026-32775 page
- SUSE CVE CVE-2026-40385 page
- SUSE CVE CVE-2026-40386 page
Описание
libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.
Затронутые продукты
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:libexif-devel-0.6.22-150000.5.12.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:libexif12-0.6.22-150000.5.12.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:libexif12-32bit-0.6.22-150000.5.12.1
Ссылки
- CVE-2026-32775
- SUSE Bug 1259755
Описание
In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.
Затронутые продукты
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:libexif-devel-0.6.22-150000.5.12.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:libexif12-0.6.22-150000.5.12.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:libexif12-32bit-0.6.22-150000.5.12.1
Ссылки
- CVE-2026-40385
- SUSE Bug 1262000
Описание
In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.
Затронутые продукты
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:libexif-devel-0.6.22-150000.5.12.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:libexif12-0.6.22-150000.5.12.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:libexif12-32bit-0.6.22-150000.5.12.1
Ссылки
- CVE-2026-40386
- SUSE Bug 1262001