Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21023-1

Опубликовано: 22 июн. 2026
Источник: suse-cvrf

Описание

Security update for libexif

This update for libexif fixes the following issues

  • CVE-2026-32775: Buffer overwrite via integer underflow in MakerNotes decoding (bsc#1259755).
  • CVE-2026-40385: information disclosure and crashes via integer overflow in Nikon MakerNote handling (bsc#1262000).
  • CVE-2026-40386: denial of service and information disclosure via integer underflow in MakerNote decoding (bsc#1262001).

Список пакетов

openSUSE Leap 16.0
libexif-devel-0.6.26-160000.1.1
libexif12-0.6.26-160000.1.1

Описание

libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.


Затронутые продукты
openSUSE Leap 16.0:libexif-devel-0.6.26-160000.1.1
openSUSE Leap 16.0:libexif12-0.6.26-160000.1.1

Ссылки

Описание

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.


Затронутые продукты
openSUSE Leap 16.0:libexif-devel-0.6.26-160000.1.1
openSUSE Leap 16.0:libexif12-0.6.26-160000.1.1

Ссылки

Описание

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.


Затронутые продукты
openSUSE Leap 16.0:libexif-devel-0.6.26-160000.1.1
openSUSE Leap 16.0:libexif12-0.6.26-160000.1.1

Ссылки