In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 12 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs. | |
| First Time appeared |
Libexif Project
Libexif Project libexif |
|
| Weaknesses | CWE-191 | |
| CPEs | cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Libexif Project
Libexif Project libexif |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-12T18:55:21.234Z
Reserved: 2026-04-12T18:19:08.139Z
Link: CVE-2026-40386
No data.
Status : Received
Published: 2026-04-12T19:16:20.640
Modified: 2026-04-12T19:16:20.640
Link: CVE-2026-40386
No data.
OpenCVE Enrichment
No data.
Weaknesses