CVE-2026-40386

medium
Published 2026-05-26 · Modified 2026-05-26
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk
5.5

Description

RHSA-2026:20929: libexif security update (Moderate)

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata — Red Hat Inc. · View original ↗ · Open-Errata-API

Description libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding Red Hat statement Moderate impact. An integer underflow in libexif's Fuji and Olympus MakerNote decoding could allow an attacker to cause a denial of service or information disclosure. This vulnerability affects programs that process specially crafted image files utilizing…

Description

libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding

Red Hat statement

Moderate impact. An integer underflow in libexif's Fuji and Olympus MakerNote decoding could allow an attacker to cause a denial of service or information disclosure. This vulnerability affects programs that process specially crafted image files utilizing libexif.

CVSS v3: 4.0 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 8libexif-0:0.6.22-6.el8_10RHSA-2026:209292026-05-26T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 10libexifAffected
Red Hat Enterprise Linux 6libexifOut of support scope
Red Hat Enterprise Linux 7libexifAffected
Red Hat Enterprise Linux 9libexifAffected

Apply commands

bash fix
Apply RHSA-2026:20929 for Red Hat Enterprise Linux 8
yum update -y libexif
# or:
dnf upgrade -y libexif

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 10Affected
redhatRed Hat Enterprise Linux 7Affected
redhatRed Hat Enterprise Linux 9Affected

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0.6.24-1+deb12u1
debian debianbullseyefixed0.6.22-3+deb11u1
debian debianforkyfixed0.6.26-1
debian debiansidfixed0.6.26-1
debian debiantrixiefixed0.6.25-1+deb13u1
suse slesaffected
redhat rhel8fixed

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.