CVE-2026-40386
Description
RHSA-2026:20929: libexif security update (Moderate)
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
Description libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding Red Hat statement Moderate impact. An integer underflow in libexif's Fuji and Olympus MakerNote decoding could allow an attacker to cause a denial of service or information disclosure. This vulnerability affects programs that process specially crafted image files utilizing…
Description
libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding
Red Hat statement
Moderate impact. An integer underflow in libexif's Fuji and Olympus MakerNote decoding could allow an attacker to cause a denial of service or information disclosure. This vulnerability affects programs that process specially crafted image files utilizing libexif.
CVSS v3: 4.0 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L)
Errata / fixed releases
| Product | Package | Advisory | Released |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | libexif-0:0.6.22-6.el8_10 | RHSA-2026:20929 | 2026-05-26T00:00:00Z |
Package state
| Product | Package | State |
|---|---|---|
| Red Hat Enterprise Linux 10 | libexif | Affected |
| Red Hat Enterprise Linux 6 | libexif | Out of support scope |
| Red Hat Enterprise Linux 7 | libexif | Affected |
| Red Hat Enterprise Linux 9 | libexif | Affected |
Apply commands
yum update -y libexif
# or:
dnf upgrade -y libexif
Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | Red Hat Enterprise Linux 10 | Affected |
| redhat | Red Hat Enterprise Linux 7 | Affected |
| redhat | Red Hat Enterprise Linux 9 | Affected |
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 0.6.24-1+deb12u1 |
| debian | bullseye | fixed | 0.6.22-3+deb11u1 |
| debian | forky | fixed | 0.6.26-1 |
| debian | sid | fixed | 0.6.26-1 |
| debian | trixie | fixed | 0.6.25-1+deb13u1 |
| sles | affected | | |
| rhel | 8 | fixed | |
References
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.