CVE-2026-40386

medium
Published 2026-05-26 Β· Modified 2026-06-03
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.5

Description

Moderate: libexif security update

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding Red Hat statement Moderate impact. An integer underflow in libexif's Fuji and Olympus MakerNote decoding could allow an attacker to cause a denial of service or information disclosure. This vulnerability affects programs that process specially crafted image files utilizing…

Description

libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding

Red Hat statement

Moderate impact. An integer underflow in libexif's Fuji and Olympus MakerNote decoding could allow an attacker to cause a denial of service or information disclosure. This vulnerability affects programs that process specially crafted image files utilizing libexif.

CVSS v3: 4.0 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 8libexif-0:0.6.22-6.el8_10RHSA-2026:209292026-05-26T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 10libexifAffected
Red Hat Enterprise Linux 6libexifOut of support scope
Red Hat Enterprise Linux 7libexifAffected
Red Hat Enterprise Linux 9libexifAffected

Apply commands

bash fix
Apply RHSA-2026:20929 for Red Hat Enterprise Linux 8
yum update -y libexif
# or:
dnf upgrade -y libexif

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 10Affected
redhatRed Hat Enterprise Linux 7Affected
redhatRed Hat Enterprise Linux 9Affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
9 Fixed libexif-0.6.22-6.el9_8.1.i686.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 0.6.25-1+deb13u1
sid Fixed 0.6.26-1
forky Fixed 0.6.26-1
bullseye Fixed 0.6.22-3+deb11u1
bookworm Fixed 0.6.24-1+deb12u1
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.