Logo
vulnerabilityCVE-2026-40386
Name
CVE-2026-40386
Source
NVD ( link)Debian ( link)
Description
In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libexif
Exploitable

Vulnerability Ratings#


4
CVSSv31
7.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
0.6.26
Not Affected
buildroot
master
0.6.26
Not Affected
openwrt
master
0.6.26-r1
Not Affected
yocto
master
0.6.26
Not Affected
yocto
scarthgap
0.6.24
Patched

Resolved with patches#


libexif (yocto:scarthgap)

#
Title
Author
Resolve
1
fixed 2 unsigned integer underflows
Marcus Meissner <meissner@suse.de>
CVE-2026-40386