CVE-2026-40386 PUBLISHED CVSS 4 MEDIUM

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.

EPSS 0.01% · 1.9th percentile

Risk Scores

CVSS v3.1
4
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
EPSS Score
0.01%
1.9th percentile

Affected Products

VendorProductVersions
libexif projectlibexif0
libexif_projectlibexif

Timeline

References

…and 2 more

Open in Interactive Console →