VDB

CVE-2026-40386

CVE-2026-40386 PUBLISHED CVSS 4 MEDIUM

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.

EPSS 0.01% · 0.7th percentile

Risk Scores

CVSS 3.1
4
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
EPSS Score
0.01%
0.7th percentile

Affected Products

VendorProductVersions
libexif projectlibexif0
libexif_projectlibexif

Timeline

  • Apr 12, 2026 CVE Published
  • Apr 13, 2026 EPSS Score
  • Apr 13, 2026 Security Advisory
  • Apr 14, 2026 CVE Updated
  • Apr 16, 2026 Security Advisory
  • Apr 16, 2026 Security Advisory
  • Apr 16, 2026 Security Advisory
  • Apr 16, 2026 Security Advisory
  • Apr 16, 2026 Security Advisory
  • Apr 16, 2026 Security Advisory
  • Apr 16, 2026 Security Advisory
  • Apr 16, 2026 Security Advisory

References

…and 2 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›