Integer Underflow Vulnerability in Libexif Affects Photography Applications
CVE-2026-40386

4MEDIUM

Key Information:

Status
Vendor
CVE Published:
12 April 2026

What is CVE-2026-40386?

An integer underflow in the size checking mechanism for Fuji and Olympus MakerNote decoding in libexif versions up to 0.6.25 may allow attackers to exploit the flaw, leading to potential application crashes or unauthorized information disclosure. This vulnerability affects programs that rely on the libexif library to process image metadata associated with certain cameras, emphasizing the need for timely updates and patch management to mitigate risk.

Affected Version(s)

libexif 0 <= 0.6.25

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.