ZeroHour

CVE-2026-40386

CVSS 3.1
7.1 high
EPSS
<1%p4
Published
()
Modified
Description

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.

Vendors
libexif project
Products
libexif
Weakness
CWE-191
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.