CVE-2026-40386
MEDIUMlibexif <0.6.25 - Info Disclosure
Title source: llmDescription
In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.
Scores
CVSS v3
4.0
EPSS
0.0001
EPSS Percentile
0.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
Details
CWE
CWE-191
Status
published
Products (2)
libexif project/libexif
< 0.6.25
libexif_project/libexif
< 0.6.25
Published
Apr 12, 2026
Tracked Since
Apr 13, 2026