CVE-2026-40386

MEDIUM

libexif < 0.6.25 - Integer Underflow in Fuji and Olympus MakerNote Decoding

Title source: llm
STIX 2.1

Description

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.

Scores

CVSS v3 4.0
EPSS 0.0014
EPSS Percentile 3.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-191
Status published
Products (2)
libexif project/libexif < 0.6.25
libexif_project/libexif < 0.6.25
Published Apr 12, 2026
Tracked Since Apr 13, 2026