CVE-2026-32775
published 2026-03-16CVE-2026-32775: libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be…
PriorityP336high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.16%
5.0th percentile
libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libexif | — | — |
| libexif_project | libexif | <= 0.6.25 | — |
| msrc | azl3_libexif_0.6.24-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libexif_0.6.24-1_on_cbl_mariner_2.0 | — | — |
| ubuntu | libexif | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.4HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.4HIGH
vendor_msrc7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libexif vulnerabilities
vendor_ubuntu·2026-07-13·CVSS 7.8
CVE-2026-40385 [HIGH] libexif vulnerabilities
Title: libexif vulnerabilities
Summary: Several security issues were fixed in libexif.
It was discovered that libexif had an integer overflow in its MakerNote
decoder when called with a zero-length buffer. An attacker could possibly
use this issue to cause a denial of service or obtain sensitive
information. (CVE-2026-32775)
It was discovered that libexif had an integer overflow in its Nikon
MakerNote handler on 32-bit systems. A local attacker could possibly use
this issue to cause a denial of service or obtain sensitive information.
(CVE-2026-40385)
It was discovered that libexif had an integer underflow in its size
checking for Fuji and Olympus MakerNote decoding. An attacker could
possibly use this issue to cause a denial of service or obtain sensitive
information. (CVE-2026-40386)
Red Hat
libexif: libexif: Buffer overwrite via integer underflow in MakerNotes decoding
vendor_redhat·2026-03-16·CVSS 7.4
CVE-2026-32775 [HIGH] CWE-191 libexif: libexif: Buffer overwrite via integer underflow in MakerNotes decoding
libexif: libexif: Buffer overwrite via integer underflow in MakerNotes decoding
libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.
A flaw was found in libexif. When decoding MakerNotes, an integer underflow can occur in the exif_mnote_data_get_value function if a zero size is passed. This can lead to a buffer overwrite, potentially allowing an attacker to achieve arbitrary code execution, disclose sensitive information, or cause a denial of service (DoS).
Mitigation: To mitigate this issue, avoid processing untrusted image files that may contain specially crafted EXIF MakerNotes. Restrict the use of applications that process EXIF data to truste
Microsoft
CVE-2026-32775: Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn
vendor_msrc·2026-03-10·CVSS 7.4
CVE-2026-32775 [HIGH] CWE-191 CVE-2026-32775: Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2026-32775: libexif - libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data...
vendor_debian·2026·CVSS 7.4
CVE-2026-32775 [HIGH] CVE-2026-32775: libexif - libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data...
libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-pq8m-942f-68cv: libexif through 0
ghsa_unreviewed·2026-03-16
CVE-2026-32775 [HIGH] CWE-191 GHSA-pq8m-942f-68cv: libexif through 0
libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.
OSV
CVE-2026-32775: libexif through 0
osv·2026-03-16·CVSS 7.4
CVE-2026-32775 [HIGH] CVE-2026-32775: libexif through 0
libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-32775 libexif: libexif: Buffer overwrite via integer underflow in MakerNotes decoding
bugzilla·2026-03-16·CVSS 7.8
CVE-2026-32775 [HIGH] CVE-2026-32775 libexif: libexif: Buffer overwrite via integer underflow in MakerNotes decoding
CVE-2026-32775 libexif: libexif: Buffer overwrite via integer underflow in MakerNotes decoding
libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.
Wiz
CVE-2026-32775 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-32775 [HIGH] CVE-2026-32775 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32775 :
CBL Mariner vulnerability analysis and mitigation
libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.
Source : NVD
## 7.4
Score
Published March 16, 2026
Severity HIGH
CNA Score 7.4
Affected Technologies
CBL Mariner
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libexif
libexif-devel
Sources
NVD
CBL-Mariner 3.0 Severity HIGH Has Fix Added at: Mar 20, 2026
Debian 11, 14 Severity HIGH No Fix Added at: Mar 17, 2026
Debian 12, 13 Sever
2026-03-16
Published