CVE-2026-40386Integer Underflow (Wrap or Wraparound) in Project Libexif

Severity
4.0MEDIUMNVD
EPSS
0.0%
top 98.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 12
Latest updateApr 14

Description

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:LExploitability: 1.4 | Impact: 2.5

Affected Packages1 packages

CVEListV5libexif_project/libexif0.6.25

🔴Vulnerability Details

3
GHSA
GHSA-p6wp-hhx9-7jj5: In libexif through 02026-04-12
VulDB
libexif up to 0.6.25 MakerNote Decoding integer underflow2026-04-12
CVEList
CVE-2026-40386: In libexif through 02026-04-12

📋Vendor Advisories

1
Red Hat
libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding2026-04-12

🕵️Threat Intelligence

1
Rapid7
Patch Tuesday - April 20262026-04-14

💬Community

2
Bugzilla
CVE-2026-40386 libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding [fedora-all]2026-04-13
Bugzilla
CVE-2026-40386 libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding2026-04-12
CVE-2026-40386 — Integer Underflow (Wrap or Wraparound) | cvebase