rpm package
opensuse/libexif&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/libexif&distro=openSUSE%20Leap%2016.0
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-40386 | Med | 4.0 | < 0.6.26-160000.1.1 | 0.6.26-160000.1.1 | Apr 12, 2026 | In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs. | |
| CVE-2026-40385 | Med | 4.0 | < 0.6.26-160000.1.1 | 0.6.26-160000.1.1 | Apr 12, 2026 | In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems. | |
| CVE-2026-32775 | Hig | 7.4 | < 0.6.26-160000.1.1 | 0.6.26-160000.1.1 | Mar 16, 2026 | libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow. |
- affected < 0.6.26-160000.1.1fixed 0.6.26-160000.1.1
In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.
- affected < 0.6.26-160000.1.1fixed 0.6.26-160000.1.1
In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.
- affected < 0.6.26-160000.1.1fixed 0.6.26-160000.1.1
libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.