Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4558-1 | libexif security update |
Tue, 14 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 13 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Sun, 12 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs. | |
| First Time appeared |
Libexif Project
Libexif Project libexif |
|
| Weaknesses | CWE-191 | |
| CPEs | cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Libexif Project
Libexif Project libexif |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-14T16:33:07.044Z
Reserved: 2026-04-12T18:19:08.139Z
Link: CVE-2026-40386
Updated: 2026-04-14T15:19:04.263Z
Status : Analyzed
Published: 2026-04-12T19:16:20.640
Modified: 2026-04-14T20:43:44.283
Link: CVE-2026-40386
OpenCVE Enrichment
Updated: 2026-04-13T12:54:04Z
Debian DLA