CVE-2026-40386: Integer Underflow
In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libexifto a version that resolves this vulnerability.Fixed in 0.6.22-3+deb11u1Fixed in 0.6.24-1+deb12u1Fixed in 0.6.25-1+deb13u1Fixed in 0.6.26-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40386?
CVE-2026-40386 has a severity rating that indicates a potential for serious impacts due to integer underflow vulnerabilities.
How do I fix CVE-2026-40386?
To fix CVE-2026-40386, update libexif to version 0.6.26 or later.
What types of programs are affected by CVE-2026-40386?
Programs that utilize libexif versions up to 0.6.25 for decoding Fuji and Olympus MakerNotes are affected by CVE-2026-40386.
What are the potential impacts of CVE-2026-40386?
The potential impacts of CVE-2026-40386 include crashing the application or leaking sensitive information.
Is CVE-2026-40386 related to specific camera manufacturers?
Yes, CVE-2026-40386 specifically affects the decoding of MakerNotes from Fuji and Olympus cameras.