RHSA-2026:20929: Moderate: libexif security update
Moderate: libexif security update
Other sources
The libexif packages provide a library for extracting extra information from image files.Security Fix(es): libexif: libexif: Information disclosure and crashes via integer overflow in Nikon MakerNote handling (CVE-2026-40385) libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding (CVE-2026-40386) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:20929?
The severity of RHSA-2026:20929 is medium, rated at 4.
What vulnerabilities are addressed by RHSA-2026:20929?
RHSA-2026:20929 addresses vulnerabilities including information disclosure and crashes via integer overflow in Nikon MakerNote handling (CVE-2026-40385).
How do I fix RHSA-2026:20929?
To fix RHSA-2026:20929, you need to update the libexif packages as specified in the security advisory.
Which software packages are affected by RHSA-2026:20929?
The affected software packages include redhat/libexif, redhat/libexif-debuginfo, redhat/libexif-debugsource, and redhat/libexif-devel.
What systems are impacted by RHSA-2026:20929?
RHSA-2026:20929 impacts Red Hat Enterprise Linux for ARM 64, IBM z Systems, and x86_64 - Extended Life Cycle.