CVE Vulnerabilities

CVE-2026-40386

Integer Underflow (Wrap or Wraparound)

Published: Apr 12, 2026 | Modified: Apr 14, 2026
CVSS 3.x
7.1
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
4 MODERATE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.

Weakness

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Affected Software

NameVendorStart VersionEnd Version
LibexifLibexif_project*0.6.25 (including)
Red Hat Enterprise Linux 10RedHatlibexif-0:0.6.24-9.el10_2.1*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatlibexif-0:0.6.24-9.el10_0.1*
Red Hat Enterprise Linux 7 Extended Lifecycle SupportRedHatlibexif-0:0.6.22-3.el7_9*
Red Hat Enterprise Linux 8RedHatlibexif-0:0.6.22-6.el8_10*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatlibexif-0:0.6.22-5.el8_4.1*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatlibexif-0:0.6.22-5.el8_4.1*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatlibexif-0:0.6.22-5.el8_6.1*
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnRedHatlibexif-0:0.6.22-5.el8_6.1*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatlibexif-0:0.6.22-5.el8_8.1*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatlibexif-0:0.6.22-5.el8_8.1*
Red Hat Enterprise Linux 9RedHatlibexif-0:0.6.22-6.el9_8.1*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatlibexif-0:0.6.22-6.el9_2.1*
Red Hat Enterprise Linux 9.4 Update Services for SAP SolutionsRedHatlibexif-0:0.6.22-6.el9_4.1*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatlibexif-0:0.6.22-6.el9_6.1*
LibexifUbuntudevel*
LibexifUbuntuesm-infra-legacy/trusty*
LibexifUbuntuesm-infra-legacy/xenial*
LibexifUbuntuesm-infra/bionic*
LibexifUbuntuesm-infra/focal*
LibexifUbuntuesm-infra/xenial*
LibexifUbuntujammy*
LibexifUbuntunoble*
LibexifUbuntuquesting*
LibexifUbunturesolute*

References