CVE-2026-40386
Severity CVSS v4.0:
Pending analysis
Type:
CWE-191
Integer Underflow (Wrap or Wraparound)
Publication date:
12/04/2026
Last modified:
12/04/2026
Description
In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.
Impact
Base Score 3.x
4.00
Severity 3.x
MEDIUM



