Opened 6 months ago

Closed 6 months ago

#23148 closed enhancement (fixed)

libexif-0.6.26

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: high Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (4)

comment:1 by Douglas R. Reno, 6 months ago

Priority: normal → high

This update contains three CVE fixes:

libexif-0.6.26 (2026-04-14):

    Security issues fixed:

CVE-2026-40386: An unsigned integer underflow in Fuji and Olympus makernote handling

CVE-2026-40385: An unsigned integer overflow on 32bit systems in Nikon makernote handling

CVE-2026-32775: A buffer overwrite via integer underflow in makernote handling

    handle JPEG APP3 marker

    added EXIF_TAG_IMAGE_DEPTH tag

    translations updated: Arabic, German, Spanish, Polish, Romanian,
    Serbian, Swedish, Ukrainian, Chinese

CVE-2026-40386 (Medium) - DoS and Info Disclosure

CVE-2026-40385 (Medium) - DoS and Info Disclosure. 32-bit only.

CVE-2026-32775 (High) - Arbitrary Code Execution

comment:2 by Joe Locash, 6 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:3 by Joe Locash, 6 months ago

Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new

Fixed at 97a32bd26f. Leaving open for SA.

comment:4 by Douglas R. Reno, 6 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-044 issued.

Note: See TracTickets for help on using tickets.