PT-2026-32180 · Libexif+3 · Libexif+3

·

CVE-2026-40385

·

Publicado

2026-04-12

·

Atualizado

2026-07-13

CVSS v3.1

7.1

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions libexif versões até 0.6.25
Description Uma falha existe no libexif que envolve um estouro de inteiro sem sinal de 32 bits ao lidar com dados Nikon MakerNote. Esta questão pode levar a falhas ou vazamentos de informações. A questão é limitada a sistemas de 32 bits.
Recommendations Atualize para uma versão do libexif mais recente que 0.6.25.

Exploit

Correção

DoS

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2026:20929
ALSA-2026:22553
BDU:2026-10464
CVE-2026-40385
JLSEC-2026-151
OESA-2026-1987
OPENSUSE-SU-2026:10717-1
OPENSUSE-SU-2026:21023-1
RHSA-2026:20929
RHSA-2026:22553
RHSA-2026:26190
RHSA-2026:26191
RHSA-2026:26192
RHSA-2026:26224
RHSA-2026:26276
RHSA-2026:26292
RHSA-2026:26567
SUSE-SU-2026:22324-1
SUSE-SU-2026:2837-1
SUSE-SU-2026:2838-1
USN-8531-1

Produtos afetados

Linuxmint
Red Os
Rocky Linux
Libexif