Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian 11 libexif Important Crashes Info Leaks DLA-4558-1 CVE-2026-32775

debian lts
Calendar Grey May 1, 2026
Dist Debian Esm H88
Three critical issues in libexif threaten image file safety, streamlining data integrity. Upgrade for protection now!
Three security vulnerabilities were discovered in libexif, a library to reads and writes EXIF metainformation from and to images files, that can causes crashes or information leaks

Summary

CVE-2026-32775

If the exif_mnote_data_get_value function in MakerNotes gets passed
in a 0 size, the passed in-buffer would be overwritten due to an
integer underflow.

CVE-2026-40385

An unsigned 32bit integer overflow in Nikon MakerNote handling could
be used by local attackers to cause crashes or information leaks.

CVE-2026-40386

An integer underflow in size checking for Fuji and Olympus MakerNote
decoding could be used by attackers to crash or leak information out
of libexif-using programs.

For Debian 11 bullseye, these problems have been fixed in version
0.6.22-3+deb11u1.

We recommend that you upgrade your libexif packages.

For the detailed security status of libexif please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libexif

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
important
Lowest
Low
Medium
High
Critical

Package: libexif
Version: 0.6.22-3+deb11u1
CVE ID: CVE-2026-32775 CVE-2026-40385 CVE-2026-40386
Debian Bug: 1131116 1133922 1133923

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here