CVE-2026-32775

Name
CVE-2026-32775
Description
libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://github.com/libexif/libexif/commit/7df372e9d31d7c993a22b913c813a5f7ec4f3692
cve@mitre.org https://github.com/libexif/libexif/issues/247

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:* libexif >= None <= 0.6.25

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libexif edge-community 0.6.25-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libexif edge-community 0.6.24-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libexif edge-community 0.6.23-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libexif edge-community 0.6.22-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libexif edge-community 0.6.21-r3 None possibly vulnerable
libexif edge-community 0.6.21-r0 None possibly vulnerable
libexif edge-community 0.6.19-r0 None possibly vulnerable
libexif 3.23-community 0.6.26-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
libexif 3.23-community 0.6.25-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable