Re: [BLFS Trac] #23148: libexif-0.6.26

"BLFS Trac" ([email protected] via blfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23148: libexif-0.6.26
-------------------------+------------------------
 Reporter:  Bruce Dubbs  |       Owner:  blfs-book
     Type:  enhancement  |      Status:  new
 Priority:  high         |   Milestone:  13.1
Component:  BOOK         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+------------------------
Changes (by Douglas R. Reno):

 * priority:  normal => high

Comment:

 This update contains three CVE fixes:

 {{{
 libexif-0.6.26 (2026-04-14):

     Security issues fixed:

 CVE-2026-40386: An unsigned integer underflow in Fuji and Olympus
 makernote handling

 CVE-2026-40385: An unsigned integer overflow on 32bit systems in Nikon
 makernote handling

 CVE-2026-32775: A buffer overwrite via integer underflow in makernote
 handling

     handle JPEG APP3 marker

     added EXIF_TAG_IMAGE_DEPTH tag

     translations updated: Arabic, German, Spanish, Polish, Romanian,
     Serbian, Swedish, Ukrainian, Chinese
 }}}

 CVE-2026-40386 (Medium) - DoS and Info Disclosure

 CVE-2026-40385 (Medium) - DoS and Info Disclosure. 32-bit only.

 CVE-2026-32775 (High) - Arbitrary Code Execution
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23148#comment:1>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.