In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.
CVSS Details
- CVSS 3.1 Base Score: 4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libexif-develUpgrade libexif | May 27, 2026 | May 26, 2026 |
| Alpine Linux | — | Upgrade libexif | Apr 29, 2026 | Apr 12, 2026 |
| Debian | — | Upgrade libexif | May 3, 2026 | May 3, 2026 |
| Oracle_linux | — | Upgrade libexif-develUpgrade libexif | May 29, 2026 | Apr 12, 2026 |
| Redhat_linux | — | Upgrade libexif-docUpgrade libexifUpgrade libexif-debuginfoUpgrade libexif-debugsourceUpgrade libexif-develNo solution exists | May 28, 2026 | Apr 12, 2026 |
| Rocky_linux | — | Upgrade libexif-debuginfoUpgrade libexif-debugsourceUpgrade libexifUpgrade libexif-devel | Jun 1, 2026 | May 29, 2026 |
| Ubuntu | — | Upgrade libexif12 | Jul 13, 2026 | Apr 12, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub