CVE-2026-40386 affecting package libexif for versions less than 0.6.24-3
Details
In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.