OESA-2026-1678

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-1678
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-1678.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-1678
Upstream
Published
2026-03-20T14:25:13Z
Modified
2026-03-20T14:30:54.035083Z
Summary
libexif security update
Details

Most digital cameras produce EXIF files, which are JPEG files with extra tags that contain information about the image. The EXIF library allows you to parse an EXIF file and read the data from those tags.

Security Fix(es):

libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exifmnotedatagetvalue function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.(CVE-2026-32775)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP4
libexif

Package

Name
libexif
Purl
pkg:rpm/openEuler/libexif&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.21-27.oe2003sp4

Ecosystem specific

{
    "aarch64": [
        "libexif-0.6.21-27.oe2003sp4.aarch64.rpm",
        "libexif-debuginfo-0.6.21-27.oe2003sp4.aarch64.rpm",
        "libexif-debugsource-0.6.21-27.oe2003sp4.aarch64.rpm",
        "libexif-devel-0.6.21-27.oe2003sp4.aarch64.rpm"
    ],
    "x86_64": [
        "libexif-0.6.21-27.oe2003sp4.x86_64.rpm",
        "libexif-debuginfo-0.6.21-27.oe2003sp4.x86_64.rpm",
        "libexif-debugsource-0.6.21-27.oe2003sp4.x86_64.rpm",
        "libexif-devel-0.6.21-27.oe2003sp4.x86_64.rpm"
    ],
    "src": [
        "libexif-0.6.21-27.oe2003sp4.src.rpm"
    ],
    "noarch": [
        "libexif-help-0.6.21-27.oe2003sp4.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1678.json"
openEuler:22.03-LTS-SP4
libexif

Package

Name
libexif
Purl
pkg:rpm/openEuler/libexif&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.22-6.oe2203sp4

Ecosystem specific

{
    "aarch64": [
        "libexif-0.6.22-6.oe2203sp4.aarch64.rpm",
        "libexif-debuginfo-0.6.22-6.oe2203sp4.aarch64.rpm",
        "libexif-debugsource-0.6.22-6.oe2203sp4.aarch64.rpm",
        "libexif-devel-0.6.22-6.oe2203sp4.aarch64.rpm"
    ],
    "x86_64": [
        "libexif-0.6.22-6.oe2203sp4.x86_64.rpm",
        "libexif-debuginfo-0.6.22-6.oe2203sp4.x86_64.rpm",
        "libexif-debugsource-0.6.22-6.oe2203sp4.x86_64.rpm",
        "libexif-devel-0.6.22-6.oe2203sp4.x86_64.rpm"
    ],
    "src": [
        "libexif-0.6.22-6.oe2203sp4.src.rpm"
    ],
    "noarch": [
        "libexif-help-0.6.22-6.oe2203sp4.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1678.json"
openEuler:24.03-LTS
libexif

Package

Name
libexif
Purl
pkg:rpm/openEuler/libexif&distro=openEuler-24.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.24-2.oe2403sp3

Ecosystem specific

{
    "aarch64": [
        "libexif-0.6.24-2.oe2403.aarch64.rpm",
        "libexif-debuginfo-0.6.24-2.oe2403.aarch64.rpm",
        "libexif-debugsource-0.6.24-2.oe2403.aarch64.rpm",
        "libexif-devel-0.6.24-2.oe2403.aarch64.rpm",
        "libexif-0.6.24-2.oe2403sp1.aarch64.rpm",
        "libexif-debuginfo-0.6.24-2.oe2403sp1.aarch64.rpm",
        "libexif-debugsource-0.6.24-2.oe2403sp1.aarch64.rpm",
        "libexif-devel-0.6.24-2.oe2403sp1.aarch64.rpm",
        "libexif-0.6.24-2.oe2403sp2.aarch64.rpm",
        "libexif-debuginfo-0.6.24-2.oe2403sp2.aarch64.rpm",
        "libexif-debugsource-0.6.24-2.oe2403sp2.aarch64.rpm",
        "libexif-devel-0.6.24-2.oe2403sp2.aarch64.rpm",
        "libexif-0.6.24-2.oe2403sp3.aarch64.rpm",
        "libexif-debuginfo-0.6.24-2.oe2403sp3.aarch64.rpm",
        "libexif-debugsource-0.6.24-2.oe2403sp3.aarch64.rpm",
        "libexif-devel-0.6.24-2.oe2403sp3.aarch64.rpm"
    ],
    "x86_64": [
        "libexif-0.6.24-2.oe2403.x86_64.rpm",
        "libexif-debuginfo-0.6.24-2.oe2403.x86_64.rpm",
        "libexif-debugsource-0.6.24-2.oe2403.x86_64.rpm",
        "libexif-devel-0.6.24-2.oe2403.x86_64.rpm",
        "libexif-0.6.24-2.oe2403sp1.x86_64.rpm",
        "libexif-debuginfo-0.6.24-2.oe2403sp1.x86_64.rpm",
        "libexif-debugsource-0.6.24-2.oe2403sp1.x86_64.rpm",
        "libexif-devel-0.6.24-2.oe2403sp1.x86_64.rpm",
        "libexif-0.6.24-2.oe2403sp2.x86_64.rpm",
        "libexif-debuginfo-0.6.24-2.oe2403sp2.x86_64.rpm",
        "libexif-debugsource-0.6.24-2.oe2403sp2.x86_64.rpm",
        "libexif-devel-0.6.24-2.oe2403sp2.x86_64.rpm",
        "libexif-0.6.24-2.oe2403sp3.x86_64.rpm",
        "libexif-debuginfo-0.6.24-2.oe2403sp3.x86_64.rpm",
        "libexif-debugsource-0.6.24-2.oe2403sp3.x86_64.rpm",
        "libexif-devel-0.6.24-2.oe2403sp3.x86_64.rpm"
    ],
    "src": [
        "libexif-0.6.24-2.oe2403.src.rpm",
        "libexif-0.6.24-2.oe2403sp1.src.rpm",
        "libexif-0.6.24-2.oe2403sp2.src.rpm",
        "libexif-0.6.24-2.oe2403sp3.src.rpm"
    ],
    "noarch": [
        "libexif-help-0.6.24-2.oe2403.noarch.rpm",
        "libexif-help-0.6.24-2.oe2403sp1.noarch.rpm",
        "libexif-help-0.6.24-2.oe2403sp2.noarch.rpm",
        "libexif-help-0.6.24-2.oe2403sp3.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1678.json"
openEuler:24.03-LTS-SP1
libexif

Package

Name
libexif
Purl
pkg:rpm/openEuler/libexif&distro=openEuler-24.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.24-2.oe2403sp1

Ecosystem specific

{
    "aarch64": [
        "libexif-0.6.24-2.oe2403sp1.aarch64.rpm",
        "libexif-debuginfo-0.6.24-2.oe2403sp1.aarch64.rpm",
        "libexif-debugsource-0.6.24-2.oe2403sp1.aarch64.rpm",
        "libexif-devel-0.6.24-2.oe2403sp1.aarch64.rpm"
    ],
    "x86_64": [
        "libexif-0.6.24-2.oe2403sp1.x86_64.rpm",
        "libexif-debuginfo-0.6.24-2.oe2403sp1.x86_64.rpm",
        "libexif-debugsource-0.6.24-2.oe2403sp1.x86_64.rpm",
        "libexif-devel-0.6.24-2.oe2403sp1.x86_64.rpm"
    ],
    "src": [
        "libexif-0.6.24-2.oe2403sp1.src.rpm"
    ],
    "noarch": [
        "libexif-help-0.6.24-2.oe2403sp1.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1678.json"
openEuler:24.03-LTS-SP2
libexif

Package

Name
libexif
Purl
pkg:rpm/openEuler/libexif&distro=openEuler-24.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.24-2.oe2403sp2

Ecosystem specific

{
    "aarch64": [
        "libexif-0.6.24-2.oe2403sp2.aarch64.rpm",
        "libexif-debuginfo-0.6.24-2.oe2403sp2.aarch64.rpm",
        "libexif-debugsource-0.6.24-2.oe2403sp2.aarch64.rpm",
        "libexif-devel-0.6.24-2.oe2403sp2.aarch64.rpm"
    ],
    "x86_64": [
        "libexif-0.6.24-2.oe2403sp2.x86_64.rpm",
        "libexif-debuginfo-0.6.24-2.oe2403sp2.x86_64.rpm",
        "libexif-debugsource-0.6.24-2.oe2403sp2.x86_64.rpm",
        "libexif-devel-0.6.24-2.oe2403sp2.x86_64.rpm"
    ],
    "src": [
        "libexif-0.6.24-2.oe2403sp2.src.rpm"
    ],
    "noarch": [
        "libexif-help-0.6.24-2.oe2403sp2.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1678.json"
openEuler:24.03-LTS-SP3
libexif

Package

Name
libexif
Purl
pkg:rpm/openEuler/libexif&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.24-2.oe2403sp3

Ecosystem specific

{
    "aarch64": [
        "libexif-0.6.24-2.oe2403sp3.aarch64.rpm",
        "libexif-debuginfo-0.6.24-2.oe2403sp3.aarch64.rpm",
        "libexif-debugsource-0.6.24-2.oe2403sp3.aarch64.rpm",
        "libexif-devel-0.6.24-2.oe2403sp3.aarch64.rpm"
    ],
    "x86_64": [
        "libexif-0.6.24-2.oe2403sp3.x86_64.rpm",
        "libexif-debuginfo-0.6.24-2.oe2403sp3.x86_64.rpm",
        "libexif-debugsource-0.6.24-2.oe2403sp3.x86_64.rpm",
        "libexif-devel-0.6.24-2.oe2403sp3.x86_64.rpm"
    ],
    "src": [
        "libexif-0.6.24-2.oe2403sp3.src.rpm"
    ],
    "noarch": [
        "libexif-help-0.6.24-2.oe2403sp3.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1678.json"