OESA-2026-1987

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-1987
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-1987.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-1987
Upstream
  • CVE-2026-40385
  • CVE-2026-40386
Published
2026-04-17T13:03:36Z
Modified
2026-04-17T13:20:42.288529Z
Summary
libexif security update
Details

Most digital cameras produce EXIF files, which are JPEG files with extra tags that contain information about the image. The EXIF library allows you to parse an EXIF file and read the data from those tags.

Security Fix(es):

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.(CVE-2026-40385)

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.(CVE-2026-40386)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:20.03-LTS-SP4
libexif

Package

Name
libexif
Purl
pkg:rpm/openEuler/libexif&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.21-28.oe2003sp4

Ecosystem specific

{
    "src": [
        "libexif-0.6.21-28.oe2003sp4.src.rpm"
    ],
    "aarch64": [
        "libexif-0.6.21-28.oe2003sp4.aarch64.rpm",
        "libexif-debuginfo-0.6.21-28.oe2003sp4.aarch64.rpm",
        "libexif-debugsource-0.6.21-28.oe2003sp4.aarch64.rpm",
        "libexif-devel-0.6.21-28.oe2003sp4.aarch64.rpm"
    ],
    "x86_64": [
        "libexif-0.6.21-28.oe2003sp4.x86_64.rpm",
        "libexif-debuginfo-0.6.21-28.oe2003sp4.x86_64.rpm",
        "libexif-debugsource-0.6.21-28.oe2003sp4.x86_64.rpm",
        "libexif-devel-0.6.21-28.oe2003sp4.x86_64.rpm"
    ],
    "noarch": [
        "libexif-help-0.6.21-28.oe2003sp4.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1987.json"
openEuler:22.03-LTS-SP4
libexif

Package

Name
libexif
Purl
pkg:rpm/openEuler/libexif&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.22-7.oe2203sp4

Ecosystem specific

{
    "src": [
        "libexif-0.6.22-7.oe2203sp4.src.rpm"
    ],
    "aarch64": [
        "libexif-0.6.22-7.oe2203sp4.aarch64.rpm",
        "libexif-debuginfo-0.6.22-7.oe2203sp4.aarch64.rpm",
        "libexif-debugsource-0.6.22-7.oe2203sp4.aarch64.rpm",
        "libexif-devel-0.6.22-7.oe2203sp4.aarch64.rpm"
    ],
    "x86_64": [
        "libexif-0.6.22-7.oe2203sp4.x86_64.rpm",
        "libexif-debuginfo-0.6.22-7.oe2203sp4.x86_64.rpm",
        "libexif-debugsource-0.6.22-7.oe2203sp4.x86_64.rpm",
        "libexif-devel-0.6.22-7.oe2203sp4.x86_64.rpm"
    ],
    "noarch": [
        "libexif-help-0.6.22-7.oe2203sp4.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1987.json"
openEuler:24.03-LTS
libexif

Package

Name
libexif
Purl
pkg:rpm/openEuler/libexif&distro=openEuler-24.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.24-3.oe2403sp3

Ecosystem specific

{
    "src": [
        "libexif-0.6.24-3.oe2403.src.rpm",
        "libexif-0.6.24-3.oe2403sp1.src.rpm",
        "libexif-0.6.24-3.oe2403sp2.src.rpm",
        "libexif-0.6.24-3.oe2403sp3.src.rpm"
    ],
    "aarch64": [
        "libexif-0.6.24-3.oe2403.aarch64.rpm",
        "libexif-debuginfo-0.6.24-3.oe2403.aarch64.rpm",
        "libexif-debugsource-0.6.24-3.oe2403.aarch64.rpm",
        "libexif-devel-0.6.24-3.oe2403.aarch64.rpm",
        "libexif-0.6.24-3.oe2403sp1.aarch64.rpm",
        "libexif-debuginfo-0.6.24-3.oe2403sp1.aarch64.rpm",
        "libexif-debugsource-0.6.24-3.oe2403sp1.aarch64.rpm",
        "libexif-devel-0.6.24-3.oe2403sp1.aarch64.rpm",
        "libexif-0.6.24-3.oe2403sp2.aarch64.rpm",
        "libexif-debuginfo-0.6.24-3.oe2403sp2.aarch64.rpm",
        "libexif-debugsource-0.6.24-3.oe2403sp2.aarch64.rpm",
        "libexif-devel-0.6.24-3.oe2403sp2.aarch64.rpm",
        "libexif-0.6.24-3.oe2403sp3.aarch64.rpm",
        "libexif-debuginfo-0.6.24-3.oe2403sp3.aarch64.rpm",
        "libexif-debugsource-0.6.24-3.oe2403sp3.aarch64.rpm",
        "libexif-devel-0.6.24-3.oe2403sp3.aarch64.rpm"
    ],
    "x86_64": [
        "libexif-0.6.24-3.oe2403.x86_64.rpm",
        "libexif-debuginfo-0.6.24-3.oe2403.x86_64.rpm",
        "libexif-debugsource-0.6.24-3.oe2403.x86_64.rpm",
        "libexif-devel-0.6.24-3.oe2403.x86_64.rpm",
        "libexif-0.6.24-3.oe2403sp1.x86_64.rpm",
        "libexif-debuginfo-0.6.24-3.oe2403sp1.x86_64.rpm",
        "libexif-debugsource-0.6.24-3.oe2403sp1.x86_64.rpm",
        "libexif-devel-0.6.24-3.oe2403sp1.x86_64.rpm",
        "libexif-0.6.24-3.oe2403sp2.x86_64.rpm",
        "libexif-debuginfo-0.6.24-3.oe2403sp2.x86_64.rpm",
        "libexif-debugsource-0.6.24-3.oe2403sp2.x86_64.rpm",
        "libexif-devel-0.6.24-3.oe2403sp2.x86_64.rpm",
        "libexif-0.6.24-3.oe2403sp3.x86_64.rpm",
        "libexif-debuginfo-0.6.24-3.oe2403sp3.x86_64.rpm",
        "libexif-debugsource-0.6.24-3.oe2403sp3.x86_64.rpm",
        "libexif-devel-0.6.24-3.oe2403sp3.x86_64.rpm"
    ],
    "noarch": [
        "libexif-help-0.6.24-3.oe2403.noarch.rpm",
        "libexif-help-0.6.24-3.oe2403sp1.noarch.rpm",
        "libexif-help-0.6.24-3.oe2403sp2.noarch.rpm",
        "libexif-help-0.6.24-3.oe2403sp3.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1987.json"
openEuler:24.03-LTS-SP1
libexif

Package

Name
libexif
Purl
pkg:rpm/openEuler/libexif&distro=openEuler-24.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.24-3.oe2403sp1

Ecosystem specific

{
    "src": [
        "libexif-0.6.24-3.oe2403sp1.src.rpm"
    ],
    "aarch64": [
        "libexif-0.6.24-3.oe2403sp1.aarch64.rpm",
        "libexif-debuginfo-0.6.24-3.oe2403sp1.aarch64.rpm",
        "libexif-debugsource-0.6.24-3.oe2403sp1.aarch64.rpm",
        "libexif-devel-0.6.24-3.oe2403sp1.aarch64.rpm"
    ],
    "x86_64": [
        "libexif-0.6.24-3.oe2403sp1.x86_64.rpm",
        "libexif-debuginfo-0.6.24-3.oe2403sp1.x86_64.rpm",
        "libexif-debugsource-0.6.24-3.oe2403sp1.x86_64.rpm",
        "libexif-devel-0.6.24-3.oe2403sp1.x86_64.rpm"
    ],
    "noarch": [
        "libexif-help-0.6.24-3.oe2403sp1.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1987.json"
openEuler:24.03-LTS-SP2
libexif

Package

Name
libexif
Purl
pkg:rpm/openEuler/libexif&distro=openEuler-24.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.24-3.oe2403sp2

Ecosystem specific

{
    "src": [
        "libexif-0.6.24-3.oe2403sp2.src.rpm"
    ],
    "aarch64": [
        "libexif-0.6.24-3.oe2403sp2.aarch64.rpm",
        "libexif-debuginfo-0.6.24-3.oe2403sp2.aarch64.rpm",
        "libexif-debugsource-0.6.24-3.oe2403sp2.aarch64.rpm",
        "libexif-devel-0.6.24-3.oe2403sp2.aarch64.rpm"
    ],
    "x86_64": [
        "libexif-0.6.24-3.oe2403sp2.x86_64.rpm",
        "libexif-debuginfo-0.6.24-3.oe2403sp2.x86_64.rpm",
        "libexif-debugsource-0.6.24-3.oe2403sp2.x86_64.rpm",
        "libexif-devel-0.6.24-3.oe2403sp2.x86_64.rpm"
    ],
    "noarch": [
        "libexif-help-0.6.24-3.oe2403sp2.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1987.json"
openEuler:24.03-LTS-SP3
libexif

Package

Name
libexif
Purl
pkg:rpm/openEuler/libexif&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.24-3.oe2403sp3

Ecosystem specific

{
    "src": [
        "libexif-0.6.24-3.oe2403sp3.src.rpm"
    ],
    "aarch64": [
        "libexif-0.6.24-3.oe2403sp3.aarch64.rpm",
        "libexif-debuginfo-0.6.24-3.oe2403sp3.aarch64.rpm",
        "libexif-debugsource-0.6.24-3.oe2403sp3.aarch64.rpm",
        "libexif-devel-0.6.24-3.oe2403sp3.aarch64.rpm"
    ],
    "x86_64": [
        "libexif-0.6.24-3.oe2403sp3.x86_64.rpm",
        "libexif-debuginfo-0.6.24-3.oe2403sp3.x86_64.rpm",
        "libexif-debugsource-0.6.24-3.oe2403sp3.x86_64.rpm",
        "libexif-devel-0.6.24-3.oe2403sp3.x86_64.rpm"
    ],
    "noarch": [
        "libexif-help-0.6.24-3.oe2403sp3.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1987.json"