<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:04:26 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:20929 — Moderate: libexif security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:20929</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libexif, AlmaLinux:8: libexif-devel&lt;/p&gt;
&lt;p&gt;The libexif packages provide a library for extracting extra information from image files.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libexif: libexif: Information disclosure and crashes via integer overflow in Nikon MakerNote handling (CVE-2026-40385)
  * libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding (CVE-2026-40386)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libexif, AlmaLinux:8: libexif-devel&lt;/p&gt;
&lt;p&gt;The libexif packages provide a library for extracting extra information from image files.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libexif: libexif: Information disclosure and crashes via integer overflow in Nikon MakerNote handling (CVE-2026-40385)
  * libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding (CVE-2026-40386)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:20929</guid>
    </item>
    <item>
      <title>bdu:2026-05545</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-05545</link>
      <description>bdu:2026-05545</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-05545</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0445 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0445</link>
      <description>certfr-2026-avi-0445</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0445</guid>
    </item>
    <item>
      <title>EUVD-2026-291290</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-291290</link>
      <description>EUVD-2026-291290</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-291290</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40386</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40386</link>
      <description>&lt;p&gt;In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40386</guid>
    </item>
    <item>
      <title>GHSA-p6wp-hhx9-7jj5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p6wp-hhx9-7jj5</link>
      <description>&lt;p&gt;In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p6wp-hhx9-7jj5</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-40386 — CVE-2026-40386</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-40386</link>
      <description>msrc_CVE-2026-40386</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-40386</guid>
    </item>
    <item>
      <title>OESA-2026-1987 — libexif security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1987</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: libexif, openEuler:22.03-LTS-SP4: libexif, openEuler:24.03-LTS: libexif, openEuler:24.03-LTS-SP1: libexif, openEuler:24.03-LTS-SP2: libexif, openEuler:24.03-LTS-SP3: libexif&lt;/p&gt;
&lt;p&gt;Most digital cameras produce EXIF files, which are JPEG files with extra tags that contain information about the image. The EXIF library allows you to parse an EXIF file and read the data from those tags.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.(CVE-2026-40385)&lt;/p&gt;
&lt;p&gt;In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.(CVE-2026-40386)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: libexif, openEuler:22.03-LTS-SP4: libexif, openEuler:24.03-LTS: libexif, openEuler:24.03-LTS-SP1: libexif, openEuler:24.03-LTS-SP2: libexif, openEuler:24.03-LTS-SP3: libexif&lt;/p&gt;
&lt;p&gt;Most digital cameras produce EXIF files, which are JPEG files with extra tags that contain information about the image. The EXIF library allows you to parse an EXIF file and read the data from those tags.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.(CVE-2026-40385)&lt;/p&gt;
&lt;p&gt;In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.(CVE-2026-40386)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1987</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10717-1 — libexif-devel-0.6.26-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10717-1</link>
      <description>&lt;p&gt;libexif-devel-0.6.26-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libexif-devel-0.6.26-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10717-1</guid>
    </item>
    <item>
      <title>RHSA-2026:26190 — Red Hat Security Advisory: libexif security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:26190</link>
      <description>&lt;p&gt;libexif: libexif: Information disclosure and crashes via integer overflow in Nikon MakerNote handling libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libexif: libexif: Information disclosure and crashes via integer overflow in Nikon MakerNote handling libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:26190</guid>
    </item>
    <item>
      <title>RLSA-2026:22529 — Moderate: libexif security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:22529</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: libexif&lt;/p&gt;
&lt;p&gt;The libexif packages provide a library for extracting extra information from image files.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding (CVE-2026-40386)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: libexif&lt;/p&gt;
&lt;p&gt;The libexif packages provide a library for extracting extra information from image files.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding (CVE-2026-40386)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:22529</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22324-1 — Security update for libexif</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22324-1</link>
      <description>&lt;p&gt;Security update for libexif&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libexif&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22324-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-40386</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-40386</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libexif, Ubuntu:16.04:LTS: libexif, Ubuntu:18.04:LTS: libexif, Ubuntu:20.04:LTS: libexif, Ubuntu:22.04:LTS: libexif, Ubuntu:24.04:LTS: libexif, Ubuntu:25.10: libexif, Ubuntu:26.04:LTS: libexif&lt;/p&gt;
&lt;p&gt;In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libexif, Ubuntu:16.04:LTS: libexif, Ubuntu:18.04:LTS: libexif, Ubuntu:20.04:LTS: libexif, Ubuntu:22.04:LTS: libexif, Ubuntu:24.04:LTS: libexif, Ubuntu:25.10: libexif, Ubuntu:26.04:LTS: libexif&lt;/p&gt;
&lt;p&gt;In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-40386</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1060 — libexif: Mehrere Schwachstellen ermöglichen Denial of Service und Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1060</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in libexif ausnutzen, um einen Denial of Service Angriff durchzuführen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in libexif ausnutzen, um einen Denial of Service Angriff durchzuführen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1060</guid>
    </item>
  </channel>
</rss>
