Security News

Cybersecurity news aggregator

🔄
MEDIUM Updates Red Hat Errata

RHSA-2026:26192: Moderate: libexif security update

  • What: Security update for libexif library
  • Impact: Addresses information disclosure and crashes in image file handling
Read Full Article →

Red Hat Product Errata RHSA-2026:26192 - Security Advisory Issued: 2026-06-16 Updated: 2026-06-16 RHSA-2026:26192 - Security Advisory Overview Updated Packages Synopsis Moderate: libexif security update Type/Severity Security Advisory: Moderate Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for libexif is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The libexif packages provide a library for extracting extra information from image files. Security Fix(es): libexif: libexif: Information disclosure and crashes via integer overflow in Nikon MakerNote handling (CVE-2026-40385) libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding (CVE-2026-40386) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.4 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 s390x Fixes BZ - 2457687 - CVE-2026-40385 libexif: libexif: Information disclosure and crashes via integer overflow in Nikon MakerNote handling BZ - 2457689 - CVE-2026-40386 libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding CVEs CVE-2026-40385 CVE-2026-40386 References https://access.redhat.com/security/updates/classification/#moderate Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.4 SRPM libexif-0.6.22-6.el9_4.1.src.rpm SHA-256: 1c5baf419e1e0a69445171b4c1efa17d231921bb051a72b7509ccc3d99ca988f x86_64 libexif-0.6.22-6.el9_4.1.i686.rpm SHA-256: fb4fa82edd30056741f5b4b3f4a8aa349a6ef340a81145c31b2ca8f4846d5fbb libexif-0.6.22-6.el9_4.1.x86_64.rpm SHA-256: ef602e6434e135390fd79a39cbfede4c7c749390968f1fc323e31a9b55916954 libexif-debuginfo-0.6.22-6.el9_4.1.i686.rpm SHA-256: c0760388506b937d6e4c4e34be3fa86e7008246a0a39e1cf83e9a0d469c1f4a6 libexif-debuginfo-0.6.22-6.el9_4.1.x86_64.rpm SHA-256: 443eeea4dcbcf61dae0c60d3e439878bb98fe0389adbeb5a1f69c3e4e6875cb5 libexif-debugsource-0.6.22-6.el9_4.1.i686.rpm SHA-256: 1dd45c9fff894a1033ddddd1362f4da9182cb6a972d913428710f0a5a8ec664f libexif-debugsource-0.6.22-6.el9_4.1.x86_64.rpm SHA-256: 9154bb565e4c8c25cbc489d834795486e86df244737d0670bd14e549e6a2cca9 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 SRPM libexif-0.6.22-6.el9_4.1.src.rpm SHA-256: 1c5baf419e1e0a69445171b4c1efa17d231921bb051a72b7509ccc3d99ca988f ppc64le libexif-0.6.22-6.el9_4.1.ppc64le.rpm SHA-256: 3ccb36024e327587c2f87e507470486fb022a12162f3ad9923c80a8ca8237842 libexif-debuginfo-0.6.22-6.el9_4.1.ppc64le.rpm SHA-256: 4685dccd0b5cc9c22e44d585f0ac5ffb66b42c8177a2c465889e54d5c3661f3a libexif-debugsource-0.6.22-6.el9_4.1.ppc64le.rpm SHA-256: 1090402e648eb6d03d1a3552677738d8639a77eb063d6b3b98ae96ef7f6f5809 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 SRPM libexif-0.6.22-6.el9_4.1.src.rpm SHA-256: 1c5baf419e1e0a69445171b4c1efa17d231921bb051a72b7509ccc3d99ca988f x86_64 libexif-0.6.22-6.el9_4.1.i686.rpm SHA-256: fb4fa82edd30056741f5b4b3f4a8aa349a6ef340a81145c31b2ca8f4846d5fbb libexif-0.6.22-6.el9_4.1.x86_64.rpm SHA-256: ef602e6434e135390fd79a39cbfede4c7c749390968f1fc323e31a9b55916954 libexif-debuginfo-0.6.22-6.el9_4.1.i686.rpm SHA-256: c0760388506b937d6e4c4e34be3fa86e7008246a0a39e1cf83e9a0d469c1f4a6 libexif-debuginfo-0.6.22-6.el9_4.1.x86_64.rpm SHA-256: 443eeea4dcbcf61dae0c60d3e439878bb98fe0389adbeb5a1f69c3e4e6875cb5 libexif-debugsource-0.6.22-6.el9_4.1.i686.rpm SHA-256: 1dd45c9fff894a1033ddddd1362f4da9182cb6a972d913428710f0a5a8ec664f libexif-debugsource-0.6.22-6.el9_4.1.x86_64.rpm SHA-256: 9154bb565e4c8c25cbc489d834795486e86df244737d0670bd14e549e6a2cca9 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 SRPM libexif-0.6.22-6.el9_4.1.src.rpm SHA-256: 1c5baf419e1e0a69445171b4c1efa17d231921bb051a72b7509ccc3d99ca988f aarch64 libexif-0.6.22-6.el9_4.1.aarch64.rpm SHA-256: b9baa9fdbb557bdbc092eebfd70d1bf8d252ad6eef25221b555c20b7216461d3 libexif-debuginfo-0.6.22-6.el9_4.1.aarch64.rpm SHA-256: e5d7c158458008ca7ef28045f7ef7351e188ec755b2823b2f07ef0b85cad1306 libexif-debugsource-0.6.22-6.el9_4.1.aarch64.rpm SHA-256: 1fd8008451aa95830696da1deeec8c4529d8813c0d6c52906e42aa7c579ad89d Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 SRPM libexif-0.6.22-6.el9_4.1.src.rpm SHA-256: 1c5baf419e1e0a69445171b4c1efa17d231921bb051a72b7509ccc3d99ca988f s390x libexif-0.6.22-6.el9_4.1.s390x.rpm SHA-256: 5f36185c749dccfe72ba5a54c7a7f62915c99e5770c213c24598ee657ab66eca libexif-debuginfo-0.6.22-6.el9_4.1.s390x.rpm SHA-256: df1b75dbd98eabf56e754009b6c20f4f83e589fd824cc3741d092d1ef93cf973 libexif-debugsource-0.6.22-6.el9_4.1.s390x.rpm SHA-256: 063ba3ecda74207bce5a299f2e22ab963baa50656a5ddc055c35523bad0a04de Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 SRPM libexif-0.6.22-6.el9_4.1.src.rpm SHA-256: 1c5baf419e1e0a69445171b4c1efa17d231921bb051a72b7509ccc3d99ca988f x86_64 libexif-0.6.22-6.el9_4.1.i686.rpm SHA-256: fb4fa82edd30056741f5b4b3f4a8aa349a6ef340a81145c31b2ca8f4846d5fbb libexif-0.6.22-6.el9_4.1.x86_64.rpm SHA-256: ef602e6434e135390fd79a39cbfede4c7c749390968f1fc323e31a9b55916954 libexif-debuginfo-0.6.22-6.el9_4.1.i686.rpm SHA-256: c0760388506b937d6e4c4e34be3fa86e7008246a0a39e1cf83e9a0d469c1f4a6 libexif-debuginfo-0.6.22-6.el9_4.1.x86_64.rpm SHA-256: 443eeea4dcbcf61dae0c60d3e439878bb98fe0389adbeb5a1f69c3e4e6875cb5 libexif-debugsource-0.6.22-6.el9_4.1.i686.rpm SHA-256: 1dd45c9fff894a1033ddddd1362f4da9182cb6a972d913428710f0a5a8ec664f libexif-debugsource-0.6.22-6.el9_4.1.x86_64.rpm SHA-256: 9154bb565e4c8c25cbc489d834795486e86df244737d0670bd14e549e6a2cca9 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 SRPM libexif-0.6.22-6.el9_4.1.src.rpm SHA-256: 1c5baf419e1e0a69445171b4c1efa17d231921bb051a72b7509ccc3d99ca988f aarch64 libexif-0.6.22-6.el9_4.1.aarch64.rpm SHA-256: b9baa9fdbb557bdbc092eebfd70d1bf8d252ad6eef25221b555c20b7216461d3 libexif-debuginfo-0.6.22-6.el9_4.1.aarch64.rpm SHA-256: e5d7c158458008ca7ef28045f7ef7351e188ec755b2823b2f07ef0b85cad1306 libexif-debugsource-0.6.22-6.el9_4.1.aarch64.rpm SHA-256: 1fd8008451aa95830696da1deeec8c4529d8813c0d6c52906e42aa7c579ad89d Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 SRPM libexif-0.6.22-6.el9_4.1.src.rpm SHA-256: 1c5baf419e1e0a69445171b4c1efa17d231921bb051a72b7509ccc3d99ca988f ppc64le libexif-0.6.22-6.el9_4.1.ppc64le.rpm SHA-256: 3ccb36024e327587c2f87e507470486fb022a12162f3ad9923c80a8ca8237842 libexif-debuginfo-0.6.22-6.el9_4.1.ppc64le.rpm SHA-256: 4685dccd0b5cc9c22e44d585f0ac5ffb66b42c8177a2c465889e54d5c3661f3a libexif-debugsource-0.6.22-6.el9_4.1.ppc64le.rpm SHA-256: 1090402e648eb6d03d1a3552677738d8639a77eb063d6b3b98ae96ef7f6f5809 Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 SRPM libexif-0.6.22-6.el9_4.1.src.rpm SHA-256: 1c5baf419e1e0a69445171b4c1efa17d231921bb051a72b7509ccc3d99ca988f s390x libexif-0.6.22-6.el9_4.1.s390x.rpm SHA-256: 5f36185c749dccfe72ba5a54c7a7f62915c99e5770c213c24598ee657ab66eca libexif-debuginfo-0.6.22-6.el9_4.1.s390x.rpm SHA-256: df1b75dbd98eabf56e754009b6c20f4f83e589fd824cc3741d092d1ef93cf973 libexif-debugsource-0.6.22-6.el9_4.1.s390x.rpm SHA-256: 063ba3ecda74207bce5a299f2e22ab963baa50656a5ddc055c35523bad0a04de The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article