- What: Security update for libexif library
- Impact: Addresses information disclosure and crashes in image file handling
Red Hat Product Errata RHSA-2026:26191 - Security Advisory Issued: 2026-06-16 Updated: 2026-06-16 RHSA-2026:26191 - Security Advisory Overview Updated Packages Synopsis Moderate: libexif security update Type/Severity Security Advisory: Moderate Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for libexif is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The libexif packages provide a library for extracting extra information from image files. Security Fix(es): libexif: libexif: Information disclosure and crashes via integer overflow in Nikon MakerNote handling (CVE-2026-40385) libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding (CVE-2026-40386) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 x86_64 Red Hat Enterprise Linux Server - AUS 8.6 x86_64 Fixes BZ - 2457687 - CVE-2026-40385 libexif: libexif: Information disclosure and crashes via integer overflow in Nikon MakerNote handling BZ - 2457689 - CVE-2026-40386 libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding CVEs CVE-2026-40385 CVE-2026-40386 References https://access.redhat.com/security/updates/classification/#moderate Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 SRPM libexif-0.6.22-5.el8_6.1.src.rpm SHA-256: c07d7eb8990db1f244b9b28eb2f550a99cbc3c221971727bbf8744e9073f9315 x86_64 libexif-0.6.22-5.el8_6.1.i686.rpm SHA-256: 794d4934d25ecdfc70ae5f4100e5817fbb14f761c2cd20c3cc3e683c7924880f libexif-0.6.22-5.el8_6.1.x86_64.rpm SHA-256: 2f19a6f102bc5c2fde6ce9808c3628b8c9328fcafc91093feba4eb7ddd496f8e libexif-debuginfo-0.6.22-5.el8_6.1.i686.rpm SHA-256: c7aea7ff5131ac8c4aecc75c1bf147e56746624ba01012684c5ca26643bb88d7 libexif-debuginfo-0.6.22-5.el8_6.1.x86_64.rpm SHA-256: f4396ad753048d7861580b4b77eb6674e539cee3a17aac7af5b8846ee2075508 libexif-debugsource-0.6.22-5.el8_6.1.i686.rpm SHA-256: 679fa5650cfb0aceae260feefb26a1cfd72a056605feba8bb9b9e51c33722151 libexif-debugsource-0.6.22-5.el8_6.1.x86_64.rpm SHA-256: 7a4cc66a5337e12d102bce8b53f895bb4acba5b0f3041006af28883ddc971ab3 Red Hat Enterprise Linux Server - AUS 8.6 SRPM libexif-0.6.22-5.el8_6.1.src.rpm SHA-256: c07d7eb8990db1f244b9b28eb2f550a99cbc3c221971727bbf8744e9073f9315 x86_64 libexif-0.6.22-5.el8_6.1.i686.rpm SHA-256: 794d4934d25ecdfc70ae5f4100e5817fbb14f761c2cd20c3cc3e683c7924880f libexif-0.6.22-5.el8_6.1.x86_64.rpm SHA-256: 2f19a6f102bc5c2fde6ce9808c3628b8c9328fcafc91093feba4eb7ddd496f8e libexif-debuginfo-0.6.22-5.el8_6.1.i686.rpm SHA-256: c7aea7ff5131ac8c4aecc75c1bf147e56746624ba01012684c5ca26643bb88d7 libexif-debuginfo-0.6.22-5.el8_6.1.x86_64.rpm SHA-256: f4396ad753048d7861580b4b77eb6674e539cee3a17aac7af5b8846ee2075508 libexif-debugsource-0.6.22-5.el8_6.1.i686.rpm SHA-256: 679fa5650cfb0aceae260feefb26a1cfd72a056605feba8bb9b9e51c33722151 libexif-debugsource-0.6.22-5.el8_6.1.x86_64.rpm SHA-256: 7a4cc66a5337e12d102bce8b53f895bb4acba5b0f3041006af28883ddc971ab3 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .