- What: Security update for libexif in Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Telecommunications Update Service
- Impact: Systems using libexif may be vulnerable if not updated
Red Hat Product Errata RHSA-2026:26190 - Security Advisory Issued: 2026-06-16 Updated: 2026-06-16 RHSA-2026:26190 - Security Advisory Overview Updated Packages Synopsis Moderate: libexif security update Type/Severity Security Advisory: Moderate Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for libexif is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The libexif packages provide a library for extracting extra information from image files. Security Fix(es): libexif: libexif: Information disclosure and crashes via integer overflow in Nikon MakerNote handling (CVE-2026-40385) libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding (CVE-2026-40386) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 x86_64 Red Hat Enterprise Linux Server - TUS 8.8 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64 Fixes BZ - 2457687 - CVE-2026-40385 libexif: libexif: Information disclosure and crashes via integer overflow in Nikon MakerNote handling BZ - 2457689 - CVE-2026-40386 libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote decoding CVEs CVE-2026-40385 CVE-2026-40386 References https://access.redhat.com/security/updates/classification/#moderate Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 SRPM libexif-0.6.22-5.el8_8.1.src.rpm SHA-256: bf6238dd01e85566993203d80e4ef088e2f91f91b1c4e575775c4e14d42fcd9a x86_64 libexif-0.6.22-5.el8_8.1.i686.rpm SHA-256: 12e20421dadb487dd2e9113de7cac80b5686f56657fc5fd79e8ebc4cacf700c6 libexif-0.6.22-5.el8_8.1.x86_64.rpm SHA-256: 3d9b9915376494c1be2c5b533abd8156ea9198e44a967465e329d1961373ff2e libexif-debuginfo-0.6.22-5.el8_8.1.i686.rpm SHA-256: 3441821056bfeeb68bbe41f32950408534a10944b7bf2648a36995365c7465c3 libexif-debuginfo-0.6.22-5.el8_8.1.x86_64.rpm SHA-256: 965eaa22e62bc98ed06dc01282de9ab3ece3c95fb047989d63372ae35dfe4a34 libexif-debugsource-0.6.22-5.el8_8.1.i686.rpm SHA-256: 760ef6696f6c900cb38f922bd6a538fb8d320855ed25d0dc45b230bdfbf98b71 libexif-debugsource-0.6.22-5.el8_8.1.x86_64.rpm SHA-256: d5470995eba80df8fc68989d2cb42bef4c69b502099aebc685fa3453a08f7367 Red Hat Enterprise Linux Server - TUS 8.8 SRPM libexif-0.6.22-5.el8_8.1.src.rpm SHA-256: bf6238dd01e85566993203d80e4ef088e2f91f91b1c4e575775c4e14d42fcd9a x86_64 libexif-0.6.22-5.el8_8.1.i686.rpm SHA-256: 12e20421dadb487dd2e9113de7cac80b5686f56657fc5fd79e8ebc4cacf700c6 libexif-0.6.22-5.el8_8.1.x86_64.rpm SHA-256: 3d9b9915376494c1be2c5b533abd8156ea9198e44a967465e329d1961373ff2e libexif-debuginfo-0.6.22-5.el8_8.1.i686.rpm SHA-256: 3441821056bfeeb68bbe41f32950408534a10944b7bf2648a36995365c7465c3 libexif-debuginfo-0.6.22-5.el8_8.1.x86_64.rpm SHA-256: 965eaa22e62bc98ed06dc01282de9ab3ece3c95fb047989d63372ae35dfe4a34 libexif-debugsource-0.6.22-5.el8_8.1.i686.rpm SHA-256: 760ef6696f6c900cb38f922bd6a538fb8d320855ed25d0dc45b230bdfbf98b71 libexif-debugsource-0.6.22-5.el8_8.1.x86_64.rpm SHA-256: d5470995eba80df8fc68989d2cb42bef4c69b502099aebc685fa3453a08f7367 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 SRPM libexif-0.6.22-5.el8_8.1.src.rpm SHA-256: bf6238dd01e85566993203d80e4ef088e2f91f91b1c4e575775c4e14d42fcd9a ppc64le libexif-0.6.22-5.el8_8.1.ppc64le.rpm SHA-256: 00ddcc95d71e4fdf66c17aa1ed31245137fc405f77fc747094e53fce488f16bb libexif-debuginfo-0.6.22-5.el8_8.1.ppc64le.rpm SHA-256: 019f55b2d4911836c1d64c8aba48db3ebef8b80182f805d0e77e3d5fa9bcb456 libexif-debugsource-0.6.22-5.el8_8.1.ppc64le.rpm SHA-256: 4efd5b445bcd9dbf6cd2844dc87f83cf08298be2f559fd5ad4cffbbe7c739851 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 SRPM libexif-0.6.22-5.el8_8.1.src.rpm SHA-256: bf6238dd01e85566993203d80e4ef088e2f91f91b1c4e575775c4e14d42fcd9a x86_64 libexif-0.6.22-5.el8_8.1.i686.rpm SHA-256: 12e20421dadb487dd2e9113de7cac80b5686f56657fc5fd79e8ebc4cacf700c6 libexif-0.6.22-5.el8_8.1.x86_64.rpm SHA-256: 3d9b9915376494c1be2c5b533abd8156ea9198e44a967465e329d1961373ff2e libexif-debuginfo-0.6.22-5.el8_8.1.i686.rpm SHA-256: 3441821056bfeeb68bbe41f32950408534a10944b7bf2648a36995365c7465c3 libexif-debuginfo-0.6.22-5.el8_8.1.x86_64.rpm SHA-256: 965eaa22e62bc98ed06dc01282de9ab3ece3c95fb047989d63372ae35dfe4a34 libexif-debugsource-0.6.22-5.el8_8.1.i686.rpm SHA-256: 760ef6696f6c900cb38f922bd6a538fb8d320855ed25d0dc45b230bdfbf98b71 libexif-debugsource-0.6.22-5.el8_8.1.x86_64.rpm SHA-256: d5470995eba80df8fc68989d2cb42bef4c69b502099aebc685fa3453a08f7367 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .