CVE-2026-32775: Libexif Project Libexif
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.
Affected products
- Libexif Project Libexif: up to and including 0.6.25
Published 2026-03-16. Last modified 2026-06-17.