Bug 35368 - libexif new security issues CVE-2026-32775 and CVE-2026-4038[56]
Summary: libexif new security issues CVE-2026-32775 and CVE-2026-4038[56]
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2026-04-15 15:34 CEST by Nicolas Salguero
Modified: 2026-05-07 07:08 CEST (History)
5 users (show)

See Also:
Source RPM: libexif-0.6.24-2.mga9.src.rpm
CVE: CVE-2026-32775, CVE-2026-40385, CVE-2026-40386
Status comment: Fixed upstream in 0.6.26 and patches available from upstream
herman.viaene: test_passed_mga9_64+


Attachments

Description Nicolas Salguero 2026-04-15 15:34:51 CEST
Slackware has issued an advisory on April 14:
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2026&m=slackware-security.368011
Comment 1 Nicolas Salguero 2026-04-15 15:36:58 CEST
CVE-2026-32775:
Fixed by: https://github.com/libexif/libexif/commit/7df372e9d31d7c993a22b913c813a5f7ec4f3692

CVE-2026-40385:
Fixed by: https://github.com/libexif/libexif/commit/93003b93e50b3d259bd2227d8775b73a53c35d58

CVE-2026-40386:
Fixed by: https://github.com/libexif/libexif/commit/dc6eac6e9655d14d0779d99e82d0f5f442d2f34b

CVE: (none) => CVE-2026-32775, CVE-2026-40385, CVE-2026-40386
Source RPM: (none) => libexif-0.6.24-2.mga9.src.rpm
Status comment: (none) => Fixed upstream in 0.6.26 and patches available from upstream

Comment 2 Marja Van Waes 2026-04-15 15:48:47 CEST
No registered maintainer, assigning to all.

CC: (none) => marja11
Assignee: bugsquad => pkg-bugs

Comment 3 David GEIGER 2026-04-29 12:33:57 CEST
Assigning to QA,

Packages in 9/Core/Updates_testing:
======================
lib64exif-devel-0.6.26-1.mga9
lib64exif12-0.6.26-1.mga9
libexif-devel-0.6.26-1.mga9
libexif12-0.6.26-1.mga9
libexif12-common-0.6.26-1.mga9

From SRPMS
libexif-0.6.26-1.mga9.src.rpm

Assignee: pkg-bugs => qa-bugs
CC: (none) => geiger.david68210

katnatek 2026-05-02 18:14:32 CEST

Keywords: (none) => advisory

Comment 4 Herman Viaene 2026-05-04 11:58:29 CEST
MGA9-64 server Plasma Wayland on Compaq H000SB.
No installation issues.
Ref bug 27592
$ exif IMG_1251.jpg
EXIF tags in 'IMG_1251.jpg' ('Intel' byte order):
--------------------+----------------------------------------------------------
Tag                 |Value
--------------------+----------------------------------------------------------
Image Description   |                               
Manufacturer        |Canon
Model               |Canon IXUS 240 HS
Orientation         |Top-left
X-Resolution        |180
Y-Resolution        |180
Resolution Unit     |Inch
Date and Time       |2014:01:19 14:54:06
YCbCr Positioning   |Co-sited
Compression         |JPEG compression
X-Resolution        |180
Y-Resolution        |180
Resolution Unit     |Inch
Exposure Time       |1/30 sec.
F-Number            |f/5.0
ISO Speed Ratings   |800
Sensitivity Type    |Standard output sensitivity (SOS) and recommended exposure
Exif Version        |Exif Version 2.3
Date and Time (Origi|2014:01:19 14:54:06
Date and Time (Digit|2014:01:19 14:54:06
Components Configura|Y Cb Cr -
Compressed Bits per | 3
Shutter Speed       |4.91 EV (1/30 sec.)
Aperture            |4.66 EV (f/5.0)
Exposure Bias       |0.00 EV
Maximum Aperture Val|4.66 EV (f/5.0)
Metering Mode       |Pattern
Flash               |Flash did not fire, compulsory flash mode
Focal Length        |12.5 mm
Maker Note          |3830 bytes undefined data
User Comment        |
FlashPixVersion     |FlashPix Version 1.0
Color Space         |sRGB
Pixel X Dimension   |4608
Pixel Y Dimension   |3456
Focal Plane X-Resolu|18962.963
Focal Plane Y-Resolu|18989.011
Focal Plane Resoluti|Inch
Sensing Method      |One-chip color area sensor
File Source         |DSC
Custom Rendered     |Normal process
Exposure Mode       |Auto exposure
White Balance       |Auto white balance
Digital Zoom Ratio  |1.0000
Scene Capture Type  |Standard
Camera Owner Name   |
Interoperability Ind|R98
Interoperability Ver|0100
RelatedImageWidth   |4608
RelatedImageLength  |3456
--------------------+----------------------------------------------------------
EXIF data contains a thumbnail (6476 bytes)

Looks OK to me.

Whiteboard: (none) => MGA9-64-OK
CC: (none) => herman.viaene
Flags: (none) => test_passed_mga9_64+

Comment 5 Thomas Andrews 2026-05-05 17:01:35 CEST
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 6 Mageia Robot 2026-05-07 07:08:19 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2026-0112.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.