4
/ 10
MEDIUM
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
Description
In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.
Basic Information
ID
CVE-2026-40385
Source
mitre
Published
Apr 12, 2026 at 18:16
Modified
Apr 12, 2026 at 18:53
Affected Product
Vendor
libexif project
Product
libexif
Affected Versions
libexif project libexif 0