In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.
References
Configurations
History
14 Apr 2026, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Libexif Project libexif
Libexif Project |
|
| CPE | cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:* | |
| References | () https://github.com/libexif/libexif/commit/93003b93e50b3d259bd2227d8775b73a53c35d58 - Patch |
12 Apr 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-12 19:16
Updated : 2026-04-14 20:15
NVD link : CVE-2026-40385
Mitre link : CVE-2026-40385
CVE.ORG link : CVE-2026-40385
JSON object : View
Products Affected
libexif_project
- libexif
CWE
CWE-190
Integer Overflow or Wraparound
