CVE-2026-40385Integer Overflow or Wraparound in Project Libexif

Severity
4.0MEDIUMNVD
EPSS
0.0%
top 98.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 12
Latest updateApr 14

Description

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:LExploitability: 1.4 | Impact: 2.5

Affected Packages1 packages

CVEListV5libexif_project/libexif0.6.25

🔴Vulnerability Details

3
GHSA
GHSA-j9xr-5c85-xjhm: In libexif through 02026-04-12
VulDB
libexif up to 0.6.25 Nikon MakerNote integer overflow2026-04-12
CVEList
CVE-2026-40385: In libexif through 02026-04-12

📋Vendor Advisories

1
Red Hat
libexif: libexif: Information disclosure and crashes via integer overflow in Nikon MakerNote handling2026-04-12

🕵️Threat Intelligence

1
Rapid7
Patch Tuesday - April 20262026-04-14

💬Community

2
Bugzilla
CVE-2026-40385 libexif: libexif: Information disclosure and crashes via integer overflow in Nikon MakerNote handling [fedora-all]2026-04-13
Bugzilla
CVE-2026-40385 libexif: libexif: Information disclosure and crashes via integer overflow in Nikon MakerNote handling2026-04-12
CVE-2026-40385 — Integer Overflow or Wraparound | cvebase